Job Summary
The Senior Specialist, Information Security provides cybersecurity advisory, solution design, governance, risk assessment and project coordination across U Mobile. The role works with business and technology teams to embed appropriate security controls throughout project implementation while supporting regulatory and internal security requirements.
The Day-to-Day ActivitiesSecurity Solution Design & Advisory
- Provide cybersecurity advisory for new systems, applications, infrastructure, cloud, network, SaaS, AI and digital transformation initiatives.
- Review high-level designs, low-level designs, architecture diagrams, data flows, security requirements and vendor solution proposals.
- Advise project teams on secure-by-design, defence-in-depth, least privilege, segmentation, logging, monitoring, encryption and data protection controls.
- Recommend appropriate preventive, detective and corrective controls, including compensating controls where standard controls cannot be fully implemented.
- Support proof-of-concept assessments and technical evaluation of cybersecurity solutions.
Security Architecture & Control Assurance
Governance, Risk & Compliance Support
- Interpret and translate security standards and regulatory expectations into practical control requirements for projects and technology teams.
- Support alignment with MCMC INSG, NACSA CoP, Cyber Security Act 2024, ISO/IEC 27001:2022, NIST CSF, PDPA, CIS Controls and PCI DSS where applicable.
- Perform cybersecurity risk assessments for projects, systems, vendors, technology changes and security exceptions.
- Support cybersecurity risk register updates, risk treatment plans, risk acceptance reviews and management reporting.
- Assist in internal audits, regulatory reviews, control validation, evidence preparation and remediation tracking.
Cybersecurity Project Management
- Lead or coordinate cybersecurity initiatives, workstreams and improvement activities assigned by Information Security management.
- Develop project plans, milestones, dependency trackers, action logs, risk logs and status updates.
- Coordinate internal stakeholders, vendors and technical teams to ensure timely delivery of cybersecurity deliverables.
- Escalate risks, issues, delays and resource constraints to management in a timely manner.
- Prepare management updates, dashboards, steering committee materials and closure reports for cybersecurity initiatives.
Vendor, Third-Party & Technology Assessment
- Review vendor security questionnaires, due diligence responses, solution proposals, contracts and exception requests from a security perspective.
- Assess third-party security risks and recommend required security controls, remediation actions or risk treatment options.
- Support procurement and project teams in evaluating the security suitability of new technology solutions and managed services.
Documentation, Reporting & Stakeholder Engagement
- Prepare clear security assessment reports, advisory notes, risk summaries, decision papers and management presentations.
- Communicate security requirements to technical and non-technical stakeholders in a practical and business-aligned manner.
- Conduct briefing or awareness sessions on security-by-design, project security requirements and compliance expectations when required.
- Maintain organised evidence, review records and documentation to support auditability and traceability.