Senior Cyber Security Specialist

Sobeys

Stellarton

On-site

CAD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sobeys is seeking a Senior Cyber Security Specialist to lead detection engineering and proactive threat hunting across retail and enterprise environments. You will design, implement, and continuously improve our detection logic and hunt operations, collaborating with SOC and IR teams.

The role involves parsing diverse log sources from POS, payment gateways, e-commerce, cloud services, and network devices; applying MITRE ATT&CK-aligned hunts; and delivering actionable reports and dashboards that

Qualifications

  • SIEM/EDR Expertise with hands-on Splunk and QRadar.
  • Experience in ingesting logs from POS, payment systems, e-commerce, cloud, and network devices.
  • Ability to operationalize threat intelligence and conduct ATT&CK-aligned hunts.
  • Knowledge of AWS, Azure, GCP in retail environments.
  • Familiarity with PCI DSS and GDPR/CCPA regimes.
  • Python and PowerShell for data parsing and automation.
  • Experience with ransomware, card-skimming, insider fraud in retail.

Responsibilities

  • Detection Engineering: design, author, and maintain high-fidelity detection rules and analytics across SIEM/EDR.
  • Parse/normalize diverse log sources to ensure consistent log data.
  • Conduct detection gap analysis and document use cases in a detection content catalog.
  • Threat Hunting & Threat Intelligence: lead hypothesis-driven hunts using MITRE ATT&CK.
  • Integrate threat intelligence into hunting/detection pipelines; produce reports.
  • Automation, SIEM/EDR Ops & Response: streamline alert triage and response; optimize dashboards.
  • Collaborate with IR/SOC to operationalize detections and hunts; reduce false positives.
  • Mentor junior analysts; lead knowledge-sharing sessions with SOC/engineering.

Skills

SIEM/EDR Expertise
Log Normalization
Threat-Informed Defense
Cloud Security
Compliance & Privacy
Scripting & Automation
Retail Threats & Fraud

Education

GIAC GCDA, GCIA, GCFA, GCTI; OSCP; PMP

Tools

Splunk SPL
Splunk
QRadar
EDR tools

Job description

Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full time opportunity for a Senior Cyber Security Specialist. This role can be based out of one our main offices including: Stellarton, NS; Mississauga, ON. Calgary, AB, Burnaby, BC We’re seeking a Subject Matter Expert (SME) who will lead both detection engineering and proactive threat hunting to design, implement, and continuously improve our detection logic and hunt operations across retail and enterprise environments.

Key Responsibilities
  • Detection Engineering Design, author, and maintain high‑fidelity detection rules and behavioral analytics across SIEM/EDR (e.g., Azure Sentinel or Elastic Stack or Splunk SPL for detections and dashboards).
  • Parse/normalize diverse log sources (POS systems, payment gateways, e‑commerce platforms, cloud services, and network devices) to ensure consistent, log data.
  • Perform detection gap analysis, recommend architecture improvements, and document use cases in a detection content catalog/knowledge base.
  • Threat Hunting & Threat Intelligence Lead hypothesis‑driven hunts using MITRE ATT&CK and behavioral analytics to uncover ransomware, data exfiltration, POS malware, supply‑chain compromises, card skimming, cloud misconfigurations, and insider fraud.
  • Integrate curated threat intelligence (including retail‑focused actors such as FIN6 and current ransomware groups) into hunting and detection pipelines; produce actionable reports and executive briefings.
  • Automation, SIEM/EDR Operations & Response Build automation to streamline alert triage and response; optimize SIEM dashboards and data models for retail‑specific visibility.
  • Partner with IR/SOC to operationalize detections and hunts; track efficacy and continuously tune for false‑positive reduction.
  • Collaboration & Leadership Collaborate closely with SOC, IR, and engineering teams; mentor junior analysts and lead knowledge‑sharing sessions.
  • Communicate status, risks, and outcomes to stakeholders; drive threat‑informed risk assessments and posture improvements.
  • Project & Program Management Own end‑to‑end delivery of detection and hunting initiatives (scope, timelines, resources, deliverables) aligned to compliance and business objectives.
Qualifications & Requirements
  • SIEM/EDR Expertise: Advanced Splunk SPL; hands‑on with SIEM (Splunk, QRadar) and EDR tools.
  • Log Engineering: Proven experience normalizing/ingesting logs from POS, payment systems, e‑commerce, cloud, and network devices.
  • Threat‑Informed Defense: Ability to operationalize threat intelligence and conduct ATT&CK‑aligned hunts.
  • Cloud Security: Working knowledge of AWS, Azure, GCP in retail environments.
  • Compliance & Privacy: Strong understanding of PCI DSS for payment security monitoring and familiarity with GDPR/CCPA.
  • Scripting & Automation: Proficiency in Python and PowerShell for data parsing, enrichment, and workflow automation.
  • Retail Threats & Fraud: Experience with ransomware, card‑skimming, insider fraud, loyalty‑program and e‑commerce fraud patterns.
Preferred Certifications

GIAC GCDA, GCIA, GCFA, GCTI; OSCP; PMP (or equivalent).

What Success Looks Like (KPIs)
  • Increased ATT&CK coverage and validated detections for priority TTPs.
  • Reduced mean‑time‑to‑detect (MTTD) and false‑positive rates through tuning and automation.
  • Regular delivery of high‑quality hunt reports, executive briefings, and detection content with measurable impact.

#LI-Hybrid #LI-VJ1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr CyberSec Spec Threat Intel
Sr CyberSec Spec Threat Intel

Canadian Tire • Toronto

Hybrid
CAD 64,000 - 106,000
Broadband salary range and incentives
Comprehensive benefits and retirement
Mental health benefits ($5,000/yr)
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
Security Analyst - Part Time
Security Analyst - Part Time

Equifax, Inc. • Toronto

On-site
USD 49,850 - 78,336
Senior Security Operations Analyst, Detection & Response
Senior Security Operations Analyst, Detection & Response

Financeit • Toronto

On-site
CAD 110,000 - 125,000
Hybrid workplace options
Competitive pay and bonus
RRSP matching
+3
Incident Response Analyst
Incident Response Analyst

Cyberwall Inc • Vaughan

Hybrid
CAD 80,000 - 110,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

STACK IT Recruitment • Burlington

On-site
CAD 154,000 - 181,000
Paid vacation and personal days
Annual bonus
Intermediate Forensics Mechanical Engineer
Intermediate Forensics Mechanical Engineer

j s held • Vancouver

On-site
CAD 90,000 - 115,000
Analyst, Information Security Risk Reporting
Analyst, Information Security Risk Reporting

Canadian Tire • Toronto

Hybrid
CAD 53,000 - 88,000
Comprehensive benefits and retirement
Mental health coverage