Information Security Specialist

Singtel

Kuala Lumpur

On-site

Confidential

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Singtel is seeking an Information Security Specialist to provide security architecture risk and cloud compliance assurance across technology initiatives. You will help identify and manage risks, advise on security for cloud deployments and ensure adherence to policies and governance.

You will collaborate with IT, telco networks and enterprise stakeholders to implement Zero Trust principles, secure-by-design practices and risk-based mitigations across complex environments.

Qualifications

  • Degree or Diploma in Information Technology, Computer Science, Engineering or a related field.
  • At least 4 years of experience in security assessment, cybersecurity or related IT roles.
  • Hands-on experience in system and security administration, implementation or solution design across applications, infrastructure, telco networks, cloud and cybersecurity technologies.
  • Knowledge of cloud security technologies and practices, including CNAPP, DevSecOps and containers.
  • Ability to apply Zero Trust security architecture principles such as defence-in-depth, least privilege and secure-by-design.
  • Experience in cybersecurity risk assessment and risk reduction initiatives.
  • Knowledge of regulatory requirements, security standards and best practices relating to cybersecurity and cloud risk management.
  • Experience in system integrator or consulting environments, including exposure to multi-client or complex delivery engagements, is an advantage.
  • Professional security certifications such as CISSP, CCSP or similar credentials are preferred.
  • Strong analytical, problem-solving, time management, prioritisation, conflict management and negotiation skills.
  • Ability to work independently with minimal supervision, including with remote stakeholders, while exercising sound judgement, accountability and initiative.
  • Resilience, adaptability and a continuous-improvement mindset in changing environments.

Responsibilities

  • Security Risk Assessment & Assurance: Support comprehensive information security risk assessments for new and existing systems, applications, infrastructure changes and cloud engagements.
  • Assess design documents, architecture diagrams and technical controls to confirm that technology risks are mitigated prior to go-live.
  • Ensure technology initiatives and controls comply with internal security policies, standards and governance requirements, proactively highlighting gaps and recommending remediation.
  • Articulate and document residual risk assessments and define appropriate compensating controls for identified risks.
  • Cloud Security & Compliance: Review security-related configurations in cloud environments using industry tools and work with application teams to remediate insecure configurations.
  • Drive governance oversight and processes for cloud security compliance, best practices and risk management.
  • Support management reporting of cloud security risks, remediation plans and security metrics.
  • Apply cybersecurity and cloud risk management requirements, security standards and recognised best practices across technology initiatives.
  • Security Architecture & Advisory: Collaborate with IT, application teams and business stakeholders to provide risk advisory for projects and ad hoc reviews.
  • Apply Zero Trust security architecture principles, including defence-in-depth, least privilege and secure-by-design, in complex enterprise environments.
  • Evaluate architecture and technology decisions, identify control gaps and recommend risk-based mitigations.
  • Translate technical security issues into clear business and risk implications to support informed stakeholder and management decisions.
  • Technology Security & Remediation: Work with application and technology teams to identify and remediate security weaknesses across applications, infrastructure, telco networks and cloud environments.
  • Support security administration, implementation and solution design activities across relevant technology domains.
  • Contribute to cybersecurity risk assessment and risk reduction initiatives, including cloud-native environments and related security technologies.
  • Support secure implementation practices across technologies such as CNAPP, DevSecOps and containers where applicable.
  • Governance, Reporting & Continuous Improvement: Support consistent cloud security governance and risk management practices across projects and operational environments.
  • Provide clear security metrics, risk reporting and remediation status updates to support management oversight.
  • Keep current with evolving cybersecurity threats, regulatory requirements and security best practices relevant to cloud and telecommunications environments.
  • Contribute to continuous improvement of security processes, controls and ways of working.

Skills

Security risk assessment
Cloud security
Zero Trust
DevSecOps
Containers
Regulatory compliance
Risk management
Stakeholder communication

Education

Degree or Diploma in IT/CS/Engineering

Tools

CISSP
CCSP
CNAPP

Job description

Be a part of something BIG!

Say HELLO to BIG Possibilities with Singtel!

Singtel is Asia's leading communications technology group, driven by innovation, digital transformation and the use of technology to create a more sustainable and connected future.

We are looking for an Information Security Specialist to provide security architecture risk and cloud compliance assurance across technology initiatives. In this role, you will help ensure security risks are identified early, assessed consistently and managed effectively throughout the system lifecycle. You will act as a security risk and cloud security advisor to Singtel IT, Telco Networks and Enterprise stakeholders, supporting secure delivery while strengthening cloud security compliance and risk management.

