Senior Specialist, IT Security (Projects)

U Mobile

Kuala Lumpur

On-site

MYR 150,000 - 230,000

Full time

32 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexi working hours arrangements
Staff Line & Device Subsidy

Job summary

U Mobile is seeking a Senior Specialist, Information Security to provide cybersecurity advisory, governance, risk assessment and project coordination across the organization. You will work with business and technology teams to embed security controls throughout project implementation and support regulatory requirements.

The role demands 7–10 years in cybersecurity, plus at least 3 years in security review or advisory, with strong ability to translate standards into practical guidance for

Qualifications

  • Bachelor’s degree in Information Security or related field.
  • 7–10 years in cybersecurity with at least 3 years in security review or advisory.
  • Experience coordinating cybersecurity initiatives, audits, regulatory reviews.
  • Ability to translate security standards/regulations into practical implementation guidance.
  • Strong communication to technical and non-technical stakeholders.

Responsibilities

  • Provide cybersecurity advisory for new systems, cloud, AI, and digital initiatives.
  • Review high-/low-level designs, data flows, and vendor proposals for security.
  • Lead or coordinate cybersecurity projects and track milestones.
  • Prepare management dashboards, risk reports and audit evidence.
  • Engage with vendors to assess security requirements and controls.

Skills

Security architecture
Security advisory
Risk assessment
Regulatory compliance
Project management
Vendor management
Stakeholder communication

Education

Bachelor's Degree in Information Security / IT

Tools

Security assessment tools
Threat modeling software

Job description

Life at U Mobile

We are Passionate, Innovative, Trustworthy, Team-Oriented & Fun-Loving.

At U Mobile, we are always on the lookout for great talents and passionate individuals to join our growing team.

Let’s start your journey with an award-winning organization!

#UnbeatableCareerAwaits

Top Reasons To Join Us!
  • Awarded For
  • Most Preferred Employers in Telecommunication Industry (2022, 2023 & 2024)
  • Bronze Winner in Cross-Generational Workforce Engagement (2024)
  • Gold Winner for Excellence in Workplace Culture (2021)
  • Comprehensive medical, dental, optical and insurance benefits
  • Flexi working hours arrangements
  • Staff Line & Device Subsidy
  • Smart Casual Attire
  • Child Parental Care Leave
  • Convenient location with access to public transport (Imbi Monorail/Bukit Bintang MRT)
  • Special employee discounts for selected F&B Brands
Job Summary

The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.

