Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
You will conduct application-layer security assessments across Grab's services covering APIs, web, and mobile attack surfaces, producing findings that service teams can act on
You will evaluate findings from automated DAST scans against OWASP ASVS controls, triage true positives from false positives, and provide clear remediation guidance
You will investigate Grab's environments for indicators of compromise, anomalous behaviour, and attacker techniques that evade automated detection
...
A challenging and rewarding advisory environment with the opportunity to directly impact the resilience of prominent regional organizations.
About the Role:
We are seeking a results-oriented GRC & IT Security Audit Consultant to join our team. This role focuses entirely on the compliance, framework, and process controls side of IT Security. If you excel at designing risk strategies, leading compliance frameworks, and conducting comprehensive IT security audits, this position offers an excellent opportunity to manage client engagements with a high degree of autonomy.
...
Solution Advisory: Provide hands-on security architecture guidance to project delivery teams from project inception through post-implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high-severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root-Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
...
Solution Advisory: Provide hands-on security architecture guidance to project delivery teams from project inception through post-implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high-severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root-Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
...
Data Classification: Develop, implement and maintain sensitivity labels and auto-labelling policies to ensure data is classified correctly at the point of creation and to ensure data is "secure by design."
Incident Response: Lead the investigation of data leakage alerts. Ensure high‑quality, SLA‑compliant service delivery together with providers; serve as escalation point for operational issues.
Policy Tuning: Regularly review and "noise-cancel" DLP policies to reduce false positives while ensuring high-risk data egress is blocked.
...
Observe and participate (where possible) in vulnerability assessments and penetration testing activities.
Assist with incident response procedures under the guidance of senior engineers, potentially involving basic scripting for log analysis or remediation tasks.
Contribute to security documentation by keeping records and updating procedures as instructed.
...
Support customer engagement and solution selling by providing expert technical input during client meetings, proposal clarification, pre-sales discussions and service presentations.
Develop and maintain service methodologies, audit checklists, technical guidance, customer-facing materials and internal knowledge resources for Digital Trust service delivery.
Provide technical input for service expansion in areas such as information security, privacy, AI governance, industrial cybersecurity, business continuity, SOC 2, PCI DSS and TISAX.
...
Strategic Project & Budget Management: Expert in managing timeline, budget, deliverables and milestone for partnership projects
Analytical & Data-Driven: Committed to using deep-dive metrics and behavioral insights to solve complex problems and drive evidence-based decision-making.
Adaptable & Results-Oriented: Thrives in fast-paced, evolving environments, with a relentless focus on delivering measurable outcomes and continuous improvement with strong target ownership
...
Support customer engagement and solution selling by providing expert technical input during client meetings, proposal clarification, pre-sales discussions and service presentations.
Develop and maintain service methodologies, audit checklists, technical guidance, customer-facing materials and internal knowledge resources for Digital Trust service delivery.
Provide technical input for service expansion in areas such as information security, privacy, AI governance, industrial cybersecurity, business continuity, SOC 2, PCI DSS and TISAX.
...
Support customer engagement and solution selling by providing expert technical input during client meetings, proposal clarification, pre-sales discussions and service presentations.
Develop and maintain service methodologies, audit checklists, technical guidance, customer-facing materials and internal knowledge resources for Digital Trust service delivery.
Provide technical input for service expansion in areas such as information security, privacy, AI governance, industrial cybersecurity, business continuity, SOC 2, PCI DSS and TISAX.
...