Product Security Engineer Graduate (Security BP) - 2027 Start
About Us
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Lemon8, CapCut, and Pico, as well as platforms specific to the China market, such as Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Inspiring creativity is at the core of ByteDance's mission. Our innovative products are built to help people authentically express themselves, discover, and connect—and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity, and enrich life. As ByteDancers, we strive to do great things with great people, leading with curiosity, humility, and a desire to make an impact in a rapidly growing tech company. By fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users.
Responsibilities
- Ensure that our applications are designed and implemented to the highest security and privacy standards, maintaining and enhancing user trust.
- Review and analyze design, architectures, existing systems, services, operating systems, networks, and applications from a security perspective via black box testing, code reviews, automation, threat modeling, and research.
- Discover security issues that appear under new threat scenarios, support incident response, forensics, and remediation in a cross-functional environment driving toward incident resolution.
- Leverage AI and LLM capabilities to build, improve, and innovate solutions to address security issues at scale.
- Work closely with business teams to design and implement tailored security strategies based on their specific operational and business needs, delivering cost-effective and scalable security solutions aligned with business objectives.
Qualifications
Minimum Qualifications
- Completing or recently completed a Bachelor's/Master's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related discipline.
- Security engineering experience such as design review, threat modeling, security mitigation development, security tooling development, or privacy engineering.
- Solid knowledge and understanding in various disciplines: web application security, mobile app security, network security, operating system internals and hardening, applied cryptography, and cloud computing. You're expected to be an expert in at least one of these areas.
- Experience in writing and reviewing code in at least one of the following programming languages: JavaScript (Node.js), Go, Python, Java, C++, or Rust.
- Strong problem-solving skills and excellent debugging/troubleshooting skills.
Preferred Qualifications
- CTF, Bug-Bounty, or Live Hacking Event experience.
- Security public recognition through Vulnerability Disclosure Programs.
- Published security research, open-source tooling, CVEs, or presentations/talks at top security conferences.
Pay
The base salary range for this position is $87,400 - $162,000 annually. Compensation may vary outside of this range depending on qualifications, skills, competencies, experience, and location. Base pay is one part of the total package, which may include additional discretionary bonuses/incentives and restricted stock units.
Benefits
- Day-one access to medical, dental, and vision insurance.
- 401(k) savings plan with company match.
- Paid parental leave.
- Short-term and long-term disability coverage.
- Life insurance.
- Wellbeing benefits.
- 10 paid holidays per year.
- 10 paid sick days per year.
- 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).