Specialist Cyber Security
Ready to Transform Retail? Embark on a rewarding career with Sobeys Inc., celebrated among Canada’s Top 100 employers where your unique contributions drive success.
Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a Full-Time opportunity for a Specialist Cyber Security. This role can be based out of our office in Dartmouth, Halifax NS.
Responsibilities:
- Support the day-to-day operation, optimization, and continuous improvement of enterprise GRC platforms and cybersecurity compliance processes.
- Configure and administer GRC tools (e.g., ServiceNow IRM, Archer, OneTrust, MetricStream) to support control assessments, evidence collection, issue/exception management, risk tracking, third-party risk, and audit readiness.
- Translate regulatory, policy, and risk requirements into structured workflows, testing procedures, and reporting dashboards.
- Support cybersecurity risk identification, assessment, documentation, and monitoring, including maintenance of risk register and risk treatment plans.
- Track control gaps, remediation activities, and risk acceptances.
- Prepare dashboards and executive reporting on compliance posture, risk trends, remediation status, and program maturity.
- Maintain data quality, taxonomies, and audit-ready documentation across GRC systems.
- Develop SOPs, playbooks, training materials, and deliver enablement sessions to drive consistent adoption of GRC processes.
- Collaborate with IT, Security, Risk, Privacy, Legal, and Business stakeholders to align risk and compliance activities with organizational objectives.
Requirements:
- 3–5+ years of experience in cybersecurity compliance, IT risk management, IT audit, or GRC operations.
- Professional certifications (e.g., CISSP, CISA, CRISC, CGRC) are assets.
- Hands-on experience administering GRC platforms such as ServiceNow IRM, Archer, OneTrust, MetricStream, or similar tools would be an asset.
- Strong knowledge of cybersecurity and risk frameworks (e.g., ISO 27005, NIST SP 800-30, PCI DSS, NIST CSF, ISO 27001, PIPEDA, SOX, SOC 2).
- Working knowledge of cybersecurity risk management concepts, including risk assessment, treatment, and exception handling.
- Strong analytical, documentation, and process design skills with attention to data quality and accuracy.
- Ability to communicate effectively with both technical and non-technical stakeholders.
Our Total Rewards package is designed to help our teammates thrive—physically, financially, and emotionally. While offerings vary by role and employment type (full-time, part-time, contractual), eligible teammates may receive:
- Comprehensive Benefits Package with health and dental coverage, life insurance, and short- and long-term disability insurance.
- Access to Virtual Health Care and an Employee and Family Assistance Program for personalized support.
- Retirement and Savings Plan to help you build financial security.
- 10% In-Store Discount at participating banners, plus additional discount programs.
- Employee Share Ownership Plan (ESOP), giving you the opportunity to invest in the company’s success.
- Learning and Development Resources to support your career growth.
- Parental Leave Top-Up to assist growing families.
- Paid Vacation and Days Off to help you recharge.
Sobeys is committed to providing a compensation structure that is flexible, equitable and competitive in the market to enable performance and growth. To learn more about this opportunity—including expected range of compensation in accordance with Pay Transparency Legislation where required —please click the “I’m interested” button above. Individual Compensation is determined based on qualifications, experience, and internal equity within the range provided.
External websites may share our organization’s job postings which includes compensation information based on similar roles and market benchmarks. These figures are provided for general comparison purposes only and are not issued or verified by our organization..
