Senior Security Engineer - Threat Detection
Job Description
Get to know our Team
We're looking for a Senior Security Engineer to join our SecAID team in Petaling Jaya, Malaysia. SecAID sits at the intersection of offensive security and software engineering. We build and operate tooling that scales security across Grab's engineering organisation, embed security into the development lifecycle before code ships, and work directly with product and platform teams to raise the security bar.
Get to know the Role
You won't just assess and reporting. You'll be a force in how Grab engineers build securely. You will shape pipelines, influencing design decisions early, triage scanner output at scale, and making security something engineering teams do with us rather than something done to them. You will suit someone who is technically deep in offensive security and mature enough to operate as a security partner to a engineering organisation. You will be reporting to Software Engineering Manager II, Threat Detection.
This role is onsite based in our Petaling Jaya, Malaysia office.
The Critical Tasks You Will Perform
DevSecOps and Shift-Left Security
• You will advocate for security integration into CI/CD pipelines across Grab's engineering teams, working with platform and developer experience teams to embed security gates early in the development lifecycle
• You will build security guardrails, standards, and developer-facing guidance that teams can self-serve without waiting for a security review
• You will identify systemic patterns across findings and translate them into reusable secure coding standards, reference architectures, and training materials for engineering teams
Security Assessments and Penetration Testing
• You will conduct application-layer security assessments across Grab's services covering APIs, web, and mobile attack surfaces, producing findings that service teams can act on
• You will evaluate findings from automated DAST scans against OWASP ASVS controls, triage true positives from false positives, and provide clear remediation guidance
Threat Hunting and Detection
• You will investigate Grab's environments for indicators of compromise, anomalous behaviour, and attacker techniques that evade automated detection
• You will develop threat hunting hypotheses grounded in attacker tradecraft and apply them to Grab's specific technology landscape
• You will contribute to detection logic and work with operations teams to operationalise findings from hunting activity
Team and Stakeholder Enablement
• You will be a technical authority for the team across security engineering work and mentor teammates from both security and software engineering backgrounds
• You will be a trusted advisor to product and platform engineering teams, helping them understand findings and implement security improvements rather than just receiving a ticket
Requirements
Function: Engineering
Experience Level: Mid-Senior Level