Routiqo

Senior Specialist, IT Security (Projects)

U Mobile

  • Kuala Lumpur
  • Full-time

Job Summary

The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.

The Day-to-Day Activities

Security Solution Design & Advisory

  • Provide cybersecurity advisory for new systems, applications, infrastructure, cloud, network, SaaS, AI and digital transformation initiatives.
  • Review high-level designs, low-level designs, architecture diagrams, data flows, security requirements and vendor solution proposals.
  • Advise project teams on secure-by-design, defence-in-depth, least privilege, segmentation, logging, monitoring, encryption and data protection controls.
  • Recommend appropriate preventive, detective and corrective controls, including compensating controls where standard controls cannot be fully implemented.
  • Support proof-of-concept assessments and technical evaluation of cybersecurity solutions.

Security Architecture & Control Assurance

  • Assess whether proposed solutions align with U Mobile security policies, standards, baseline requirements and approved architecture principles.
  • Identify security design gaps, control weaknesses, implementation risks and residual risks before production deployment.
  • Work with IT Operations, Network Division, Cloud, Application, Enterprise Architecture and vendors to ensure security requirements are properly implemented.
  • Maintain documentation for security review outcomes, control recommendations, risk decisions and advisory records.

Governance, Risk & Compliance Support

  • Interpret and translate security standards and regulatory expectations into practical control requirements for projects and technology teams.
  • Support alignment with MCMC INSG, NACSA CoP, Cyber Security Act 2024, ISO/IEC 27001:2022, NIST CSF, PDPA, CIS Controls and PCI DSS where applicable.
  • Perform cybersecurity risk assessments for projects, systems, vendors, technology changes and security exceptions.
  • Support cybersecurity risk register updates, risk treatment plans, risk acceptance reviews and management reporting.
  • Assist in internal audits, regulatory reviews, control validation, evidence preparation and remediation tracking.

Cybersecurity Project Management

  • Lead or coordinate cybersecurity initiatives, workstreams and improvement activities assigned by Information Security management.
  • Develop project plans, milestones, dependency trackers, action logs, risk logs and status updates.
  • Coordinate internal stakeholders, vendors and technical teams to ensure timely delivery of cybersecurity deliverables.
  • Escalate risks, issues, delays and resource constraints to management in a timely manner.
  • Prepare management updates, dashboards, steering committee materials and closure reports for cybersecurity initiatives.

Vendor, Third-Party & Technology Assessment

  • Review vendor security questionnaires, due diligence responses, solution proposals, contracts and exception requests from a security perspective.
  • Assess third-party security risks and recommend required security controls, remediation actions or risk treatment options.
  • Support procurement and project teams in evaluating the security suitability of new technology solutions and managed services.

Documentation, Reporting & Stakeholder Engagement

  • Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations.
  • Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner.
  • Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required.
  • Maintain organised evidence, review records and documentation to support auditability and traceability.

About You

  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Information Technology, Telecommunications, Engineering or a related discipline.
  • Minimum 7 to 10 years’ experience in cybersecurity, information security, IT security, security architecture, security engineering, IT GRC or technology risk management, including at least 3 years in security solution review, security advisory, project security assessment, control design or cybersecurity risk assessment.
  • Experience working with technology, network, application, cloud, infrastructure, vendor and business stakeholders, including audits, regulatory reviews, risk assessments, policy compliance or internal control validation.
  • Experience coordinating cybersecurity initiatives or technology security workstreams, with the ability to manage planning, tracking, dependencies, risks and stakeholder reporting.
  • Able to review solution designs, assess cybersecurity and residual risks, recommend practical controls and risk treatments, and translate security standards, regulatory requirements and internal policies into implementation guidance.
  • Able to communicate complex cybersecurity matters to technical and non-technical stakeholders and prepare structured reports, security review records, management updates and audit evidence.
  • Preferred certifications include CISSP, CISM, CRISC, CCSP, SABSA, ISO/IEC 27001 Lead Implementer or Lead Auditor; Microsoft Security, Azure Security Engineer, AWS Security Specialty, GIAC, CompTIA Security+, CySA+ or equivalent technical certification. PMP, PRINCE2, Agile Practitioner or ITIL Foundation is an advantage.

Skills

  • Cybersecurity
  • Procurement
  • Risk assessment
  • Security engineering
  • Solution architecture