Senior Information Security Specialist
Date: 17 Sept 2026
Location: Kuala Lumpur, Malaysia
Company: Singtel Group
Be a part of something BIG!
Say HELLO to BIG Possibilities with Singtel!
Singtel is Asia's leading communications technology group, driven by innovation, digital transformation and the use of technology to create a more sustainable and connected future.
We are looking for a Senior Information Security Specialist to provide independent security architecture and risk assurance across technology initiatives. In this role, you will help identify information security risks early, assess them consistently and ensure they are managed effectively throughout the system lifecycle. You will act as a trusted security risk and architecture advisor to Singtel IT, Telco Networks and Enterprise stakeholders, supporting secure and timely delivery while strengthening the organisation's overall security posture.
Make an Impact by:
1. Security Risk Assessment & Assurance
• Perform comprehensive information security risk assessments for new and existing systems, applications, infrastructure changes and third-party engagements.
• Assess design documents, architecture diagrams and technical controls to confirm that technology risks are identified and mitigated before go-live.
• Articulate and document residual risks, define appropriate compensating controls and support formal risk acceptance where required.
• Conduct project security reviews and provide security sign-off within the role's delegated authority.
2. Security Architecture & Control Design
• Review and validate security control designs across IT infrastructure, cloud environments, network security, identity and access management, data protection and application security.
• Apply recognised security frameworks and Zero Trust architecture principles to evaluate design decisions and recommend risk-based mitigations.
• Define, review and promote secure architecture and security design patterns that enable consistent, scalable and risk-aligned controls.
• Validate systems and solution designs against security and compliance baselines, identify gaps and recommend appropriate remediation measures.
3. Threat Modelling & Security Advisory
• Conduct threat modelling for critical systems and application deployments, identifying attack paths, threat scenarios and control weaknesses.
• Provide risk advisory to IT, application teams and business stakeholders for projects, solution reviews and ad hoc security assessments.
• Translate technical security issues into clear business and risk implications to support informed decision-making.
• Guide application and technology teams on security requirements and recommended controls.
4. Governance, Compliance & Continuous Improvement
• Ensure technology initiatives and controls comply with internal security policies, standards and governance requirements, proactively highlighting gaps and recommending remediation.
• Drive continuous improvement of security risk assessment and design review frameworks, processes and templates to improve consistency, quality and efficiency.
• Interpret security baselines and standards and translate them into appropriate architecture and control requirements aligned with regulatory, enterprise and technology contexts.
• Stay current with evolving cybersecurity threats and regulatory changes relevant to the telecommunications environment.
5. Emerging Risk & Security Control Enhancement
• Recommend new or enhanced security controls and architecture patterns based on emerging threats, risk assessment outcomes, regulatory changes and industry best practices.
• Work with stakeholders to support implementation of agreed security improvements and risk treatments.
• Collaborate across complex technology environments to obtain accurate system information, identify relevant stakeholders and build a complete understanding of system architectures.
• Escalate open residual risks and project-related security issues to the appropriate management and governance forums when required.
Skills for Success
• Degree or Diploma in Information Technology, Computer Science, Engineering or a related field.
• At least 6 years of experience in security assessment, cybersecurity or related IT roles.
• Experience in systems security, network security, identity and access management or virtualisation security.
• Strong capability in threat modelling and technology risk assessment, including evaluation of control effectiveness and recommendation of risk mitigation strategies.
• Ability to apply Zero Trust security architecture principles in complex enterprise environments.
• Strong ability to interpret security baselines and standards and translate them into practical architecture and control requirements.
• Experience validating system and solution designs against security and compliance requirements and recommending remediation for identified gaps.
• Experience in system integrator or consulting environments, including multi-client or complex delivery engagements, is an advantage.
• Hands-on experience in system and security administration, implementation and solution design across servers, applications or telco networks is useful.
• Professional security certifications such as CISSP, CISM or similar credentials are preferred.
• Strong analytical, problem-solving, time management, prioritisation, negotiation and stakeholder communication skills.
• Ability to work independently with minimal supervision, including with remote stakeholders, while exercising sound judgement, accountability and initiative.
Your Career Growth Starts Here. Apply Now!