Sobre esta vaga de Director, Technology & Cyber Control Testing na Sun Life
You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.
At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.
When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.
Discover how you can make a difference in the lives of individuals, families and communities around the world.
Job Description:
Role Summary
Sun Life is seeking a highly experienced and strategic Director, Technology & Cyber Control Testing to lead the execution and continuous evolution of our first-line Technology & Cyber Control Testing Program.
Reporting to the AVP, Technology Risk & Compliance, the Director will be responsible for establishing and operating a scalable, risk-based control testing function that provides independent challenge and assurance over the design and operating effectiveness of technology and cyber controls across the Digital Business & Technology Solutions (DBTS) organization.
This role will play a critical leadership position in advancing Sun Life's technology risk management capabilities and strengthening compliance with regulatory expectations, including OSFI, industry frameworks, and internal policies. The successful candidate will build and lead a team responsible for control testing strategy, methodology execution, testing operations, quality assurance, issue reporting, remediation validation, and continuous improvement.
What You Will Do?
Lead the Technology & Cyber Control Testing Program
Establish and manage an enterprise-scale technology and cyber control testing program across DBTS.
Develop multi-year testing strategies and annual testing plans aligned to technology, cyber, operational resilience, regulatory, and business risks.
Maintain the control testing universe and ensure testing coverage is aligned to material risk areas and control requirements.
Drive risk-based prioritization, scoping, and testing frequency decisions across technology and cyber domains.
Direct Control Testing Execution
Oversee the end-to-end lifecycle of control testing activities including planning, execution, review, reporting, and remediation validation.
Ensure testing is conducted using standardized methodologies, procedures, templates, sampling approaches, and evidence standards.
Lead teams performing design effectiveness and operating effectiveness assessments.
Provide oversight for thematic reviews, targeted reviews, process adequacy assessments, and substantive testing activities.
Ensure testing conclusions are evidence-based, traceable, and defensible.
Build Scalable Testing Operations
Develop operating models, workflows, governance processes, tooling, and repositories that enable consistent testing at scale.
Drive automation opportunities and data-driven approaches to improve testing efficiency and coverage.
Establish coordinated testing cycles and monitor execution performance against annual plans.
Manage resource capacity, delivery timelines, and stakeholder engagement across multiple concurrent testing activities.
Lead Quality Assurance and Program Governance
Build and oversee a formal quality assurance framework for technology and cyber control testing.
Establish reviewer standards, calibration programs, testing guidance, and quality metrics.
Drive consistency in testing execution, evidence assessment, issue classification, and reporting.
Conduct periodic program reviews to identify opportunities for enhancement and increased maturity.
Drive Reporting and Management Insights
Translate testing results into meaningful executive-level insights, trends, and risk intelligence.
Prepare reporting for senior management, risk committees, executives, regulators, and oversight functions.
Identify recurring control themes, emerging risks, systemic weaknesses, and root causes.
Develop actionable recommendations that strengthen the control environment and improve risk outcomes.
Manage Issues and Remediation
Oversee identification, assessment, escalation, and tracking of control deficiencies and exceptions.
Partner with technology, cybersecurity, engineering, and business leaders to drive remediation activities.
Validate corrective actions and assess remediation effectiveness.
Monitor recurring issues and ensure lessons learned are integrated into future testing activities.
Build and Lead a High-Performing Team
Recruit, develop, coach, and mentor a team of high-performing testing professionals.
Establish a culture of accountability, continuous improvement, collaboration, and technical excellence.
Provide career development and technical training across testing, technology risk, cybersecurity, data analytics, and regulatory compliance disciplines.
Promote consistency in testing practices across all team members.
What You Will Need to succeed?
Experience
10+ years of experience in technology risk, cybersecurity, IT audit, internal controls, operational risk, compliance, assurance, or related disciplines.
5+ years of experience leading teams within technology risk, cyber risk, IT audit, controls assurance, or testing functions.
Demonstrated experience building or managing large-scale control testing, assurance, or audit programs.
Experience working within complex, highly regulated financial services environments.
Experience interacting with senior executives, regulators, internal audit, and second-line risk functions.
Technical Expertise
Strong knowledge of:
Technology risk management
Cybersecurity controls and frameworks
IT general controls (ITGCs)
Cloud security and technology operations
Identity and access management
Change management
Vulnerability management
Incident management
Operational resilience and disaster recovery
Third-party technology risk management
Data protection and cyber resilience
Experience with regulatory and industry frameworks such as:
OSFI B-13
OSFI E-21
NIST Cybersecurity Framework
COBIT
ISO 27001
CIS Controls
DORA
SOC reporting and assurance frameworks
Skills
Exceptional leadership and people management skills.
Strong executive communication and presentation capabilities.
Ability to influence and challenge senior stakeholders constructively.
Strong analytical, problem-solving, and critical thinking skills.
Excellent report writing and executive storytelling capabilities.
Ability to lead large-scale transformation and continuous improvement initiatives.
Advanced knowledge of testing methodologies, sampling techniques, controls evaluation, and quality assurance practices.
Preferred Qualifications
CPA, CIA, CISA, CISSP, CRISC, CISM, CBCP, or equivalent professional designation.
Experience establishing first-line assurance or control testing functions.
Experience with data analytics, visualization tools, workflow automation, and GRC platforms.
Master's degree in Business, Information Technology, Cybersecurity, Risk Management, or related discipline.
Reasons why you should join us under the sun?
A competitive salary and bonus program, based on market scale
A flexible group insurance program starting on your first day of work to meet your needs and those of your family.
Time off that allows you to focus on the moments that matter most. 20 vacation days per year.
Our Share Ownership Program gives you the opportunity to invest in Sun Life while benefiting from employer matching contributions.
We are proud to be included in Great Place to Work's 2025 list of Canada's Best Workplaces.
A warm, supportive, and inclusive culture
The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other factors. In addition to Base Pay, eligible Sun Life employees participate in various incentive plans, payment under which is discretionary and subject to individual and company performance. Certain sales focused roles have sales incentive plans based on individual or group sales results.
Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.
Persons with disabilities who need accommodation in the application process, or those needing job postings in an alternative format, may e-mail a request to [email protected].
We are proud to be a hybrid organization that offers our employees the choice and flexibility to work from both the office and virtually based on the needs of the business, our Clients and you.
We may use artificial intelligence to support candidate sourcing, screening, interview scheduling.
We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.
Salary Range:
110,000/110 000 - 180,000/180 000Job Category:
ProcurementPosting End Date:
30/09/2026