Back to job search
Sobeys Capital Incorporated logo

Senior Cyber Security Specialist

  • Calgary, AB
  • Hybrid
  • Posted Oct 10, 2026
  • 1 position

$102,000–$140,000 / year

Opens an external site

Sign in to save this job
Employment type
Full-time
Experience level
Senior · 5+ years
Apply by
Oct 27, 2026
Posting language
English
Working hours
40 hours per week

Job summary

The Senior Cyber Security Specialist will lead detection engineering and proactive threat hunting to improve security operations across retail and enterprise environments. This role involves building automation, managing SIEM/EDR content, and collaborating with SOC and IR teams to mitigate threats.

Job details

Embark on a rewarding career with Sobeys Inc., celebrated among Canada’s Top 100 employers where your unique contributions drive success. Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full time opportunity for a Senior Cyber Security Specialist. This role can be based out of one our main offices including: Stellarton, NS; Mississauga, ON. Calgary, AB, Burnaby, BC We’re seeking a Subject Matter Expert (SME) who will lead both detection engineering and proactive threat hunting to design, implement, and continuously improve our detection logic and hunt operations across retail and enterprise environments. The role blends advanced SIEM/EDR content engineering with hypothesis‑driven hunts and actionable threat intelligence to build a threat‑informed defense. Key Responsibilities Detection Engineering Design, author, and maintain high‑fidelity detection rules and behavioral analytics across SIEM/EDR (e.g., Azure Sentinel or Elastic Stack or Splunk SPL for detections and dashboards). Parse/normalize diverse log sources (POS systems, payment gateways, e‑commerce platforms, cloud services, and network devices) to ensure consistent, log data. Perform detection gap analysis, recommend architecture improvements, and document use cases in a detection content catalog/knowledge base. Threat Hunting & Threat Intelligence Lead hypothesis‑driven hunts using MITRE ATT&CK and behavioral analytics to uncover ransomware, data exfiltration, POS malware, supply‑chain compromises, card skimming, cloud misconfigurations, and insider fraud. Integrate curated threat intelligence (including retail‑focused actors such as FIN6 and current ransomware groups) into hunting and detection pipelines; produce actionable reports and executive briefings. Automation, SIEM/EDR Operations & Response Build automation to streamline alert triage and response; optimize SIEM dashboards and data models for retail‑specific visibility. Partner with IR/SOC to operationalize detections and hunts; track efficacy and continuously tune for false‑positive reduction. Collaboration & Leadership Collaborate closely with SOC, IR, and engineering teams; mentor junior analysts and lead knowledge‑sharing sessions. Communicate status, risks, and outcomes to stakeholders; drive threat‑informed risk assessments and posture improvements. Project & Program Management Own end‑to‑end delivery of detection and hunting initiatives (scope, timelines, resources, deliverables) aligned to compliance and business objectives. Qualifications & Requirements SIEM/EDR Expertise: Advanced Splunk SPL; hands‑on with SIEM (Splunk, QRadar) and EDR tools. Log Engineering: Proven experience normalizing/ingesting logs from POS, payment systems, e‑commerce, cloud, and network devices. Threat‑Informed Defense: Ability to operationalize threat intelligence and conduct ATT&CK‑aligned hunts. Cloud Security: Working knowledge of AWS, Azure, GCP in retail environments. Compliance & Privacy: Strong understanding of PCI DSS for payment security monitoring and familiarity with GDPR/CCPA. Scripting & Automation: Proficiency in Python and PowerShell for data parsing, enrichment, and workflow automation. Retail Threats & Fraud: Experience with ransomware, card‑skimming, insider fraud, loyalty‑program and e‑commerce fraud patterns. Preferred Certifications GIAC GCDA, GCIA, GCFA, GCTI; OSCP; PMP (or equivalent). #LI-Hybrid #LI-VJ1 What Success Looks Like (KPIs) Increased ATT&CK coverage and validated detections for priority TTPs. Reduced mean‑time‑to‑detect (MTTD) and false‑positive rates through tuning and automation. Regular delivery of high‑quality hunt reports, executive briefings, and detection content with measurable impact. Who we are Sobeys is one of Canada’s leading grocery retailers, with more than 1,600 stores across all 10 provinces and banners including Sobeys, Safeway, IGA, Foodland, FreshCo, Thrifty Foods, and Lawtons Drug Stores. Our 128,000 teammates and franchise affiliates are passionate about delivering great food and exceptional experiences to our customers and communities. Learn more about our story and culture: Who We Are | Why Work With Us Total Rewards We offer a Total Rewards package designed to support teammates at work and in life. Depending on role and eligibility, teammates may receive health and dental benefits, retirement and savings programs including an Employee Share Ownership Plan, a 10% in-store discount at participating banners, virtual healthcare and an Employee and Family Assistance Program, learning and development opportunities, parental leave top-up, and paid vacation. Sobeys is committed to providing a compensation structure that is flexible, equitable and competitive in the market to enable performance and growth. To learn more about this opportunity including the expected range of compensation in accordance with Pay Transparency Legislation where required please click the “I’m interested” or "Apply" button above. Individual compensation is determined based on qualifications, experience, and internal equity within the range provided. Additional Information External websites may share our organization's job postings which includes compensation information based on similar roles and market benchmarks. These figures are provided for general comparison purposes only and are not issued or verified by our organization. We may use Artificial Intelligence (AI) tools to support efficiencies in the candidate screening, assessment, and recruitment processes. These AI tools do not make hiring decisions on behalf of the Company. Hiring decisions are made by our Hiring Teams. Sobeys is committed to creating accessible and inclusive hiring processes. We will work with applicants requesting accommodation at any stage of the recruitment process. Please note: Successful candidates will be required to provide documentation to prove their legal ability to work in the position during the onboarding process. Documentation will be assessed by the employer prior to commencement of work.