Make an Impact by:
1. Security Risk Assessment & Assurance
  • Support comprehensive information security risk assessments for new and existing systems, applications, infrastructure changes and cloud engagements.
  • Assess design documents, architecture diagrams and technical controls to confirm that technology risks are mitigated prior to go-live.
  • Ensure technology initiatives and controls comply with internal security policies, standards and governance requirements, proactively highlighting gaps and recommending remediation.
  • Articulate and document residual risk assessments and define appropriate compensating controls for identified risks.
2. Cloud Security & Compliance
  • Review security-related configurations in cloud environments using industry tools and work with application teams to remediate insecure configurations.
  • Drive governance oversight and processes for cloud security compliance, best practices and risk management.
  • Support management reporting of cloud security risks, remediation plans and security metrics.
  • Apply cybersecurity and cloud risk management requirements, security standards and recognised best practices across technology initiatives.
3. Security Architecture & Advisory
  • Collaborate with IT, application teams and business stakeholders to provide risk advisory for projects and ad hoc reviews.
  • Apply Zero Trust security architecture principles, including defence-in-depth, least privilege and secure-by-design, in complex enterprise environments.
  • Evaluate architecture and technology decisions, identify control gaps and recommend risk-based mitigations.
  • Translate technical security issues into clear business and risk implications to support informed stakeholder and management decisions.
4. Technology Security & Remediation
  • Work with application and technology teams to identify and remediate security weaknesses across applications, infrastructure, telco networks and cloud environments.
  • Support security administration, implementation and solution design activities across relevant technology domains.
  • Contribute to cybersecurity risk assessment and risk reduction initiatives, including cloud-native environments and related security technologies.
  • Support secure implementation practices across technologies such as CNAPP, DevSecOps and containers where applicable.
5. Governance, Reporting & Continuous Improvement
  • Support consistent cloud security governance and risk management practices across projects and operational environments.
  • Provide clear security metrics, risk reporting and remediation status updates to support management oversight.
  • Keep current with evolving cybersecurity threats, regulatory requirements and security best practices relevant to cloud and telecommunications environments.
  • Contribute to continuous improvement of security processes, controls and ways of working.
Skills for Success
  • Degree or Diploma in Information Technology, Computer Science, Engineering or a related field.
  • At least 4 years of experience in security assessment, cybersecurity or related IT roles.
  • Hands-on experience in system and security administration, implementation or solution design across applications, infrastructure, telco networks, cloud and cybersecurity technologies.
  • Knowledge of cloud security technologies and practices, including CNAPP, DevSecOps and containers.
  • Ability to apply Zero Trust security architecture principles such as defence-in-depth, least privilege and secure-by-design.
  • Experience in cybersecurity risk assessment and risk reduction initiatives.
  • Knowledge of regulatory requirements, security standards and best practices relating to cybersecurity and cloud risk management.
  • Experience in system integrator or consulting environments, including exposure to multi-client or complex delivery engagements, is an advantage.
  • Professional security certifications such as CISSP, CCSP or similar credentials are preferred.
  • Strong analytical, problem-solving, time management, prioritisation, conflict management and negotiation skills.
  • Ability to work independently with minimal supervision, including with remote stakeholders, while exercising sound judgement, accountability and initiative.
  • Resilience, adaptability and a continuous-improvement mindset in changing environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

Singtel Group • Kampung Kual

On-site
Confidential
Information Security Specialist
Information Security Specialist

Singapore Telecommunications Limited • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Security Specialist
Information Security Specialist

Singtel Group • Kuala Lumpur

On-site
MYR 89,000 - 134,000
Senior Information Security Specialist
Senior Information Security Specialist

Singtel • Kuala Lumpur

On-site
Confidential
Senior Information Security Specialist
Senior Information Security Specialist

Singtel Group • Kampung Kual

On-site
Confidential
Senior Information Security Specialist
Senior Information Security Specialist

Singtel Group • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Senior Information Security Specialist
Senior Information Security Specialist

Singapore Telecommunications Limited • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Cloud Security Architect & Risk Advisor
Cloud Security Architect & Risk Advisor

Singtel • Kuala Lumpur

On-site
Confidential
Cloud Security Architect & Risk Advisor
Cloud Security Architect & Risk Advisor

Singapore Telecommunications Limited • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Architect: Cloud Risk & Compliance Advisor
Security Architect: Cloud Risk & Compliance Advisor

Singtel Group • Kampung Kual

On-site
Confidential