AVP, Technology & Cyber Risk Management
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Sun Life U.S. is one of the largest providers of employee and government benefits, helping approximately 50 million Americans access the care and coverage they need. Through employers, industry partners and government programs, Sun Life U.S. offers a portfolio of benefits and services, including dental, vision, disability, absence management, life, supplemental health, medical stop-loss insurance, and healthcare navigation. We have more than 6,400 employees and associates in our partner dental practices and operate nationwide.
At Sun Life, we're driven by our
Purpose:
helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.
When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.
Visit our website to discover how Sun Life is making life brighter for our customers, partners and communities.
Job DescriptionThe AVP, Technology & Cyber Risk Management US leads second-line technology and cyber risk oversight for the US business group. The role shifts oversight from a primarily reactive, data-driven approach to proactive, embedded challenge—partnering with first-line leaders to provide timely insight on key initiatives, processes, controls, incidents, and emerging risks. This leader ensures that challenge activities and governance artifacts give executive management and boards clear assurance regarding the effectiveness of the technology and cyber program, the organization's risk posture, and alignment with risk appetite.
KeyAccountabilities Own US technology and cyber risk oversight (25%)
- Develop, execute, and maintain the independent second-line oversight program for the US business group.
- Challenge technology and security risk policies, standards, and supporting directives.
- Apply subject-matter expertise to challenge Risk and Control Self-Assessments (RCSAs).
- Partner with the first line of defense to establish and refresh Key Risk Indicators (KRIs).
- Challenge and report on significant technology and cyber incidents and Operational Risk Events (OREs).
- Monitor key indicators of compliance with policy and provide proactive, consultative challenge to first-line leaders.
- Report quarterly on the US technology risk profile to the Operational Risk and Compliance Committee and Risk Review Committee.
- Support annual reporting to the Risk Committee on compliance with technology risk policy.
- Provide reporting to regional risk committees in support of the US Business Group Chief Risk Officer's mandate.
- Lead the execution, maintenance, and continuous improvement of the US technology and cyber risk program.
- Independently assess the effectiveness of management's processes to identify, measure, manage, monitor, and report technology and cyber risk.
- Establish the vision and strategy needed to address evolving regulatory expectations, business growth, digital engineering practices, and emerging business models.
- Advise and support US business-group risk professionals responsible for technology and cyber risk management.
- Build maturity and consistency across regional practices, including alignment in tone, risk appetite, methods, and outcomes with the corporate risk function.
- Operate with minimal day-to-day direction and define the challenge strategy for technology and cyber risk management in the US business group.
- Exercise sound independent judgment when determining challenge approaches, conclusions, and escalation paths.
- Lead one direct report and coordinate with indirect resources and geographically dispersed risk partners.
- Escalate significant policy, control, risk-acceptance, or management-judgment concerns to the VP, Technology & Cyber Risk Management.
- Drive process improvement, innovation, and consistent execution across the second-line risk function.
- University degree and professional designation, with more than 10 years of relevant experience, or an equivalent combination of education and experience.
- Professional technology or information-security certification such as CISSP, CISM, CISA, or ITIL.
- Deep knowledge of global technology and cyber standards, regulatory expectations, and industry practices,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).