Senior Insider Threat Engineer

Grab

Jakarta Pusat

On-site

IDR 400,000,000 - 800,000,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Term Life Insurance
Medical Insurance
GrabFlex benefits
Parental leave
Birthday leave
LASA volunteering leave
Grabber Assistance Programme
FlexWork hours

Job summary

Grab is seeking a senior cybersecurity engineer to join the Insider Threat Detection team in Jakarta. You will design detections across identity, endpoints, cloud services, and data platforms, turning complex threat scenarios into measurable signals and preventive controls.

The role reports to the Lead of Insider Threat Detection and requires hands-on experience with detections, investigations, and AI-enabled security workflows in an on-site capacity.

Qualifications

  • At least 5 years of experience in cybersecurity engineering, detection engineering, threat hunting, incident response, insider threat, or enterprise data protection.
  • Proficiency in SQL and at least one programming or security-query language such as Python, KQL, or SPL.
  • Solid understanding of identity, endpoint, cloud, SaaS, and enterprise data architectures.
  • Practical experience investigating user activity across telemetry sources and producing evidence-based findings.
  • Familiarity with SIEM, UEBA, DLP, CASB, EDR/XDR, IAM, and cloud-security platforms.
  • Hands-on experience building and tuning detections using large-scale security datasets, behavioural baselines, event correlation, anomaly detection, or risk scoring.
  • Experience using AI tools and latest technologies to improve security workflows.

Responsibilities

  • Design, build and improve behavioural detections for data misuse, unusual access, excessive downloads, unauthorised data movement, credential misuse, privilege abuse, and attempts to bypass security controls.
  • Lead complex technical investigations and proactive threat hunts, correlating identity, endpoint, network, cloud, SaaS, application, and data-access telemetry to reconstruct user activity and assess risk.
  • Develop queries, scripts, data pipelines, risk-scoring models, and automation to improve telemetry enrichment, alert quality, case triage, investigation speed, and detection coverage.
  • Partner with Identity and Access Management, Endpoint Security, Data Governance, and Enterprise Security teams to identify and address gaps across DLP, CASB, SIEM, UEBA, EDR/XDR, cloud, and data-protection controls.
  • Develop detection scenarios for Generative AI, large language models, AI agents, and Shadow AI, including sensitive-data exposure, misuse of enterprise AI capabilities, and AI-assisted attempts to evade security controls.

Skills

Cybersecurity engineering
SQL
Python/KQL/SPL
Threat hunting
AI for security
Identity/Endpoint/Cloud/SaaS arch

Tools

SIEM Platforms
EDR/XDR
Cloud security tools

Job description

Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Job Description

Get to Know the Team

The Insider Threat Management team is part of Cyber Defense. We protect Grab's people, data, systems, and customers from risks involving trusted users, compromised identities, data misuse, privilege abuse, and latest AI-enabled threats.

We are an evidence-led, engineering-focused team. We combine behavioural analytics, threat hunting, investigations, and security controls to detect meaningful risks early while respecting privacy, due process, and legitimate business activity.

You will work with Security Engineering, Enterprise Security, Identity and Access Management, Endpoint Security, Data Governance, Privacy, Legal, People, and AI teams across Grab.

Get to Know the Role

You will help build and operate Grab's insider threat detection and investigation capabilities across identity, endpoints, cloud services, SaaS applications, enterprise systems, data platforms, and AI environments.

This is a senior, hands-on engineering role. You will turn complex and sometimes ambiguous threat scenarios into measurable signals, scalable detections, investigation workflows, and preventive controls.

You will report to the Lead of Insider Threat Detection. This is an onsite role based in Jakarta.

