Senior Security Engineer, Cyber Defense (Threat Detection)
Core
Senior Security Engineer responsible for triaging security alerts, reducing mean time to detection and containment, and leading incident response for Grab's Cyber Defence team.
Role type
Senior IC security operations engineer (threat detection & response)
Builds
Automated detection rules, playbooks, and SOAR workflows for host and network intrusion detection
Domain
Cybersecurity, Threat Detection, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security Operations Centre (SOC) experience, alert triage and escalation, SIEM usage, threat hunting, malware analysis, scripting for automation, knowledge of ATT&CK and kill-chain frameworks, incident response leadership
Preferred skills
Pen-testing, Red-team, Digital Forensics, Cyber Threat Intelligence, Cloud infrastructure (AWS/Azure/GCP), CI/CD pipelines, Containerisation, SANS certifications (GCIH, GMON, GCIA, GCFA)
Technologies
SIEM, SOAR, EDR, WAF, Network logs, OS logs, Malware analysis tools
Responsibilities
Review and evaluate severity of Cyber Security alerts; Create and push alert criteria for host and network intrusions to production; Mature detection rules and create automated tests/workflows; Identify gaps in logging/detection and suggest remediation; Participate in threat hunting and purple team engagements; Respond to incidents on the front lines; Engage with the broader Grab team to address security challenges
Seniority
Senior, hands-on IC with mentorship responsibilities