Senior Identity Access Management IAM Specialist – CyberArk
Ready to Make an impact?
At Sobeys, making work meaningful is what we do. As we continue down the path of our digital transformation, we are looking for top talent who want to be part of this exciting journey. Our Cyber Security Team is looking for a seasoned team member who is passionate about Cyber Security and has experience taking SAP Roles Based Security to the next level. Watch our Director of Cyber Security, Angela Mathies, discuss our exciting work and why she chose Sobeys:
https://vimeo.com/696132783/f544c1efaa
You are a builder, influencer, and change agent
In this exciting role, you will be working alongside a team of high-performing Cyber Security professionals who are skilled and knowledgeable in all facets of Cyber Security and SAP. You will engage in Role Management such as updates related to role creation, maintenance, and design. From enterprise architecture to operational technology, you will help Sobeys continue to advance as the nationally recognized gold standard in grocery and pharmacy.
Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full-time opportunity for a Senior IAM Specialist. This role can be based out of one our main offices including: Stellarton, NS; Mississauga, ON, Calgary, AB.
Here’s where you’ll be focusing:
Sobeys Inc. is investing big in technology – Join us and invest in your future
We are on a journey to completely transform how we do business, and we offer a hybrid work model with the opportunity for additional flexibility. Join us and you’ll be working with:
- Leading tools and systems in our modern infrastructure.
- A data-driven culture.
- Strong, collaborative team of energetic and experienced security experts.
This is an outstanding opportunity to join a leading Canadian company with a clear vision of their future in Cyber Security. Are you ready to be part of this success story? #cyberatsobeys #DigitalatSobeys
#LI-Hybrid
#LI-VJ1
What you have to offer:
What you bring to the table:
- Act as the SME for all CyberArk technologies in both on-prem and SaaS environments.
- Design, deploy and manage CyberArk Secure Infrastructure Access (SIA) for secure, credential-less access to Linux, Windows and Databases across hybrid environments.
- Implement and maintain Identity Security Intelligence (ISI) for behavioral analytics, anomaly detection, and risk-based policy enforcement.
- Configure and manage CyberArk Remote Access for secure, agentless vendor access without VPN dependency.
- Build and optimize Flows for automating identity and access governance processes, such as access requests and approvals.
- Ensure seamless integration with directories, cloud platforms (Azure, AWS), ITSM systems, and SIEM tools.
- Develop technical documentation, architecture diagrams, and operational playbooks.
- Troubleshoot advanced issues and support Tier 3 escalations.
- Partner with cybersecurity, infrastructure, and compliance teams to support audits and ensure policy enforcement.
- Upgrade CyberArk connectors such as PSM, CPM, SIA.
- Appetite to learn the CyberArk new technologies such as SRS, Identity Protection, Risk Management, Incident and Response and Secure Browser.
- Develop and manage integration with Cloud and on-premises applications.
- Secure Cloud Access and manage Entra/AWS/GCP administrators via CyberArk.
What you have to offer:
- 7+ years of hands-on experience with CyberArk PAM solutions.
- Must have Strong experience with CyberArk SaaS Spaces and Services:
- Identity Administration
- PVWA
- Flows
- Secure Access
- Remote Access (Vendor PAM/Alero)
- Must have solid understanding of least privilege and Zero Trust.
- Must have a good understand of Active Directory and Entra.
- Must have strong knowledge on how single sign-on works
- Nice to have experience with CyberArk SaaS Spaces and Services:
- SWS & CBS
- ISI
- Audit
- Secure Cloud Access
- SIA (Secure Infrastructure Access)
- Nice to have proficiency in PowerShell or Python scripting and REST APIs.