Manager IT, Cyber & Transformation Audit ( 12 months contract )

Sobeys
Sobeys

IT

Stellarton, NS, Canada

Posted on Aug 27, 2026
The Manager IT, Cyber & Transformation Audit plays a critical role in providing independent assurance over the organization’s technology risk landscape, with a focus on cybersecurity, digital platforms, and enterprise transformation initiatives. Operating within a complex, high-volume retail environment, this role leads the assessment of technology-enabled risks and advises on the effectiveness of controls across cyber, cloud, data, and application ecosystems. Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a 12 months contract opportunity for a Manager IT, Cyber & Transformation Audit. This role can be based out of offices located in Mississauga; ON, Calgary; AB, Stellarton; NS This role has high visibility with Senior Management and the Audit Committee of the Empire Company Limited group of companies and is instrumental in delivering forward-looking insights on emerging cyber threats, technology disruption, and transformation risk. The position partners closely with IT Operations and Cybersecurity teams to provide assurance across major initiatives. The role emphasizes proactive risk identification, embedded assurance, and continuous improvement, leveraging automation, analytics, and modern audit approaches to enhance organizational resilience and support successful business transformation. IT/Cyber Audit Program and Transformation Assurance Leadership Lead the end-to-end IT/Cyber audit program, including annual planning, risk assessment, scoping, and execution across application, infrastructure, and operational controls, and cybersecurity domainsLead Transformation Assurance activities including testing plans and reportingMaintain and enhance IT control frameworks aligned with COBIT, NIST, and regulatory expectations IT Control Design & Effectiveness Evaluate IT & cybersecurity controls, including identity and access management, IT operations, IT governance, vulnerability management, incident response, and data protectionIdentify control gaps, deficiencies, and emerging risks; recommend pragmatic and scalable remediation strategiesPartner with IT and business stakeholders to embed sustainable, efficient controls Testing, Assurance & Reporting Develop and execute risk-based audit and control testing plans (annual and quarterly)Review testing performed by team members and ensure adherence to audit standardsAssess and risk-rank control deficiencies, including cyber and IT-related issues impacting financial reportingDeliver clear, concise reporting and insights to senior management and the Audit Committee Board & Executive Engagement Support development of materials for Board and Audit Committee reporting, highlighting key IT and cyber risks, control deficiencies, and remediation progressPresent audit findings, insights, and emerging risks to senior leadershipProvide ongoing updates on technology risk posture, audit outcomes, and program progress Stakeholder Engagement Act as a trusted advisor to IT, Cybersecurity, Finance, and Operations on risk management and internal controlsDeliver training and guidance to control owners on IT risk, cyber hygiene, and control expectations Continuous Improvement & Transformation Drive standardization and optimization of IT audit processesLeverage data analytics, automation, and emerging technologies to enhance audit coverage and efficiencySupport enterprise transformation initiatives from a risk and controls perspective Team Leadership Lead, coach, and develop a high-performing IT/Cyber audit teamManage resource planning, prioritization, and performance managementFoster a collaborative, innovative, and risk-aware culture #LI-HybridQualifications & Experience 6–10+ years of experience in IT audit, cybersecurity, or risk managementStrong knowledge of application and infrastructure controls, and cybersecurity frameworks (e.g., NIST, ISO 27001, COBIT)Strong technical knowledge of Operating systems, databases, and networks, Identity and access management, Cybersecurity controls and monitoring, Cloud architectures and security modelsExperience with ERP systems (e.g., SAP), cloud environments, and modern technology platforms and operating systemsProfessional certifications preferred (e.g., CISA, CISM, CISSP, CPA)Strong communication skills and experience engaging with senior stakeholders and audit committees