Senior Security Engineer - Threat Detection

🗓️ Posted 2026-08-24 Petaling Jaya, Selangor, Malaysia Full-time Hybrid ICT

Company shared salary

NA

Market rate

RM10,000–RM18,000/mo (RM120,000–RM216,000/yr)

Based on similar roles (title + domain + location).

About the Company

About Grab and Our Workplace Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility. Get to know our Team We're looking for a Senior Security Engineer to join our SecAID team in Petaling Jaya, Malaysia. SecAID sits at the intersection of offensive security and software engineering. We build and operate tooling that scales security across Grab's engineering organisation, embed security into the development lifecycle before code ships, and work directly with product and platform teams to raise the security bar. Get to know the Role You won't just assess and reporting. You'll be a force in how Grab engineers build securely. You will shape pipelines, influencing design decisions early, triage scanner output at scale, and making security something engineering teams do with us rather than something done to them. You will suit someone who is technically deep in offensive security and mature enough to operate as a security partner to a engineering organisation. You will be reporting to Software Engineering Manager II, Threat Detection. This role is onsite based in our Petaling Jaya, Malaysia office. The Critical Tasks You Will Perform DevSecOps and Shift-Left Security You will be a technical authority for the team across security engineering work and mentor teammates from both security and software engineering backgrounds You will be a trusted advisor to product and platform engineering teams, helping them understand findings and implement security improvements rather than just receiving a ticket

Requirements

  • You have 5+ years in cybersecurity with a offensive security foundation; you have done assessments, found vulnerabilities, and understand how attackers think
  • You have solid hands-on experience in application security: API testing, auth flows, injection classes, business logic abuse, OWASP Top 10 and ASVS
  • You demonstrated experience integrating security into software development pipelines, including hands-on work with SAST, DAST, SCA, or secrets scanning tools in a CI/CD context
  • You have enough software engineering knowledge to read code, review architecture diagrams, and have credible conversations with developers; you do not need to build production systems but you need to understand them
  • You have experience conducting security design and specification reviews
  • You have offensive security certifications: OSCP, OSWE, BSCP, or equivalent practical credentials
  • You have familiarity with cloud-native architectures (AWS, GCP, or Azure) and container security
  • You have experience with MITRE ATT&CK and applying it to detection or assessment work
  • You have background working in a product company or platform engineering environment with an understanding of the pace and constraints of a shipping team
  • You have experience building developer-facing security programmes, secure coding standards, or threat modelling frameworks
  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.