Senior Security Engineer - Threat Detection
Core
Build and operate security tooling to embed security into Grab's engineering lifecycle, conduct application-layer security assessments, and perform threat hunting across APIs, web, and mobile attack surfaces.
Role type
Senior Security Engineer (Offensive Security & DevSecOps)
Builds
Security guardrails, CI/CD security gates, detection logic, and secure coding standards for Grab's engineering organization
Domain
Cybersecurity, Application Security, DevSecOps, Threat Detection
Required skills
Offensive security methodology, Application security testing (API, auth, injection, business logic), CI/CD security integration (SAST/DAST/SCA), Security design reviews, Code review capability
Preferred skills
Cloud-native security (AWS/GCP/Azure), Container security, MITRE ATT&CK framework, Threat modelling, Developer security program building
Technologies
SAST, DAST, SCA, secrets scanning tools, OWASP ASVS
Responsibilities
Advocate for security integration into CI/CD pipelines, Conduct application-layer security assessments, Investigate environments for indicators of compromise and anomalous behavior, Develop threat hunting hypotheses, Build security guardrails and developer-facing guidance, Mentor teammates and advise product/platform teams
Seniority
Senior, hands-on IC
