Senior Threat Detection Engineer

Grab

Petaling Jaya

On-site

MYR 180,000 - 240,000

Full time

6 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Term Life Insurance
Medical Insurance
GrabFlex benefits
Parental leave
Birthday leave
LASA volunteering leave
Grabber Assistance Program
FlexWork hours

Job summary

Grab in Malaysia is seeking a Security Engineer (Detection Engineering) to research and build new detection capabilities focusing on cloud, containerized services, and AI-related threats. This is a hands-on engineering role reporting to the Security Automation and Detection Engineering Manager, with collaboration across CSIRT, incident response, and platform teams.

This onsite role based in Petaling Jaya requires a degree in CS/SE/Security and 3+ years experience with AWS/Azure/GCP,

Qualifications

  • A degree in Computer Science, Software Engineering, Cyber Security or related fields.
  • Hands-on security response experience (e.g., SOC, DFIR, and security engineering) with incident investigation and remediation.
  • 3+ years of experience with at least one cloud platform (Azure, AWS, GCP).
  • Direct experience with SIEM, EDR and SOAR platforms in an operational environment.
  • Coding skills in Python or Go for building detection logic and automation.
  • Proficient in writing detection queries in SQL for large datasets.
  • Experience tuning detection rules across multiple log sources (cloud, endpoint, network, identity, SaaS).
  • Experience using AI tooling in security contexts.

Responsibilities

  • Research new detections and translate attacker TTPs into detection opportunities.
  • Build, test, and deploy detection logic across SIEM/EDR/SOAR with CI/CD.
  • Prototype and validate detection logic using large-scale logs.
  • Lead the detection lifecycle, tuning, and metrics.
  • Triage alerts with CSIRT when required and provide incident guidance.
  • Document detections and present results to Cyber Defence.

Skills

Python
Go
SQL
Threat Detection
Cloud Security
Security Operations
Incident Response

Education

Bachelor's degree in Computer Science / Software Engineering / Cyber Security

Tools

SIEM
EDR
SOAR
Azure
AWS
GCP

Job description

About Grab and Our Workplace
Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Company Description
About Grab and Our Workplace
Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Job Description
Get to Know the Team
Our Detection Engineering function in Cyber Defence is responsible for detecting, managing, and responding to malicious activity across Grab's infrastructure — from cloud and SaaS to endpoints and identity platforms. We follow our detection-as-code framework and lifecycle, G-DARF (Grab Detection, Alerting and Response Framework).
You will be reporting to the Security Automation and Detection Engineering Manager, partnering with the Security Operations team, platform teams, and other cyber functions.

Get to Know the Role
We Are Looking For a Security Engineer (Detection Engineering) – To Research And Build New Detection Capabilities, With a Primary Focus On

  • Amazon EKS and containerized microservices
  • AI / MCP and agentic systems security detections
  • Autonomous vehicle / IOT platforms and supporting infrastructure
  • Other new threats identified through incidents, threat intel, purple teaming, and ongoing findings

This is a hands-on, engineering-heavy role that combines threat research, security operations experience, and software engineering.

This is a fully onsite role, and will be based at our office in Petaling Jaya.

