Senior Specialist, IT Security (Projects)
U Mobile
Job Summary
The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.
The Day-to-Day Activities
Security Solution Design & Advisory
- Provide cybersecurity advisory for new systems, applications, infrastructure, cloud, network, SaaS, AI and digital transformation initiatives.
- Review high-level designs, low-level designs, architecture diagrams, data flows, security requirements and vendor solution proposals.
- Advise project teams on secure-by-design, defence-in-depth, least privilege, segmentation, logging, monitoring, encryption and data protection controls.
- Recommend appropriate preventive, detective and corrective controls, including compensating controls where standard controls cannot be fully implemented.
- Support proof-of-concept assessments and technical evaluation of cybersecurity solutions.
Security Architecture & Control Assurance
- Assess whether proposed solutions align with U Mobile security policies, standards, baseline requirements and approved architecture principles.
- Identify security design gaps, control weaknesses, implementation risks and residual risks before production deployment.
- Work with IT Operations, Network Division, Cloud, Application, Enterprise Architecture and vendors to ensure security requirements are properly implemented.
- Maintain documentation for security review outcomes, control recommendations, risk decisions and advisory records.
Governance, Risk & Compliance Support
- Interpret and translate security standards and regulatory expectations into practical control requirements for projects and technology teams.
- Support alignment with MCMC INSG, NACSA CoP, Cyber Security Act 2024, ISO/IEC 27001:2022, NIST CSF, PDPA, CIS Controls and PCI DSS where applicable.
- Perform cybersecurity risk assessments for projects, systems, vendors, technology changes and security exceptions.
- Support cybersecurity risk register updates, risk treatment plans, risk acceptance reviews and management reporting.
- Assist in internal audits, regulatory reviews, control validation, evidence preparation and remediation tracking.
Cybersecurity Project Management
- Lead or coordinate cybersecurity initiatives, workstreams and improvement activities assigned by Information Security management.
- Develop project plans, milestones, dependency trackers, action logs, risk logs and status updates.
- Coordinate internal stakeholders, vendors and technical teams to ensure timely delivery of cybersecurity deliverables.
- Escalate risks, issues, delays and resource constraints to management in a timely manner.
- Prepare management updates, dashboards, steering committee materials and closure reports for cybersecurity initiatives.
Vendor, Third-Party & Technology Assessment
- Review vendor security questionnaires, due diligence responses, solution proposals, contracts and exception requests from a security perspective.
- Assess third-party security risks and recommend required security controls, remediation actions or risk treatment options.
- Support procurement and project teams in evaluating the security suitability of new technology solutions and managed services.
Documentation, Reporting & Stakeholder Engagement
- Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations.
- Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner.
- Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required.
- Maintain organised evidence, review records and documentation to support auditability and traceability.
About You
- Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Technology, Telecommunications, Engineering or a related discipline.
- Minimum 7 to 10 years’ experience in cybersecurity, information security, IT security, security architecture, security engineering, IT GRC or technology risk management, including at least 3 years in security solution review, security advisory, project security assessment, control design or cybersecurity risk assessment.
- Experience working with technology, network, application, cloud, infrastructure, vendor and business stakeholders, including audits, regulatory reviews, risk assessments, policy compliance or internal control validation.
- Experience coordinating cybersecurity initiatives or technology security workstreams, with the ability to manage planning, tracking, dependencies, risks and stakeholder reporting.
- Able to review solution designs, assess cybersecurity and residual risks, recommend practical controls and risk treatments, and translate security standards, regulatory requirements and internal policies into implementation guidance.
- Able to communicate complex cybersecurity matters to technical and non-technical stakeholders and prepare structured reports, security review records, management updates and audit evidence.
- Preferred certifications include CISSP, CISM, CRISC, CCSP, SABSA, ISO/IEC 27001 Lead Implementer or Lead Auditor; Microsoft Security, Azure Security Engineer, AWS Security Specialty, GIAC, CompTIA Security+, CySA+ or equivalent technical certification. PMP, PRINCE2, Agile Practitioner or ITIL Foundation is an advantage.
Skills
- Cybersecurity
- Procurement
- Risk assessment
- Security engineering
- Solution architecture


