368,530open jobs
9,432companies
50,439added this week
Browse all
Location
In office (Petaling Jaya)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Grab Holdings is a leading Southeast Asian "super-app" technology company headquartered in Singapore. Originally founded as a ride-hailing service, Grab has expanded into a comprehensive digital ecosystem offering transportation (GrabCar, GrabBike), food and grocery delivery (GrabFood, GrabMart), and fintech services (GrabPay, digital banking, lending, and insurance). Operating across eight countries in the region, Grab connects millions of consumers with driver and merchant partners daily.

About Grab and Our Workplace

Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Get to know our Team

We're looking for a Senior Security Engineer to join our SecAID team in Petaling Jaya, Malaysia. SecAID sits at the intersection of offensive security and software engineering. We build and operate tooling that scales security across Grab's engineering organisation, embed security into the development lifecycle before code ships, and work directly with product and platform teams to raise the security bar.

Get to know the Role

You won't just assess and reporting. You'll be a force in how Grab engineers build securely. You will shape pipelines, influencing design decisions early, triage scanner output at scale, and making security something engineering teams do with us rather than something done to them. You will suit someone who is technically deep in offensive security and mature enough to operate as a security partner to a engineering organisation. You will be reporting to Software Engineering Manager II, Threat Detection.

This role is onsite based in our Petaling Jaya, Malaysia office.

The Critical Tasks You Will Perform

DevSecOps and Shift-Left Security

  • You will advocate for security integration into CI/CD pipelines across Grab's engineering teams, working with platform and developer experience teams to embed security gates early in the development lifecycle
  • You will build security guardrails, standards, and developer-facing guidance that teams can self-serve without waiting for a security review
  • You will identify systemic patterns across findings and translate them into reusable secure coding standards, reference architectures, and training materials for engineering teams

Security Assessments and Penetration Testing

  • You will conduct application-layer security assessments across Grab's services covering APIs, web, and mobile attack surfaces, producing findings that service teams can act on
  • You will evaluate findings from automated DAST scans against OWASP ASVS controls, triage true positives from false positives, and provide clear remediation guidance

Threat Hunting and Detection

  • You will investigate Grab's environments for indicators of compromise, anomalous behaviour, and attacker techniques that evade automated detection
  • You will develop threat hunting hypotheses grounded in attacker tradecraft and apply them to Grab's specific technology landscape
  • You will contribute to detection logic and work with operations teams to operationalise findings from hunting activity

Team and Stakeholder Enablement

  • You will be a technical authority for the team across security engineering work and mentor teammates from both security and software engineering backgrounds
  • You will be a trusted advisor to product and platform engineering teams, helping them understand findings and implement security improvements rather than just receiving a ticket

What Essential Skills You will Need

  • You have 5+ years in cybersecurity with a offensive security foundation; you have done assessments, found vulnerabilities, and understand how attackers think
  • You have solid hands-on experience in application security: API testing, auth flows, injection classes, business logic abuse, OWASP Top 10 and ASVS
  • You demonstrated experience integrating security into software development pipelines, including hands-on work with SAST, DAST, SCA, or secrets scanning tools in a CI/CD context
  • You have enough software engineering knowledge to read code, review architecture diagrams, and have credible conversations with developers; you do not need to build production systems but you need to understand them
  • You have experience conducting security design and specification reviews

Good to have:

  • You have offensive security certifications: OSCP, OSWE, BSCP, or equivalent practical credentials
  • You have familiarity with cloud-native architectures (AWS, GCP, or Azure) and container security
  • You have experience with MITRE ATT&CK and applying it to detection or assessment work
  • You have background working in a product company or platform engineering environment with an understanding of the pace and constraints of a shipping team
  • You have experience building developer-facing security programmes, secure coding standards, or threat modelling frameworks

Life at Grab

We care about your well-being at Grab, here are some of the global benefits we offer:

  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.

What We Stand For At Grab

We are committed to building an inclusive and equitable workplace that provides equal opportunity for Grabbers to grow and perform at their best. We consider all candidates fairly and equally regardless of nationality, ethnicity, race, religion, age, gender, family commitments, physical and mental impairments or disabilities, and other attributes that make them unique.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Petaling Jaya
$18k – $46k per year (Estimated) • In office • Full-Time • Moscow
DevOps
Ansible
ArgoCD
AWS
CI/CD
Docker
GitLab CI
Helm
Kubernetes
OpenTofu
Terraform
Terragrunt
Yandex Cloud
GitLab
Apply
$32k – $57k per year (Estimated) • Remote • 4+ years exp • Moscow
Python
Python
Django
FastAPI
Databases
MySQL
PostgreSQL
DevOps
CI/CD
Docker
Grafana
Prometheus
Apply
Sr DevOps Engineer 1 day ago
$23k – $59k per year (Estimated) • In office • Full-Time
AI/ML
AI Agents
DevOps
Ansible
CI/CD
Configuration Management
SLI/SLO/SLA
Terraform
Apply
$61k – $143k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Cambridge
Go
Node JS
Python
TypeScript
JavaScript
Databases
ElasticSearch
MySQL
Frontend
GraphQL
Next.js
React.js
DevOps
CI/CD
Kubernetes
Apply
$23k – $62k per year (Estimated) • In office • Full-Time • 10+ years exp • Gurgaon
C#
SQL
Databases
Apache Kafka
Redis
DevOps
Azure
CI/CD
Docker
gRPC
Kubernetes
Apply
$31k – $61k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Python
SQL
Databases
Presto
AI/ML
AI Agents
Fine-tuning
Kubeflow
LangChain
LangGraph
LangSmith
LLM
LoRA
MLFlow
PEFT
Prompt Engineering
Spark
Transformers
Amazon SageMaker
LLM Guardrails
DevOps
Git
GitHub
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Ho Chi Minh City
C#
C++
Erlang
Go
Haskell
Java
Node JS
OCaml
PHP
Python
Ruby
Rust
Scala
JavaScript
Apply
In office • Full-Time • 7+ years exp • Jakarta
Go
Python
DevOps
AWS
CI/CD
Datadog
GitLab CI
Grafana
Kibana
GitLab
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Ho Chi Minh City
C#
C++
Erlang
Go
Haskell
Java
Node JS
OCaml
PHP
Python
Ruby
Rust
Scala
JavaScript
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Jakarta
Python
SQL
JavaScript
Frontend
D3.js
Analytics
Power BI
A/B Testing
Apply
In office • Full-Time • 3+ years exp • Bachelor's Degree • Petaling Jaya
Python
SQL
AI/ML
Claude
LangChain
LangGraph
LightGBM
LLM
PyTorch
Qwen
RAG
Scikit-learn
Spark
Synthetic Data
TensorFlow
Transformers
XGBoost
AI Agents
Apply
In office • Full-Time • Petaling Jaya
Apply
QA Automated Tester 3 days ago
In office • Full-Time • 2+ years exp • Bachelor's Degree • Petaling Jaya
Java
TypeScript
JavaScript
Frontend
Angular
DevOps
CI/CD
Git
QA
Cucumber
Selenium
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Petaling Jaya
C++
Go
JavaScript
Scala
Databases
MySQL
PostgreSQL
Redis
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Analytics
A/B Testing
Apply
In office • Full-Time • 3+ years exp • Petaling Jaya
C++
Go
Java
Python
SQL
Databases
Apache Kafka
RabbitMQ
DevOps
AWS
Azure
CI/CD
Docker
GCP
Git
Kubernetes
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.