

Technology-Software
This role is for a Senior Technical Security Specialist based in the APAC region. The position involves designing secure IT systems, collaborating with diverse teams, and addressing cybersecurity threats while ensuring compliance with relevant standards.
The role is responsible for ensuring that IT systems and projects undergoing change are secure by design, build, and implementation. The ideal candidate will embed security principles throughout the project lifecycle to ensure compliance with organizational Global Information Security policies, industry standards, and regulatory requirements. This position requires collaboration with cross-functional teams to deliver secure IT solutions, leveraging expertise in security architecture, risk management, and secure development practices.
Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
7+ years of experience in information security, with a focus on secure design, architecture, and implementation.
Strong knowledge of security frameworks and standards (e.g., ISO 27001, NIST, PCI DSS, OWASP).
Experience conducting threat modeling, risk assessments, and security reviews.
Proficiency in secure development practices, including secure coding, encryption, and vulnerability management.
Familiarity with IT change management processes and governance frameworks.
Strong analytical and problem-solving skills, with the ability to assess complex technical environments.
Excellent communication and interpersonal skills, with the ability to influence and collaborate with diverse stakeholders.
Relevant certifications such as CISSP, CISM, CEH, or SABSA.
Experience with cloud security (e.g., AWS, Azure, GCP) and DevSecOps practices.
Experience working in Agile or DevOps environments.
Company
Chubb
Location
Kuala Lumpur
Salary
Undisclosed
Skills Required
6 skills
Click to submit your application
Information Security Security Architecture Risk Management Threat Modeling Secure Development Practices Security Frameworks (ISO 27001
NIST
PCI DSS
OWASP) Cloud Security (AWS
Azure
GCP) Devsecops Analytical Skills Communication