Security Solution Design & Advisory
  • Provide cybersecurity advisory for new systems, applications, infrastructure, cloud, network, SaaS, AI and digital transformation initiatives.
  • Review high-level designs, low-level designs, architecture diagrams, data flows, security requirements and vendor solution proposals.
  • Advise project teams on secure-by-design, defence-in-depth, least privilege, segmentation, logging, monitoring, encryption and data protection controls.
  • Recommend appropriate preventive, detective and corrective controls, including compensating controls where standard controls cannot be fully implemented.
  • Support proof-of-concept assessments and technical evaluation of cybersecurity solutions.
Security Architecture & Control Assurance
  • Assess whether proposed solutions align with U Mobile security policies, standards, baseline requirements and approved architecture principles.
  • Identify security design gaps, control weaknesses, implementation risks and residual risks before production deployment.
  • Work with IT Operations, Network Division, Cloud, Application, Enterprise Architecture and vendors to ensure security requirements are properly implemented.
  • Maintain documentation for security review outcomes, control recommendations, risk decisions and advisory records.
Governance, Risk & Compliance Support
  • Interpret and translate security standards and regulatory expectations into practical control requirements for projects and technology teams.
  • Support alignment with MCMC INSG, NACSA CoP, Cyber Security Act 2024, ISO/IEC 27001:2022, NIST CSF, PDPA, CIS Controls and PCI DSS where applicable.
  • Perform cybersecurity risk assessments for projects, systems, vendors, technology changes and security exceptions.
  • Support cybersecurity risk register updates, risk treatment plans, risk acceptance reviews and management reporting.
  • Assist in internal audits, regulatory reviews, control validation, evidence preparation and remediation tracking.
Cybersecurity Project Management
  • Lead or coordinate cybersecurity initiatives, workstreams and improvement activities assigned by Information Security management.
  • Develop project plans, milestones, dependency trackers, action logs, risk logs and status updates.
  • Coordinate internal stakeholders, vendors and technical teams to ensure timely delivery of cybersecurity deliverables.
  • Escalate risks, issues, delays and resource constraints to management in a timely manner.
  • Prepare management updates, dashboards, steering committee materials and closure reports for cybersecurity initiatives.
Vendor, Third-Party & Technology Assessment
  • Review vendor security questionnaires, due diligence responses, solution proposals, contracts and exception requests from a security perspective.
  • Assess third-party security risks and recommend required security controls, remediation actions or risk treatment options.
  • Support procurement and project teams in evaluating the security suitability of new technology solutions and managed services.
Documentation, Reporting & Stakeholder Engagement
  • Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations.
  • Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner.
  • Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required.
  • Maintain organised evidence, review records and documentation to support auditability and traceability.
About You
  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Technology, Telecommunications, Engineering or a related discipline.
  • Minimum 7 to 10 years’ experience in cybersecurity, information security, IT security, security architecture, security engineering, IT GRC or technology risk management, including at least 3 years in security solution review, security advisory, project security assessment, control design or cybersecurity risk assessment.
  • Experience working with technology, network, application, cloud, infrastructure, vendor and business stakeholders, including audits, regulatory reviews, risk assessments, policy compliance or internal control validation.
  • Experience coordinating cybersecurity initiatives or technology security workstreams, with the ability to manage planning, tracking, dependencies, risks and stakeholder reporting.
  • Able to review solution designs, assess cybersecurity and residual risks, recommend practical controls and risk treatments, and translate security standards, regulatory requirements and internal policies into implementation guidance.
  • Able to communicate complex cybersecurity matters to technical and non-technical stakeholders and prepare structured reports, security review records, management updates and audit evidence.
  • Preferred certifications include CISSP, CISM, CRISC, CCSP, SABSA, ISO/IEC 27001 Lead Implementer or Lead Auditor; Microsoft Security, Azure Security Engineer, AWS Security Specialty, GIAC, CompTIA Security+, CySA+ or equivalent technical certification. PMP, PRINCE2, Agile Practitioner or ITIL Foundation is an advantage.

Min. Education: Bachelor's Degree

Industry: IT / Science & Technology,Other Industries,TELCO

Spoken Language: Malay, English

Written Language: Malay, English

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Specialist, IT Security (Projects)
Senior Specialist, IT Security (Projects)

U Mobile Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Medical, dental, optical and insurance
Flexible working hours
Device subsidy
+4
Section Head, Enterprise Cybersecurity Architect
Section Head, Enterprise Cybersecurity Architect

U Mobile • Kuala Lumpur

On-site
MYR 300,000 - 600,000
Comprehensive benefits
Flexi working hours
Staff line & device subsidy
+4
Specialist, IT Governance & Compliance
Specialist, IT Governance & Compliance

U Mobile • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Comprehensive medical, dental, optical
Insurance benefits
Flexi working hours
+5
Specialist, IT Governance & Compliance
Specialist, IT Governance & Compliance

U Mobile Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Comprehensive medical benefits
Dental & optical benefits
Insurance benefits
+6
Senior IT Security Project Lead
Senior IT Security Project Lead

U Mobile Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Medical, dental, optical and insurance
Flexible working hours
Device subsidy
+4
Senior Specialist, IP and Security Planning
Senior Specialist, IP and Security Planning

U Mobile • Kuala Lumpur

On-site
MYR 133,920 - 200,880
Comprehensive medical, dental, optical and insurance benefits
Flexi working hour arrangements
Child Parental Care Leave
+1
Senior Specialist, Data Governance & Enablement
Senior Specialist, Data Governance & Enablement

U Mobile • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Information Security Specialist
Senior Information Security Specialist

Singtel • Kuala Lumpur

On-site
Confidential
Senior Information Security Specialist
Senior Information Security Specialist

Singtel Group • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Information Security Specialist
Information Security Specialist

Singtel Group • Kuala Lumpur

On-site
MYR 89,000 - 134,000