Senior Security Engineer - Threat Detection

GrabTaxi Holdings Pte. Ltd.

Petaling Jaya

On-site

MYR 180,000 - 300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Term Life Insurance
Medical Insurance
GrabFlex benefits
Parental leave
Birthday leave
LASA volunteering leave
Grabber Assistance Programme

Job summary

GrabTaxi Holdings Pte. Ltd. in Petaling Jaya, Malaysia, is seeking a Senior Security Engineer to join the SecAID team onsite. You will be a security partner to engineering, shaping secure development pipelines and triaging scanner output at scale.

You will lead DevSecOps, perform application security assessments, and mentor engineers while collaborating with product and platform teams to raise the security bar.

Qualifications

  • 5+ years in cybersecurity with an offensive security foundation.
  • Hands-on app security experience: API tests, auth flows, OWASP Top 10/ASVS.
  • Experience integrating security into CI/CD with SAST/DAST/SCA in pipelines.
  • Ability to read code and discuss architecture with developers.
  • Experience performing security design and specification reviews.

Responsibilities

  • DevSecOps: advocate security in CI/CD pipelines and embed gates early.
  • Security assessments across APIs, web, and mobile attack surfaces with actionable findings.
  • Threat hunting and detection, developing hypotheses for Grab's tech stack.
  • Mentor teammates and advise product/platform teams on security improvements.

Skills

Offensive security
Application security
CI/CD security
Code & architecture reading
Security design reviews

Tools

SAST
DAST
SCA

Job description

About Grab and Our Workplace

Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Get to know our Team

We're looking for a Senior Security Engineer to join our SecAID team in Petaling Jaya, Malaysia. SecAID sits at the intersection of offensive security and software engineering. We build and operate tooling that scales security across Grab's engineering organisation, embed security into the development lifecycle before code ships, and work directly with product and platform teams to raise the security bar.

Get to know the Role

You won't just assess and reporting. You'll be a force in how Grab engineers build securely. You will shape pipelines, influencing design decisions early, triage scanner output at scale, and making security something engineering teams do with us rather than something done to them. You will suit someone who is technically deep in offensive security and mature enough to operate as a security partner to a engineering organisation. You will be reporting to Software Engineering Manager II, Threat Detection.

This role is onsite based in our Petaling Jaya, Malaysia office.

The Critical Tasks You Will Perform
DevSecOps and Shift-Left Security
  • You will advocate for security integration into CI/CD pipelines across Grab's engineering teams, working with platform and developer experience teams to embed security gates early in the development lifecycle
  • You will build security guardrails, standards, and developer-facing guidance that teams can self-serve without waiting for a security review
  • You will identify systemic patterns across findings and translate them into reusable secure coding standards, reference architectures, and training materials for engineering teams
Security Assessments and Penetration Testing
  • You will conduct application-layer security assessments across Grab's services covering APIs, web, and mobile attack surfaces, producing findings that service teams can act on
  • You will evaluate findings from automated DAST scans against OWASP ASVS controls, triage true positives from false positives, and provide clear remediation guidance
Threat Hunting and Detection
  • You will investigate Grab's environments for indicators of compromise, anomalous behaviour, and attacker techniques that evade automated detection
  • You will develop threat hunting hypotheses grounded in attacker tradecraft and apply them to Grab's specific technology landscape
  • You will contribute to detection logic and work with operations teams to operationalise findings from hunting activity
Team and Stakeholder Enablement
  • You will be a technical authority for the team across security engineering work and mentor teammates from both security and software engineering backgrounds
  • You will be a trusted advisor to product and platform engineering teams, helping them understand findings and implement security improvements rather than just receiving a ticket
What Essential Skills You will Need
  • You have 5+ years in cybersecurity with a offensive security foundation; you have done assessments, found vulnerabilities, and understand how attackers think
  • You have solid hands-on experience in application security: API testing, auth flows, injection classes, business logic abuse, OWASP Top 10 and ASVS
  • You demonstrated experience integrating security into software development pipelines, including hands-on work with SAST, DAST, SCA, or secrets scanning tools in a CI/CD context
  • You have enough software engineering knowledge to read code, review architecture diagrams, and have credible conversations with developers; you do not need to build production systems but you need to understand them
  • You have experience conducting security design and specification reviews
Good to have:
  • You have offensive security certifications: OSCP, OSWE, BSCP, or equivalent practical credentials
  • You have familiarity with cloud-native architectures (AWS, GCP, or Azure) and container security
  • You have experience with MITRE ATT&CK and applying it to detection or assessment work
  • You have background working in a product company or platform engineering environment with an understanding of the pace and constraints of a shipping team
  • You have experience building developer-facing security programmes, secure coding standards, or threat modelling frameworks
Life at Grab

We care about your well-being at Grab, here are some of the global benefits we offer:

  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.
What We Stand For At Grab

We are committed to building an inclusive and equitable workplace that provides equal opportunity for Grabbers to grow and perform at their best. We consider all candidates fairly and equally regardless of nationality, ethnicity, race, religion, age, gender, family commitments, physical and mental impairments or disabilities, and other attributes that make them unique.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

Grab • Petaling Jaya

On-site
MYR 220,000 - 360,000
Term Life Insurance & Medical Coverage
GrabFlex benefits package
Parental & Birthday leave
+2
Lead Security Engineer, Red Team & Threat Intel
Lead Security Engineer, Red Team & Threat Intel

Grab • Petaling Jaya

On-site
MYR 120,000 - 160,000
Term Life Insurance
Comprehensive Medical Insurance
FlexBenefits package
+2
Lead Security Engineer, Red Team & Threat Intel
Lead Security Engineer, Red Team & Threat Intel

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 244,000 - 367,000
Term Life Insurance
Comprehensive Medical Insurance
GrabFlex benefits package
+3
Lead Software Engineer, Backend
Lead Software Engineer, Backend

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 240,000
Term Life Insurance
Medical Insurance
GrabFlex
+5
Software Engineer, Backend - GrabDefence
Software Engineer, Backend - GrabDefence

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 210,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+1
Software Engineer, Backend - GrabDefence
Software Engineer, Backend - GrabDefence

Grab • Selangor

On-site
MYR 120,000 - 240,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+4
Senior Software Engineer, Backend
Senior Software Engineer, Backend

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 180,000
Term Life Insurance
Medical Insurance
GrabFlex
+5
Software Engineer, Backend
Software Engineer, Backend

Grab • Petaling Jaya

On-site
MYR 60,000 - 120,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+4
Enterprise Security Engineer
Enterprise Security Engineer

Grab • Petaling Jaya

On-site
MYR 60,000 - 120,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+5
Enterprise Security Engineer
Enterprise Security Engineer

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 90,000 - 130,000
Term Life Insurance
Medical Insurance
GrabFlex benefits package
+5