Senior Specialist, IT Security (Projects)

🗓️ Posted 2026-08-31 Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia Full-time Hybrid ICT

Company shared salary

NA

Market rate

RM8,000–RM15,000/mo (RM96,000–RM180,000/yr)

Based on similar roles (title + domain + location).

About the Company

We are Passionate, Innovative, Trustworthy, Team-Oriented & Fun-Loving. At U Mobile, we are always on the lookout for great talents and passionate individuals to join our growing team. Let's start your journey with an award-winning organization UnbeatableCareerAwaits Top Reasons To Join Us The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements. The Day-to-Day Activities Security Solution Design & Advisory Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations. Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner. Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required. Maintain organised evidence, review records and documentation to support auditability and traceability.

Requirements

  • Bachelor's Degree in Information Security, Cybersecurity, Computer Science, Information Technology, Telecommunications, Engineering or a related discipline.
  • Minimum 7 to 10 years' experience in cybersecurity, information security, IT security, security architecture, security engineering, IT GRC or technology risk management, including at least 3 years in security solution review, security advisory, project security assessment, control design or cybersecurity risk assessment.
  • Experience working with technology, network, application, cloud, infrastructure, vendor and business stakeholders, including audits, regulatory reviews, risk assessments, policy compliance or internal control validation.
  • Experience coordinating cybersecurity initiatives or technology security workstreams, with the ability to manage planning, tracking, dependencies, risks and stakeholder reporting.
  • Able to review solution designs, assess cybersecurity and residual risks, recommend practical controls and risk treatments, and translate security standards, regulatory requirements and internal policies into implementation guidance.
  • Able to communicate complex cybersecurity matters to technical and non-technical stakeholders and prepare structured reports, security review records, management updates and audit evidence.
  • Preferred certifications include CISSP, CISM, CRISC, CCSP, SABSA, ISO/IEC 27001 Lead Implementer or Lead Auditor; Microsoft Security, Azure Security Engineer, AWS Security Specialty, GIAC, CompTIA Security+, CySA+ or equivalent technical certification. PMP, PRINCE2, Agile Practitioner or ITIL Foundation is an advantage.