Senior Security Engineer
GrabMalaysiaFull-time6d ago
SecurityEngineeringremotecurated-jd
Job description
Senior Security Engineer at Grab.
About the role
This position involves shaping how Grab engineers build secure systems. You will influence design decisions, manage scanner output, and integrate security into the development process. The role requires deep technical knowledge in offensive security and the ability to partner with engineering teams.
Key facts
What you'll do
- Promote security integration into CI/CD pipelines and collaborate with platform teams to embed security gates early in development.
- Create security guardrails, standards, and guidance for developers to use independently.
- Identify common security patterns and translate them into secure coding standards, reference architectures, and training.
- Perform application security assessments on Grab's services, including APIs, web, and mobile, and provide actionable findings.
- Evaluate DAST scan results against OWASP ASVS, distinguishing true positives from false positives, and offer clear remediation advice.
- Investigate Grab's environments for signs of compromise, unusual behavior, and attacker methods that bypass automated detection.
- Develop threat hunting hypotheses based on attacker tactics and apply them to Grab's technology stack.
- Contribute to detection logic and work with operations teams to implement findings from hunting activities.
- Act as a technical expert for the team, mentoring colleagues from both security and software engineering backgrounds.
- Advise product and platform engineering teams on understanding findings and implementing security improvements.
Requirements
- 5+ years in cybersecurity with a background in offensive security, including assessments and vulnerability discovery.
- Strong practical experience in application security, covering API testing, authentication flows, injection flaws, business logic abuse, OWASP Top 10, and ASVS.
- Demonstrated experience integrating security into software development pipelines, including hands-on work with SAST, DAST, SCA, or secrets scanning tools in CI/CD.
- Sufficient software engineering knowledge to read code, review architecture diagrams, and engage in technical discussions with developers.
- Experience conducting security design and specification reviews.
Nice to have
- Offensive security certifications such as OSCP, OSWE, BSCP, or similar practical credentials.
- Familiarity with cloud-native architectures (AWS, GCP, or Azure) and container security.
- Experience with MITRE ATT&CK and its application to detection or assessment work.
- Background working in a product company or platform engineering environment, understanding the pace and constraints of shipping teams.
- Experience building developer-facing security programs, secure coding standards, or threat modeling frameworks.
Skills & tools
- SAST
- DAST
- SCA
- Secrets scanning tools
- OWASP Top 10
- OWASP ASVS
- CI/CD
- AWS
- GCP
- Azure
- MITRE ATT&CK
Practical notes
This is an onsite role in Petaling Jaya, Malaysia. The position reports to the Software Engineering Manager II, Threat Detection. Grab offers term life insurance, comprehensive medical insurance, and a flexible benefits package (GrabFlex). Benefits include parental leave, birthday leave, and volunteering leave (Love-all-Serve-all). A confidential Grabber Assistance Programme is available.