The Critical Tasks You Will Perform

  • Research new detections
    • Research attacker TTPs relevant to focus areas and translate them into concrete detection opportunities.
    • Perform focused analysis of log sources (e.g., Kubernetes/EKS, CloudTrail, GuardDuty, AV telemetry, AI/agent frameworks) to understand visibility, constraints, and potential blind spots.
    • Collaborate with threat intel, red/purple team, incident responders, and platform teams to turn incident insights and threat intel into proactive detections, improve log coverage, and validate assumptions.
  • Build, test, and deploy detection logic
    • Implement high-fidelity detection rules and analytics across SIEM, EDR, SOAR, and custom detection frameworks. Follow detection-as-code practices, including version control, code review, automated tests, and CI/CD.
    • Prototype and validate detection logic against large-scale log data in the Security Data Lake using SQL/KQL.
    • Ensure detection logic is operationally sound: performant at scale, and suitable for near real‑time and batch use cases.
  • Lead the detection lifecycle and tuning
    • Participate in daily detection lifecycle activities: backlog grooming, prioritisation, development, staging, deployment, monitoring, and iterative tuning.
    • Review alert quality, false positive patterns, and coverage gaps; create targeted fine-tuning and suppression strategies to reduce alert fatigue while preserving coverage.
    • Support the creation and tracking of detection metrics (e.g., time to deploy, false positive rate, coverage, detection MTTR inputs) and use them to guide continuous improvement.
  • Incident and response support
    • Triage and investigate alerts with CSIRT if required, validate our detection hypotheses, and deliver emergency detections when we discover active threats.
    • Provide clear guidance on expected behaviour, triage steps, and response actions so responders can act.
    • Participate (where required) in ad‑hoc or rostered on‑call / incident support to address urgent security matters.
  • Documentation, communication and collaboration
    • Produce high-quality detection documentation (goal, context, logic, false positives, blind spots, response runbook) aligned to our detection framework standards.
    • Present new detections and alerts to Cyber Defence; explain the why, how, and operational impact.

Qualifications
What Essential Skills You Will Need

  • A degree in Computer Science, Software Engineering, Cyber Security or related fields
  • Hands-on security response experience (e.g., SOC, DFIR, and security engineering) with experience investigating incidents, writing timelines, and driving remediation.
  • 3+ years of experience with at least one cloud platform (Azure, AWS, GCP)
  • Direct experience working with SIEM, EDR and SOAR platforms in an operational environment (e.g., building rules, dashboards, runbooks, or integrations).
  • Coding skills in at least one general‑purpose language ( Python/Go) for building detection logic, data processing scripts, and automation/integration workflows.
  • Comfortable writing detection and investigation queries in SQL, including working with large security datasets in a data‑lake or big‑data environment.
  • Experience tuning detection rules across multiple log sources (cloud, endpoint, network, identity, SaaS).
  • Experience using AI

Additional Information

Life at Grab

  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.
  • Balancing personal commitments and life's demands are made easier with our FlexWork arrangements such as differentiated hours

What We Stand For At Grab

We are committed to building an inclusive and equitable workplace that provides equal opportunity for Grabbers to grow and perform at their best. We consider all candidates fairly and equally regardless of nationality, ethnicity, race, religion, age, gender, family commitments, physical and mental impairments or disabilities, and other attributes that make them unique.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Detection Engineer
Senior Threat Detection Engineer

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 180,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+2
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 180,000 - 300,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+4
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

Grab • Petaling Jaya

On-site
MYR 220,000 - 360,000
Term Life Insurance & Medical Coverage
GrabFlex benefits package
Parental & Birthday leave
+2
Lead Security Engineer, Red Team & Threat Intel
Lead Security Engineer, Red Team & Threat Intel

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 244,000 - 367,000
Term Life Insurance
Comprehensive Medical Insurance
GrabFlex benefits package
+3
Software Engineer, Backend - GrabDefence
Software Engineer, Backend - GrabDefence

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 210,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+1
Senior Software Engineer, Backend
Senior Software Engineer, Backend

Grab • Petaling Jaya

On-site
MYR 60,000 - 100,000
Term Life Insurance
Medical Insurance
Flexible Work Arrangements
+4
Senior IT Cloud Engineer
Senior IT Cloud Engineer

Grab • Petaling Jaya

On-site
MYR 180,000 - 300,000
Life Insurance
Medical Insurance
GrabFlex benefits
+4
Senior Infrastructure Engineer
Senior Infrastructure Engineer

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 180,000 - 280,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+5
Lead Software Engineer, Backend
Lead Software Engineer, Backend

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 120,000 - 240,000
Term Life Insurance
Medical Insurance
GrabFlex
+5
Senior Systems Engineer (Mobile Device Management)
Senior Systems Engineer (Mobile Device Management)

Grab • Petaling Jaya

On-site
MYR 180,000 - 280,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+4