Senior DevSecOps Engineer

Petaling Jaya, Malaysia

Applications have closed

Grab

Grab is Southeast Asia’s leading superapp. It provides everyday services like Deliveries, Mobility, Financial Services, and More.

View all jobs at Grab

Company Description

About Grab and Our Workplace

Grab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence while harnessing the power of Technology and AI to deliver the mission of driving Southeast Asia forward by economically empowering everyone, with heart, hunger, honour, and humility.

Job Description

Get to know the team

The DevSecOps team at Grab is dedicated to integrating security practices into our development and operations processes. With a focus on ensuring the security and reliability of our services, we aim to stay ahead of latest threats and protect our users' data.

Get to know the role

We are looking for an experienced Senior DevSecOps Engineer to join our dynamic team in a hybrid working arrangement. You will report to our Senior DevSecOps Engineering Manager and will have a background in DevSecOps tools, application security, and automation. As a Senior DevSecOps Engineer, you will help architect secure DevOps practices across our organization, collaborating with team members in a hybrid setup.

The Critical Tasks You Will Perform

  • You will implement and maintain DevSecOps tools such as Static Security Testing, Dynamic security Testing, Dependency scanning solutions and Supply Chain Security.
  • You will develop and automate security processes using Python and Go Lang to enhance efficiency and scalability.
  • You will collaborate with cross-functional teams to integrate security into the software development lifecycle (SDLC) and CI/CD pipelines.
  • You will provide expertise and guidance on application security best practices and help implement secure coding standards.
  • You will conduct security assessments, vulnerability scanning, and penetration testing to identify and fix security vulnerabilities.
  • You will stay up to date with latest security threats, industry trends, and best practices in DevSecOps.

Qualifications

What Essential Skills You Will Need

  • At least 5 years of security industry experience using web/mobile application security and knowledge of the security / threat landscape.
  • Experience with DevSecOps practices, including the implementation and management of DevSecOps tools such as GIT, SAST, DAST, Secret Scanning, and dependency scanning solutions.
  • In-depth knowledge of application security principles, common vulnerabilities, and secure coding practices. Excellent knowledge of pen-testing tools and procedures for Web/Mobile.
  • Experienced in vulnerability management, patching automation, and understanding of VA/PT techniques
  • Programming skills in one of the languages (preferably Golang or Python)
  • Experience with containerization technologies (e.g., Docker, Kubernetes) and cloud platforms (e.g., AWS, Azure, GCP).
  • Demonstrated proficiency in setting up and managing CI/CD pipelines in platforms such as GitLab and Jenkins.

Additional Information

Life at Grab

We care about your well-being at Grab, here are some of the global benefits we offer:

  • We have your back with Term Life Insurance and comprehensive Medical Insurance.
  • With GrabFlex, create a benefits package that suits your needs and aspirations.
  • Celebrate moments that matter in life with loved ones through Parental and Birthday leave, and give back to your communities through Love-all-Serve-all (LASA) volunteering leave
  • We have a confidential Grabber Assistance Programme to guide and uplift you and your loved ones through life's challenges.

What we stand for at Grab

We are committed to building an inclusive and equitable workplace that enables diverse Grabbers to grow and perform at their best. As an equal opportunity employer, we consider all candidates fairly and equally regardless of nationality, ethnicity, religion, age, gender identity, sexual orientation, family commitments, physical and mental impairments or disabilities, and other attributes that make them unique.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index πŸ’°

Job stats:  1  0  0

Tags: Application security Automation AWS Azure CI/CD Cloud DAST DevOps DevSecOps Docker GCP GitLab Golang Jenkins Kubernetes Pentesting Python SAST SDLC Security assessment Vulnerabilities Vulnerability management

Perks/benefits: Career development Medical leave Parental leave

Region: Asia/Pacific
Country: Malaysia

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.