Senior Specialist, IT Security (Projects)
- Posted 9 hours ago
- Be among the first 10 applicants
Job Description
Life at U Mobile
We are Passionate, Innovative, Trustworthy, Team-Oriented & Fun-Loving.
At U Mobile, we are always on the lookout for great talents and passionate individuals to join our growing team.
Let's start your journey with an award-winning organization!
#UnbeatableCareerAwaits
Top Reasons To Join Us!
The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.
The Day-to-Day Activities
Security Solution Design & Advisory
Industry: IT / Science & Technology,Other Industries,TELCO
Spoken Language: Malay, English
Written Language: Malay, English
What's Next Once you have applied online, our team will review your application and due to a high volume of applications, only shortlisted candidates will be notified.
We are Passionate, Innovative, Trustworthy, Team-Oriented & Fun-Loving.
At U Mobile, we are always on the lookout for great talents and passionate individuals to join our growing team.
Let's start your journey with an award-winning organization!
#UnbeatableCareerAwaits
Top Reasons To Join Us!
- Awarded For
- Most Preferred Employers in Telecommunication Industry (2022, 2023 & 2024)
- Bronze Winner in Cross-Generational Workforce Engagement (2024)
- Gold Winner for Excellence in Workplace Culture (2021)
- Comprehensive medical, dental, optical and insurance benefits
- Flexi working hours arrangements
- Staff Line & Device Subsidy
- Smart Casual Attire
- Child Parental Care Leave
- Convenient location with access to public transport (Imbi Monorail/Bukit Bintang MRT)
- Special employee discounts for selected F&B Brands
The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.
The Day-to-Day Activities
Security Solution Design & Advisory
- Provide cybersecurity advisory for new systems, applications, infrastructure, cloud, network, SaaS, AI and digital transformation initiatives.
- Review high-level designs, low-level designs, architecture diagrams, data flows, security requirements and vendor solution proposals.
- Advise project teams on secure-by-design, defence-in-depth, least privilege, segmentation, logging, monitoring, encryption and data protection controls.
- Recommend appropriate preventive, detective and corrective controls, including compensating controls where standard controls cannot be fully implemented.
- Support proof-of-concept assessments and technical evaluation of cybersecurity solutions.
- Assess whether proposed solutions align with U Mobile security policies, standards, baseline requirements and approved architecture principles.
- Identify security design gaps, control weaknesses, implementation risks and residual risks before production deployment.
- Work with IT Operations, Network Division, Cloud, Application, Enterprise Architecture and vendors to ensure security requirements are properly implemented.
- Maintain documentation for security review outcomes, control recommendations, risk decisions and advisory records.
- Interpret and translate security standards and regulatory expectations into practical control requirements for projects and technology teams.
- Support alignment with MCMC INSG, NACSA CoP, Cyber Security Act 2024, ISO/IEC 27001:2022, NIST CSF, PDPA, CIS Controls and PCI DSS where applicable.
- Perform cybersecurity risk assessments for projects, systems, vendors, technology changes and security exceptions.
- Support cybersecurity risk register updates, risk treatment plans, risk acceptance reviews and management reporting.
- Assist in internal audits, regulatory reviews, control validation, evidence preparation and remediation tracking.
- Lead or coordinate cybersecurity initiatives, workstreams and improvement activities assigned by Information Security management.
- Develop project plans, milestones, dependency trackers, action logs, risk logs and status updates.
- Coordinate internal stakeholders, vendors and technical teams to ensure timely delivery of cybersecurity deliverables.
- Escalate risks, issues, delays and resource constraints to management in a timely manner.
- Prepare management updates, dashboards, steering committee materials and closure reports for cybersecurity initiatives.
- Review vendor security questionnaires, due diligence responses, solution proposals, contracts and exception requests from a security perspective.
- Assess third-party security risks and recommend required security controls, remediation actions or risk treatment options.
- Support procurement and project teams in evaluating the security suitability of new technology solutions and managed services.
- Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations.
- Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner.
- Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required.
- Maintain organised evidence, review records and documentation to support auditability and traceability.
- Bachelor's Degree in Information Security, Cybersecurity, Computer Science, Information Technology, Telecommunications, Engineering or a related discipline.
- Minimum 7 to 10 years experience in cybersecurity, information security, IT security, security architecture, security engineering, IT GRC or technology risk management, including at least 3 years in security solution review, security advisory, project security assessment, control design or cybersecurity risk assessment.
- Experience working with technology, network, application, cloud, infrastructure, vendor and business stakeholders, including audits, regulatory reviews, risk assessments, policy compliance or internal control validation.
- Experience coordinating cybersecurity initiatives or technology security workstreams, with the ability to manage planning, tracking, dependencies, risks and stakeholder reporting.
- Able to review solution designs, assess cybersecurity and residual risks, recommend practical controls and risk treatments, and translate security standards, regulatory requirements and internal policies into implementation guidance.
- Able to communicate complex cybersecurity matters to technical and non-technical stakeholders and prepare structured reports, security review records, management updates and audit evidence.
- Preferred certifications include CISSP, CISM, CRISC, CCSP, SABSA, ISO/IEC 27001 Lead Implementer or Lead Auditor; Microsoft Security, Azure Security Engineer, AWS Security Specialty, GIAC, CompTIA Security+, CySA+ or equivalent technical certification. PMP, PRINCE2, Agile Practitioner or ITIL Foundation is an advantage.
Industry: IT / Science & Technology,Other Industries,TELCO
Spoken Language: Malay, English
Written Language: Malay, English
What's Next Once you have applied online, our team will review your application and due to a high volume of applications, only shortlisted candidates will be notified.
More Info
Key Skills
NIST CSF
CIS Controls
cybersecurity risk assessment
security solution review
security advisory
project security assessment
ISO IEC 27001




