Our Detection Engineering function in Cyber Defence is responsible for detecting, managing, and responding to malicious activity across Grab's infrastructure - from cloud and SaaS to endpoints and identity platforms. We follow our detection-as-code framework and lifecycle, G-DARF (Grab Detection, Alerting and Response Framework).
You will be reporting to the Security Automation and Detection Engineering Manager, partnering with the Security Operations team, platform teams, and other cyber functions.
Get to Know the Role
We are looking for a Security Engineer (Detection Engineering) – to research and build new detection capabilities, with a primary focus on:
- Amazon EKS and containerized microservices
- AI / MCP and agentic systems security detections
- Autonomous vehicle / IOT platforms and supporting infrastructure
- Other new threats identified through incidents, threat intel, purple teaming, and ongoing findings
This is a hands-on, engineering-heavy role that combines threat research, security operations experience, and software engineering.
This is a fully onsite role, and will be based at our office in Petaling Jaya.
The Critical Tasks You Will Perform
- Research new detections
- Research attacker TTPs relevant to focus areas and translate them into concrete detection opportunities.
- Perform focused analysis of log sources (e.g., Kubernetes/EKS, CloudTrail, GuardDuty, AV telemetry, AI/agent frameworks) to understand visibility, constraints, and potential blind spots.
- Collaborate with threat intel, red/purple team, incident responders, and platform teams to turn incident insights and threat intel into proactive detections, improve log coverage, and validate assumptions.
- Build, test, and deploy detection logic
- Implement high-fidelity detection rules and analytics across SIEM, EDR, SOAR, and custom detection frameworks. Follow detection-as-code practices, including version control, code review, automated tests, and CI/CD.
- Prototype and validate detection logic against large-scale log data in the Security Data Lake using SQL/KQL.
- Ensure detection logic is operationally sound: performant at scale, and suitable for near real-time and batch use cases.
- Lead the detection lifecycle and tuning
- Participate in daily detection lifecycle activities: backlog grooming, prioritisation, development, staging, deployment, monitoring, and iterative tuning.
- Review alert quality, false positive patterns, and coverage gaps; create targeted fine-tuning and suppression strategies to reduce alert fatigue while preserving coverage.
- Support the creation and tracking of detection metrics (e.g., time to deploy, false positive rate, coverage, detection MTTR inputs) and use them to guide continuous improvement.
- Incident and response support
- Triage and investigate alerts with CSIRT if required, validate our detection hypotheses, and deliver emergency detections when we discover active threats.
- Provide clear guidance on expected behaviour, triage steps, and response actions so responders can act.
- Participate (where required) in ad-hoc or rostered on-call / incident support to address urgent security matters.
- Documentation, communication and collaboration
- Produce high-quality detection documentation (goal, context, logic, false positives, blind spots, response runbook) aligned to our detection framework standards.
- Present new detections and alerts to Cyber Defence; explain the why, how, and operational impact.