×
Register Here to Apply for Jobs or Post Jobs. X

AVP, Threat and Vulnerability Management

Job in Toronto, Ontario, C6A, Canada
Listing for: Sun Life
Full Time position
Listed on 2026-02-08
Job specializations:
  • IT/Tech
    Cybersecurity, Security Manager, Information Security, Network Security
Job Description & How to Apply Below

You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.

Discover how you can make a difference in the lives of individuals, families and communities around the world.

Overview

As the AVP, Global Threat & Vulnerability Management (TVM) within Digital Security Threat Management (DSTM) under Security, Risk & Crisis Management (SRC), you will lead Sun Life’s global capability for identifying, assessing, prioritizing, and mitigating cyber vulnerabilities and threats across the enterprise. You will oversee multiple sub‑disciplines—vulnerability management, red teaming, threat intelligence, defensive security (blue team), application security platform & testing, and incident management & process development—ensuring Sun Life maintains a resilient and compliant security posture.

This role partners closely with Security Engineering & Advisory, Technology Risk & Compliance, Security Governance & Client Programs, Security Initiatives & Awareness, and Security Operations to drive measurable improvements in cyber resilience and reduce enterprise attack surface.

Key Responsibilities
  • Enterprise Vulnerability Management Leadership
    • Responsible Person/Contact for the enterprise Vulnerability Management Directive, overseeing the entire vulnerability lifecycle across Sun Life: identification, prioritization, reporting, remediation governance, and compliance monitoring.
    • VM program encompasses: internal and external vulnerability scanning, database scanning, Security Scorecard monitoring, threat‑intel‑driven vulnerability monitoring, classification of vulnerabilities and zero‑day response, audit, client and regulatory responses, management of platforms related to Vulnerability Management, and senior leadership/executive reporting.
  • Cyber Threat Intelligence (CTI) & Threat Hunting (CTH)
    • Lead the collection, analysis, and operationalization of internal and external threat intelligence.
    • Monitor global threats affecting Sun Life brands, staff, infrastructure, and clients; identify indicators of compromise and attacker behaviors.
    • Produce actionable threat briefings for Security teams, Technology Risk, and senior leadership; maintain relationships with intelligence‑sharing communities and government partners.
    • Ensure threat intelligence informs detection engineering, vulnerability prioritization, and offensive testing; perform continuous Threat Hunting.
    • Develop and refine use cases with Security Operations and Engineering for alerting to Defensive Security teams.
  • Red Team / Offensive Security Oversight
    • Lead Offensive Security (Red Team) program, including application, network, social engineering, and physical penetration tests; adversary emulation engagements; intelligence‑led penetration testing.
    • Translate findings into prioritized remediation actions and long‑term security improvements; validate remediation with technology teams.
  • Blue Team / Defensive Security Oversight
    • Lead Defensive Security (Blue Team) program; respond to detections and evolve capabilities based on threat intelligence and testing results.
    • Collaborate with Offensive Security, CTI and Security Operations to enhance detection coverage, reduce dwell time, and improve alert fidelity.
  • Security Incident & Process Management
    • Lead the Security Incident team; respond to incidents and govern maturity of incident response processes, playbooks, and readiness exercises.
    • Ensure consistent, high‑quality incident handling with clear communication and post‑incident reviews.
  • Application Security Platforms & Testing
    • Oversee application security scanning capabilities (static, dynamic, software composition, mobile analysis); integrate with Dev Ops pipelines.
    • Identify systemic weaknesses, drive remediation strategies, provide secure development guidance, and ensure findings feed…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary