Closing Date : 31/12/2026

Section Head, Enterprise Cybersecurity Architect  

** For registered candidates, please login to apply

Life at U Mobile

We are Passionate, Innovative, Trustworthy, Team-Oriented & Fun-Loving.

At U Mobile, we are always on the lookout for great talents and passionate individuals to join our growing team.
Let’s start your journey with an award-winning organization!

#UnbeatableCareerAwaits

Top Reasons To Join Us!
•  Awarded For
    o Most Preferred Employers in Telecommunication Industry (2022, 2023 & 2024)
    o Bronze Winner in Cross-Generational Workforce Engagement (2024)
    o Gold Winner for Excellence in Workplace Culture (2021)
•  Comprehensive medical, dental, optical and insurance benefits
•  Flexi working hours arrangements
•  Staff Line & Device Subsidy
•  Smart Casual Attire
•  Child Parental Care Leave
•  Convenient location with access to public transport (Imbi Monorail/Bukit Bintang MRT)
•  Special employee discounts for selected F&B Brands

Job Summary
Lead U Mobile’s enterprise cybersecurity architecture function, setting the security direction, standards and long-term roadmap across IT, telecommunications networks, cloud, applications, data, digital platforms and emerging technologies. You will ensure security is built into technology initiatives from design through implementation, advise senior leaders on security risks and decisions, lead major security transformation initiatives, oversee vendors, and develop the cybersecurity architecture team.

The Day-to-Day Activities


Cybersecurity Strategy and Roadmap

  • Lead and maintain U Mobile’s enterprise cybersecurity architecture strategy, standards and multi-year roadmap in line with business, technology and network priorities.
  • Turn cybersecurity risks, threats, regulatory requirements and technology trends into prioritised initiatives and investment proposals.
  • Define future security capabilities, transition plans, dependencies and priorities for security transformation.
  • Advise senior management and technology leaders on key security architecture risks, options and decisions.

Security Architecture and Governance

  • Lead security architecture reviews for major IT, network, cloud, application, data, AI, digital, SaaS and third-party initiatives.
  • Establish and maintain security architecture principles, standards, design patterns and control requirements.
  • Review solution designs, data flows, integrations and proposals, providing clear security requirements and approval conditions.
  • Ensure key security principles, including secure-by-design, zero trust, least privilege, segmentation, encryption, resilience, monitoring and privacy, are applied throughout the technology lifecycle.
  • Maintain clear records of architecture decisions, exceptions, alternative controls and accepted risks for governance and audit purposes.

Enterprise and Telecommunications Security
  • Oversee security architecture across enterprise IT, cloud and on-premises infrastructure, identity, endpoints, networks, applications, APIs, databases and data platforms.
  • Provide security architecture direction for telecommunications environments, including RAN, transport, packet core, OSS/BSS, signalling, interconnect and virtualised or cloud-based network functions.
  • Define appropriate security approaches for access control, privileged access, system protection, APIs, encryption keys, logging, detection and recovery.
  • Ensure security controls consider availability, performance, scalability, operational needs and vendor support requirements.

Cloud, Application, Data and AI Security
  • Set security architecture requirements for cloud environments, containers, Kubernetes, software development and deployment processes, application security and software supply chains.
  • Guide identity and data security controls covering access management, privileged access, secrets, encryption, tokenisation, data loss prevention, data classification and secure information exchange.
  • Define security requirements for enterprise and generative AI, AI agents, model access, prompts and data, integrations, monitoring and third-party AI services.
  • Promote automated security controls and testing across applications, infrastructure and cloud environments.

Cybersecurity Risk, Compliance and Assurance
  • Translate applicable regulatory, industry and internal requirements into practical security architecture controls.
  • Lead security design risk assessments for critical systems, major changes, new technologies, acquisitions, outsourcing arrangements and security exceptions.
  • Confirm required controls are implemented and effective before go-live, with unresolved risks formally addressed, accepted or escalated.
  • Support audits, regulatory engagements and management assurance through complete architecture records, control mapping and remediation tracking.

Security Technology and Transformation
  • Lead technical assessments, proof-of-concept activities, testing and recommendations for cybersecurity platforms and strategic solutions.
  • Define solution requirements, evaluation criteria, integration needs and acceptance conditions.
  • Provide architecture leadership for major cybersecurity programmes, resolving design issues, dependencies and implementation risks.
  • Ensure solutions can be effectively supported after implementation, with clear ownership, monitoring, procedures and control evidence.

Stakeholder, Vendor and Financial Management
  • Partner with Architecture, IT, Network, Cloud, Application, Data, Digital, Procurement, Legal, Risk, Audit and business teams.
  • Influence senior stakeholders and technical teams to adopt appropriate security controls while supporting operational needs.
  • Hold vendors, service providers and technology partners accountable for agreed architecture, security and contractual deliverables.
  • Contribute to CAPEX and OPEX planning, business cases, prioritisation and benefits tracking for security architecture initiatives.

People Leadership and Capability Development
  • Lead, coach and develop cybersecurity architects and specialists, including objective setting, performance management and succession planning.
  • Establish consistent architecture review methods, templates, knowledge resources and quality standards.
  • Build internal capability through mentoring, technical knowledge sharing and targeted development.
  • Promote accountability, continuous learning and practical, risk-based decision-making.

Reporting and Continuous Improvement
  • Provide management reporting on architecture coverage, design risks, exceptions, roadmap progress, technical debt and remediation.
  • Monitor emerging threats, technology developments and lessons from incidents to improve security standards and priorities.
  • Assess security architecture maturity and recommend improvements based on identified gaps and business impact.

About You
  • Bachelor’s Degree in Cybersecurity, Information Security, Computer Science, Information Technology, Telecommunications, Engineering or a related field.
  • 12–15 years of relevant cybersecurity or information security experience, including at least 5 years in senior security architecture, security engineering or technical leadership.
  • Strong knowledge of enterprise security architecture, risk management, cloud and telecommunications security.
  • Proven experience developing enterprise security architecture and long-term security roadmaps in large, complex or regulated organisations.
  • Experience leading major security design reviews and transformation programmes across IT, networks, cloud, applications, identity, data and third parties.
  • Telecommunications security experience, including areas such as OSS/BSS, core networks, RAN, signalling, interconnect or virtualised network functions, is strongly preferred.
  • Able to communicate security risks, investment options and architecture decisions effectively to senior leaders and governance forums.
  • Experienced in leading people, vendors and delivery partners, managing budgets and balancing multiple priorities.
  • Able to make sound, risk-based decisions, influence stakeholders and translate complex security requirements into practical outcomes.
  • Strong communicator and collaborative leader with sound technical judgement, integrity and a continuous improvement mindset.
  • Preferred certifications include CISSP, CISM, CCSP, CRISC, SABSA, TOGAF or ISO/IEC 27001 Lead Implementer/Lead Auditor. Relevant cloud, network, telecommunications, application security or architecture certifications are an advantage.
#LI-NE1

  Min. Education:  Bachelor's Degree

  Industry:  IT / Science & Technology,TELCO

  Spoken Language:  Malay, English

  Written Language:  Malay, English

What’s Next ?
Once you have applied online, our team will review your application and due to a high volume of applications, only shortlisted candidates will be notified.