AVP, Technology & Cyber Risk Management US

Sun Life Financial, Inc.

• $166K — $266K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • University degree and professional designation; 10+ years of relevant experience or equivalent.
  • Professional technology or information-security certification (CISSP, CISM, CISA, ITIL).
  • Expertise in global technology and cyber standards, regulatory expectations, and industry practices (e.g., NIST Cybersecurity Framework).
  • Experience with Risk and Control Self-Assessments, Operational Risk Events, Key Risk Indicators, and scenario analysis.
  • Understanding of first-line technology processes, controls, and systems (risk, change, problem, and incident management).
  • Strong executive-level communication, negotiation, and conflict-resolution skills.
  • Ability to influence and build credibility with senior stakeholders in business and technology.

Responsibilities

  • Develop and maintain the independent second-line oversight program for technology and cyber risk.
  • Challenge and update risk policies, standards, and directives to enhance security measures.
  • Apply expertise in Risk and Control Self-Assessments to ensure thorough oversight.
  • Collaborate with first-line defense to refine Key Risk Indicators.
  • Monitor compliance and provide proactive advice to first-line leaders.
  • Report on the technology risk profile to key committees quarterly and annually.
  • Enhance and execute the US technology and cyber risk program continuously.

Benefits

  • Commitment to pay transparency and equity in compensation.
  • Eligibility for a discretionary annual incentive award based on performance.
  • Supportive work environment that rewards contributions.
Full Job Description
Job Description:

The AVP, Technology & Cyber Risk Management - US leads second-line technology and cyber risk oversight for the US business group. The role shifts oversight from a primarily reactive, data-driven approach to proactive, embedded challenge-partnering with first-line leaders to provide timely insight on key initiatives, processes, controls, incidents, and emerging risks.

This leader ensures that challenge activities and governance artifacts give executive management and boards clear assurance regarding the effectiveness of the technology and cyber program, the organization's risk posture, and alignment with risk appetite.

KEY ACCOUNTABILITIES

Own US technology and cyber risk oversight (25%)
• Develop, execute, and maintain the independent second-line oversight program for the US business group.
• Challenge technology and security risk policies, standards, and supporting directives.
• Apply subject-matter expertise to challenge Risk and Control Self-Assessments (RCSAs).
• Partner with the first line of defense to establish and refresh Key Risk Indicators (KRIs).
• Challenge and report on significant technology and cyber incidents and Operational Risk Events (OREs).
• Monitor key indicators of compliance with policy and provide proactive, consultative challenge to first-line leaders.

Deliver risk reporting and committee assurance (15%)
• Report quarterly on the US technology risk profile to the Operational Risk and Compliance Committee and Risk Review Committee.
• Support annual reporting to the Risk Committee on compliance with technology risk policy.
• Provide reporting to regional risk committees in support of the US Business Group Chief Risk Officer's mandate.

Lead and enhance the US risk program (50%)
• Lead the execution, maintenance, and continuous improvement of the US technology and cyber risk program.
• Independently assess the effectiveness of management's processes to identify, measure, manage, monitor, and report technology and cyber risk.
• Establish the vision and strategy needed to address evolving regulatory expectations, business growth, digital engineering practices, and emerging business models.

Strengthen regional risk capability and alignment (10%)
• Advise and support US business-group risk professionals responsible for technology and cyber risk management.
• Build maturity and consistency across regional practices, including alignment in tone, risk appetite, methods, and outcomes with the corporate risk function.

LEADERSHIP & DECISION-MAKING
• Operate with minimal day-to-day direction and define the challenge strategy for technology and cyber risk management in the US business group.
• Exercise sound independent judgment when determining challenge approaches, conclusions, and escalation paths.
• Lead one direct report and coordinate with indirect resources and geographically dispersed risk partners.
• Escalate significant policy, control, risk-acceptance, or management-judgment concerns to the VP, Technology & Cyber Risk Management.
• Drive process improvement, innovation, and consistent execution across the second-line risk function.

REQUIRED QUALIFICATIONS
• University degree and professional designation, with more than 10 years of relevant experience, or an equivalent combination of education and experience.
• Professional technology or information-security certification such as CISSP, CISM, CISA, or ITIL.
• Deep knowledge of global technology and cyber standards, regulatory expectations, and industry practices, including the NIST Cybersecurity Framework.
• Demonstrated experience with Risk and Control Self-Assessments, Operational Risk Events, Key Risk Indicators, and scenario analysis.
• Strong understanding of first-line technology processes, controls, and systems, including risk management, change management, problem management, and incident management.
• Executive-level presentation, communication, negotiation, and conflict-management skills.
• Proven ability to build credibility and influence senior business, technology, security, and risk stakeholders.
• Strong change-leadership, relationship-management, and strategic-planning capabilities.

Salary Range: $166,600 - $266,600

At our company, we are committed to pay transparency and equity. The salary range for this role is competitive nationwide, and we strive to ensure that compensation is fair and equitable. Your actual base salary will be determined based on your unique skills, qualifications, experience, education, and geographic location. In addition to your base salary, this position is eligible for a discretionary annual incentive award based on your individual performance as well as the overall performance of the business. We are dedicated to creating a work environment where everyone is rewarded for their contributions.

Not ready to apply yet but want to stay in touch? Join our talent community to stay connected until the time is right for you!

Job Category:

Risk Management

Posting End Date:

19/11/2026

Similar Jobs

More Jobs at Sun Life Financial, Inc.

More Finance & Insurance Jobs

Find similar AVP, Technology & Cyber Risk Management US jobs: