Job Description
Embark on a rewarding career with Sobeys Inc., celebrated among Canada’s Top 100 employers where your unique contributions drive success.
We are seeking a highly skilled and forward-thinking Senior Cybersecurity Specialist to help advance and modernize our Offensive Security and Application Security capabilities. This role will play a critical part in shaping the future of security testing across traditional applications, cloud platforms, APIs, and emerging AI-powered systems.
As a senior member of the team, you will partner closely with security leadership to design and evolve offensive security frameworks, testing methodologies, policies, standards, and governance practices that keep pace with rapidly changing technologies and threat landscapes. You will contribute to complex penetration testing engagements, perform advanced application security assessments, contribute to red team operations, and help establish best practices for securing AI-enabled products and services.
Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full-time opportunity for a Senior Cyber Security Specialist. This role can be based out of one our main offices including: Mississauga, ON. Calgary, AB; Burnaby, BC; Stellarton, NS.
The successful candidate combines deep technical expertise with strategic thinking, enabling them to influence security programs, mentor team members, and drive innovation in offensive security, application security, and AI security testing.
Key Responsibilities
Offensive Security & Penetration Testing
• Lead the planning, coordination, and oversight of penetration testing engagements across enterprise systems, external-facing applications, cloud environments, APIs, and critical business platforms.
• Act as the primary technical liaison with external security testing providers, ensuring testing activities align with organizational objectives, methodologies, and risk priorities.
• Review, validate, and challenge security findings to ensure accuracy, context, and business relevance.
• Perform targeted hands-on security assessments and technical validation activities where required to support high-risk initiatives or complex findings.
• Coordinate and support red team exercises and adversarial assessments while ensuring alignment with organizational threat scenarios and business risks.
Application Security
• Perform comprehensive Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and manual application security reviews.
• Conduct secure code reviews to identify vulnerabilities, insecure design patterns, authentication weaknesses, and other application-layer risks.
• Evaluate web, mobile, API, SaaS, and internally developed applications against industry standards including OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, and Mobile Security Testing Guide
• Support secure-by-design initiatives and provide security guidance throughout the Software Development Lifecycle (SDLC).
Security Strategy & Program Development
• Partner with leadership to establish and mature offensive security and application security frameworks, standards, policies, and assessment methodologies.
• Continuously evaluate industry trends, threat intelligence, and security innovations to identify opportunities for program enhancement.
• Develop security testing playbooks, reporting standards, risk-rating methodologies, and operational procedures.
• Provide technical leadership and mentorship to team members while fostering a culture of continuous learning and innovation.
• Advocate for security best practices and influence strategic security decisions across the organization.
Stakeholder Engagement & Reporting
• Translate technical findings into business-focused risk assessments and actionable remediation guidance.
• Collaborate with Infrastructure, Engineering, Cloud, Architecture, and DevSecOps teams to improve security posture and reduce organizational risk.
• Support regulatory, compliance, and audit requirements through effective security documentation and reporting.
AI Security & Emerging Technologies
• Develop and evolve testing methodologies for AI-enabled and Large Language Model (LLM)-powered applications.
• Assess AI systems for security risks including prompt injection, model manipulation, data leakage, insecure integrations, excessive agency, and other
• emerging AI attack vectors.
• Contribute to the development of security standards, governance frameworks, and best practices for AI application security testing.
• Collaborate with engineering and architecture teams to integrate security controls into AI development pipelines, MLOps environments, and model deployment processes.
• Stay current with emerging AI security threats, industry standards, and offensive testing techniques.
Required Qualifications & Experience :
• Minimum 5+ years of hands-on experience in one or more of Offensive Security, Application Security, Penetration Testing, Red Teaming, or related cybersecurity disciplines.
• Strong expertise in web, API, mobile, cloud, and enterprise security assessment methodologies.
• Demonstrated experience performing penetration testing, vulnerability validation, exploit development, and security research.
• In-depth knowledge of OWASP frameworks, including OWASP Top 10, ASVS, WSTG, API Security Top 10, and AI Security guidance.
• Experience conducting SAST, DAST, SCA, and manual code reviews across modern application architectures.
• Strong understanding of threat modeling, attack-path analysis, and security architecture principles.
• Proficiency with offensive security tools such as Burp Suite, Nmap, Metasploit, Nessus, BloodHound, AttackIQ, and related platforms.
• Solid understanding of modern development practices, CI/CD pipelines, DevSecOps, Infrastructure as Code (IaC), and containerized environments.
• Strong understanding of security considerations associated with artificial intelligence and machine learning technologies.
• Exceptional analytical, communication, documentation, and stakeholder management skills.
#LI-Hybrid
Preferred Qualifications
Industry-recognized certifications such as:
• OSCP
• OSEP
• OSWE
• OSCE
• GPEN
• GWAPT
• GCPN
• CCSK
• AZ-500
Experience with:
• AI/LLM security testing and red teaming
• Cloud-native application security
• Offensive security automation
• Secure SDLC implementation
• Threat modeling and architecture reviews
• Security engineering and security tooling development
• Purple team exercises and adversary emulation
Who We Are Looking For
We are looking for a cybersecurity professional who is:
• Passionate about offensive security, application security, and the future of AI security.
• A strategic thinker capable of helping define and evolve security programs rather than simply executing assessments.
• Curious, innovative, and committed to staying ahead of emerging threats and industry developments.
• Able to balance deep technical expertise with practical business risk management.
• Comfortable operating in ambiguous environments and building new capabilities from the ground up.
• An effective communicator who can influence technical and executive stakeholders alike.
• Collaborative, dependable, and committed to raising the overall security maturity of the organization.
• Driven to continuously learn, innovate, and shape the next generation of offensive security practices.
Who we are
Sobeys is one of Canada’s leading grocery retailers, with more than 1,600 stores across all 10 provinces and banners including Sobeys, Safeway, IGA, Foodland, FreshCo, Thrifty Foods, and Lawtons Drug Stores. Our 128,000 teammates and franchise affiliates are passionate about delivering great food and exceptional experiences to our customers and communities.
Learn more about our story and culture:
Who We Are | Why Work With Us
Total Rewards
We offer a Total Rewards package designed to support teammates at work and in life. Depending on role and eligibility, teammates may receive health and dental benefits, retirement and savings programs including an Employee Share Ownership Plan, a 10% in-store discount at participating banners, virtual healthcare and an Employee and Family Assistance Program, learning and development opportunities, parental leave top-up, and paid vacation.
Sobeys is committed to providing a compensation structure that is flexible, equitable and competitive in the market to enable performance and growth. To learn more about this opportunity including the expected range of compensation in accordance with Pay Transparency Legislation where required please click the “I’m interested” or "Apply" button above. Individual compensation is determined based on qualifications, experience, and internal equity within the range provided.
Additional Information
External websites may share our organization's job postings which includes compensation information based on similar roles and market benchmarks. These figures are provided for general comparison purposes only and are not issued or verified by our organization.
We may use Artificial Intelligence (AI) tools to support efficiencies in the candidate screening, assessment, and recruitment processes. These AI tools do not make hiring decisions on behalf of the Company. Hiring decisions are made by our Hiring Teams.
Sobeys is committed to creating accessible and inclusive hiring processes. We will work with applicants requesting accommodation at any stage of the recruitment process.
Please note: Successful candidates will be required to provide documentation to prove their legal ability to work in the position during the onboarding process. Documentation will be assessed by the employer prior to commencement of work.