Senior Information Security Specialist

5 hours ago


Kuala Lumpur, Kuala Lumpur, Malaysia Shopee Full time 120,000 - 200,000 per year

About The Team
As a Senior Information Security Specialist at ShopeePay & Monee Malaysia, you will play a key role in safeguarding our digital assets, information systems and data. You will leverage your extensive information security/cybersecurity experience to develop, implement and manage robust security strategies, policies, and controls. This role involves leading security risk assessments, providing expert technical guidance and overseeing the incident response process to maintain a strong security posture and ensure compliance with regulatory requirements.

Job Description
Security Strategy & Governance

  • Lead the development, implementation, and maintenance of a comprehensive information security framework, policies, procedures, and guidelines.
  • Ensure that the organization's security posture aligns with compliance requirements (e.g., NIST CSF, ISO 27001, BNM RMiT/MCIPD, Cyber Security Act, SC TRM, PDPA, SOC2/etc).
  • Review and endorse IT and Cybersecurity risk assessments, risk acceptances as well as technology Key Risk Indicators (KRI)
  • Provide information security guidance to business and cross-functional teams.
  • Coordinate and complete regulatory/compliance posture reporting for technology matters to the related management and Board committees.

Risk Management & Audits

  • Conduct holistic security risk assessments, audits, and gap analyses to identify gaps, vulnerabilities and potential threats to our systems and networks.
  • Oversee and conduct penetration testing, vulnerability scanning, and security architecture reviews.
  • Perform independent review / analysis of critical technology / cyber risks, and identify areas for improvement, e.g., network architectural design, Vulnerability Assessment and Penetration Testing (VAPT) findings.
  • Recommend and manage the implementation of effective remediation strategies to mitigate identified risks, tracking them through to resolution.

IT Incident Response, Disaster Recovery & Operations

  • Lead the information security incident response process, including investigation, containment, mitigation, and root cause analysis of security breaches and events.
  • Serve as a technical Subject Matter Expert (SME) during legal, regulatory, or corporate investigations, ensuring proper collection, preservation, and chain of custody for digital evidence.
  • Plan, lead, and report on regular, full-scale DR testing and simulation exercises, identifying gaps in the recovery procedures and working with infrastructure teams to remediate the gaps.
  • Provide security advice on integrating security requirements into the DR process, ensuring that data and systems recovered at the designated site.
  • Conduct Business Impact Analyses (BIA) and risk assessments from a security perspective to determine the criticality of systems and define appropriate Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
  • Prepare and submit detailed incident reports by translating complex technical jargon details into clear business risks and recommendation actions.

Collaboration & Communication

  • Collaborate with IT, Infrastructure, Engineering, Security and Development teams (DevSecOps) to integrate security best practices into the System Development Lifecycle (SDLC) and secure system architecture.
  • Provide expert technical advice and security requirements for new products, projects, systems, technologies and third party engagement.
  • Develop and deliver periodic security awareness training/learning programmes and communications to employees and stakeholders.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 5-7 years of direct experience in an Information Security or Cybersecurity role, with at least 3 years in a senior capacity.
  • Must possess relevant certifications in IT Risk and Cybersecurity in at least one of the following but not limited to:-

  • Certified in CyberSecurity (CC)

  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Other relevant cybersecurity certifications

  • Proven knowledge and experience in security architecture design, network security protocols, application security assessment, disaster recovery, cloud security and secure system design.

  • Proven experience in designing and implementing security controls within on-premise and cloud environments.
  • Hands-on proficiency with security tools and technologies (e.g., SIEM, DLP, IDS/IPS, EDR, APT, DDOS/etc).
  • Strong understanding of security governance, risk management, and regulation frameworks (e.g., NIST CSF, ISO 27001, BNM RMiT/MCIPD, Cyber Security Act, SC TRM, PDPA, SOC2/etc).
  • Exceptional analytical and problem-solving skills with a keen attention to detail.
  • Strong verbal and written communication skills, with the ability to explain complex security issues to both technical and non-technical audiences.
  • Demonstrated ability to lead projects, manage competing priorities, and drive continuous process improvement.
  • Experience with digital forensics and malware analysis.
  • Experience with scripting languages (e.g., Python, Bash, PowerShell) for security automation and task efficiency is a plus.
  • Able to cover Cybersecurity, IT and Business Continuity risks for both ShopeePay and Monee Malaysia.


  • Kuala Lumpur, Kuala Lumpur, Malaysia Shopee Mobile Malaysia Sdn Bhd Full time 120,000 - 180,000 per year

    The Compliance and Risk Management team ensures that Shopee complies with applicable regulations and is primed for success with the right checks and balances while safeguarding the interests of our stakeholders in an inclusive and sustainable digital ecosystem.The team manages potential risks to the company's operations and reputation through risk...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Zurich Insurance Full time

    Job DescriptionThe Information Security Specialist's role is to support the organization's identity and access management (IAM) program & services for APAC region with collaboration with other global regions. Candidates will need to be analytical, ethical, reflect professional attitude & passionate for learning.Administer & supervise users, accounts, and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TechLab Security Sdn Bhd Full time 120,000 - 180,000 per year

    Job SummaryWe are seeking an experienced Senior Cybersecurity Engineer to lead and manage daily Security Operations (SecOps) activities. The role involves hands-on management of endpoint security, firewalls, email security, and WAF, as well as leading cybersecurity enhancement projects across the organization.The ideal candidate is a technically strong and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Appnovation Full time 120,000 - 240,000 per year

    About UsAppnovation is a global, full-service digital partner that combines Strategy, Experience & Design, Engineering and Managed Services. We build digital solutions that deliver real impact today and serve as foundations for future growth. Bold ambition. Practical action. Endless possibilities.As a member of the IT team, the Sr. Associate, IT (Security)...


  • Kuala Lumpur, Kuala Lumpur, Malaysia EPS Consultants Full time

    Are you ahands-on Security Engineerwith a passion for protecting digital ecosystems and leading proactive defense strategies?We're looking for aSenior Specialist, Security Engineerto drive our endpoint protection, threat hunting, and security operations initiatives — ensuring our technology environment remains secure, resilient, and future-ready.What...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 120,000 - 180,000 per year

    PurposeAre you interested in spearheading cybersecurity excellence in a growth and diverse region? Chubb is seeking a seasoned Information Security Manager to lead our information security initiatives across multiple countries in the APAC region. This is a unique opportunity to make a significant impact by shaping the regional security culture and enabling...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Agensi Pekerjaan Randstad Sdn Bhd - Professional Full time 150,000 - 250,000 per year

    About the companyAn award-winning telecommunications leader is seeking a Senior Specialist for their IP Planning team in Kuala Lumpur.What You'll Do:Architect, design, and implement E2E 5G DN, Enterprise, Security, and Cloud solutions.Assist the pre-sales team in bidding efforts, from solution design to customer presentations.Govern the overall network...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Zurich Insurance Full time 50,000 - 100,000 per year

    Job Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:Manage identity services related to accounts, roles, and access...


  • Kuala Lumpur, Kuala Lumpur, Malaysia LiveWell Full time 90,000 - 120,000 per year

    Job Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:•    Manage identity services related to accounts, roles, and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per year

    DUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...