What you’ll do

The Senior Cyber Security Specialist will lead detection engineering and proactive threat hunting to improve security operations across retail and enterprise environments. This role involves building automation, managing SIEM/EDR content, and collaborating with SOC and IR teams to mitigate threats.

Requirements

Candidates must possess advanced expertise in SIEM/EDR tools, log engineering, and threat-informed defense strategies. Proficiency in Python, PowerShell, and knowledge of retail-specific threats and compliance standards like PCI DSS are required.

Benefits

  • Health insurance
  • Dental benefits
  • Retirement and savings programs
  • Employee share ownership plan
  • In-store discount
  • Virtual healthcare
  • Employee and family assistance program
  • Learning and development opportunities
  • Parental leave top-up
  • Paid vacation

Listed skills

  • Splunk · Preferred
  • Python · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Detection engineering
  • Threat hunting
  • SIEM
  • EDR
  • Splunk
  • Azure Sentinel
  • Python
  • PowerShell
  • MITRE ATT&CK
  • Log normalization
  • Cloud security
  • PCI DSS
  • Threat intelligence
  • Automation
  • Behavioral analytics
  • Incident response
  • MITRE ATT&CK Framework
  • Cloud Services
  • Endpoint Detection And Response
  • GIAC Cyber Threat Intelligence
  • Cyber Threat Intelligence
  • Virtual Health
  • General Data Protection Regulation (GDPR)
  • Microsoft Sentinel
  • Business Objectives
  • IBM QRadar (SIEM Software)
  • Workflow Automation
  • Cyber Threat Hunting
  • Amazon Web Services
  • Build Automation
  • Microsoft Azure
  • Behavioral Analytics
  • Dashboard
  • Cloud Security
  • Content Engineering
  • Cyber Security
  • Data Modeling
  • Engineering Design Process
  • Payment Systems
  • Gap Analysis
  • GIAC Certified Forensics Analyst
  • GIAC Certified Intrusion Analyst
  • GIAC Certifications
  • Leadership
  • Python (Programming Language)
  • Key Performance Indicators (KPIs)
  • Operations
  • Offensive Security Certified Professional
  • Parsing
  • Payment Card Industry (PCI) Data Security Standards

Job areas

  • Security & Safety
  • Technology
  • Software
  • Data & Analytics
  • Retail
  • Cybersecurity Specialist
  • Cyber Security Specialist / Technician
  • Database and Network Professionals Not Elsewhere Classified
  • Information Security Analysts

More jobs from Sobeys Capital Incorporated

See all jobs from Sobeys Capital Incorporated