The Critical Tasks You Will Perform

  • You will design, build and improve behavioural detections for data misuse, unusual access, excessive downloads, unauthorised data movement, credential misuse, privilege abuse, and attempts to bypass security controls.
  • You will lead complex technical investigations and proactive threat hunts, correlating identity, endpoint, network, cloud, SaaS, application, and data-access telemetry to reconstruct user activity and assess risk.
  • You will develop queries, scripts, data pipelines, risk-scoring models, and automation to improve telemetry enrichment, alert quality, case triage, investigation speed, and detection coverage.
  • You will partner with Identity and Access Management, Endpoint Security, Data Governance, and Enterprise Security teams to identify and address gaps across DLP, CASB, SIEM, UEBA, EDR/XDR, cloud, and data-protection controls.
  • You will develop detection scenarios for Generative AI, large language models, AI agents, and Shadow AI, including sensitive-data exposure, misuse of enterprise AI capabilities, and AI-assisted attempts to evade security controls.
Qualifications

The Essential Skills You Will Need

  • At least 5 years of experience in cybersecurity engineering, detection engineering, threat hunting, incident response, insider threat, or enterprise data protection.
  • Proficiency in SQL and at least one programming or security-query language such as Python, KQL, or SPL.
  • A solid understanding of identity, endpoint, cloud, SaaS, and enterprise data architectures, including common paths for credential, privilege, and data misuse.
  • Practical experience investigating user activity across multiple telemetry sources and producing evidence-based findings.
  • Familiarity with SIEM, UEBA, DLP, CASB, EDR/XDR, IAM, and cloud-security platforms.
  • Hands-on experience building and tuning detections using large-scale security datasets, behavioural baselines, event correlation, anomaly detection, or risk scoring.
  • Experience using AI tools and latest technologies to improve security workflows, with care when handling sensitive information.
Additional Information

Life at Grab

We care about your well-being at Grab, here are some of the global benefits we offer:

  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.
  • Balancing personal commitments and life's demands are made easier with our FlexWork arrangements such as differentiated hours

What We Stand For at Grab

We are committed to building an inclusive and equitable workplace that provides equal opportunity for Grabbers to grow and perform at their best. We consider all candidates fairly and equally regardless of nationality, ethnicity, race, religion, age, gender, family commitments, physical and mental impairments or disabilities, and other attributes that make them unique.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Insider Threat Engineer
Senior Insider Threat Engineer

Grab • Indonesia

On-site
IDR 446,400,000 - 781,200,000
Senior Insider Threat Engineer
Senior Insider Threat Engineer

PT Solusi Transportasi Indonesia • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Term Life Insurance
Medical Insurance
GrabFlex
+5
Senior Insider Threat Engineer
Senior Insider Threat Engineer

GrabTaxi Holdings Pte. Ltd. • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Term Life Insurance
Medical Insurance
GrabFlex
+5
Lead Security Engineer, Red Team & Threat Intel
Lead Security Engineer, Red Team & Threat Intel

GrabTaxi Holdings Pte. Ltd. • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,361,903,000 - 1,815,871,000
Term Life Insurance
Medical Insurance
Flexible work arrangements
+3
Lead Security Engineer, Red Team & Threat Intel
Lead Security Engineer, Red Team & Threat Intel

Grab • Jakarta Timur

Hybrid
IDR 1,254,255,000 - 1,612,615,000
Term Life Insurance
Medical Insurance
FlexWork arrangements
Senior Insider Threat Engineer
Senior Insider Threat Engineer

Security • Jakarta Utara

On-site
IDR 480,000,000 - 720,000,000
Software Engineering Manager II
Software Engineering Manager II

Grab • Jakarta Pusat

On-site
IDR 350,000,000 - 600,000,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+5
Senior Software Engineer, Backend
Senior Software Engineer, Backend

GrabTaxi Holdings Pte. Ltd. • Jakarta Pusat

On-site
IDR 420,000,000 - 720,000,000
Term Life Insurance
Medical Insurance
GrabFlex benefits package
+4
Identity Management Engineer
Identity Management Engineer

Grab • Jakarta Timur

On-site
IDR 15,000,000 - 20,000,000
Term Life Insurance
Comprehensive Medical Insurance
Flexible Work Arrangements
Senior Software Software Engineer, Backend - Insurance
Senior Software Software Engineer, Backend - Insurance

Grab • Jakarta Pusat

On-site
IDR 120,000,000 - 210,000,000
Term Life Insurance
Medical Insurance
GrabFlex
+5