Director, Technology & Cyber Control Testing

Sun Life Financial, Inc.

$110K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in technology risk, cybersecurity, IT audit, or related fields.
  • 5+ years leading teams in technology risk and cybersecurity functions.
  • Proven experience managing large-scale control testing programs.
  • Background in regulated financial services environments.
  • Strong interaction with senior executives and regulatory bodies.

Responsibilities

  • Lead the enterprise-scale Technology & Cyber Control Testing Program.
  • Develop alignment strategies for annual testing plans and material risk areas.
  • Oversee the complete lifecycle of control testing activities from planning to reporting.
  • Build scalable operations including workflows and governance for consistent testing.
  • Establish a quality assurance framework for control testing and reporting.

Benefits

  • Flexible group insurance program from day one.
  • 20 vacation days per year for work-life balance.
  • Opportunity to invest in the company through a Share Ownership Program with employer matching.
  • Recognized as one of Canada's Best Workplaces by Great Place to Work.
  • Supportive and inclusive company culture.
Full Job Description
Job Description:

Role Summary

Sun Life is seeking a highly experienced and strategic Director, Technology & Cyber Control Testing to lead the execution and continuous evolution of our first-line Technology & Cyber Control Testing Program.

Reporting to the AVP, Technology Risk & Compliance, the Director will be responsible for establishing and operating a scalable, risk-based control testing function that provides independent challenge and assurance over the design and operating effectiveness of technology and cyber controls across the Digital Business & Technology Solutions (DBTS) organization.

This role will play a critical leadership position in advancing Sun Life's technology risk management capabilities and strengthening compliance with regulatory expectations, including OSFI, industry frameworks, and internal policies. The successful candidate will build and lead a team responsible for control testing strategy, methodology execution, testing operations, quality assurance, issue reporting, remediation validation, and continuous improvement.

What You Will Do?

Lead the Technology & Cyber Control Testing Program
  • Establish and manage an enterprise-scale technology and cyber control testing program across DBTS.
  • Develop multi-year testing strategies and annual testing plans aligned to technology, cyber, operational resilience, regulatory, and business risks.
  • Maintain the control testing universe and ensure testing coverage is aligned to material risk areas and control requirements.
  • Drive risk-based prioritization, scoping, and testing frequency decisions across technology and cyber domains.

Direct Control Testing Execution
  • Oversee the end-to-end lifecycle of control testing activities including planning, execution, review, reporting, and remediation validation.
  • Ensure testing is conducted using standardized methodologies, procedures, templates, sampling approaches, and evidence standards.
  • Lead teams performing design effectiveness and operating effectiveness assessments.
  • Provide oversight for thematic reviews, targeted reviews, process adequacy assessments, and substantive testing activities.
  • Ensure testing conclusions are evidence-based, traceable, and defensible.

Build Scalable Testing Operations
  • Develop operating models, workflows, governance processes, tooling, and repositories that enable consistent testing at scale.
  • Drive automation opportunities and data-driven approaches to improve testing efficiency and coverage.
  • Establish coordinated testing cycles and monitor execution performance against annual plans.
  • Manage resource capacity, delivery timelines, and stakeholder engagement across multiple concurrent testing activities.

Lead Quality Assurance and Program Governance
  • Build and oversee a formal quality assurance framework for technology and cyber control testing.
  • Establish reviewer standards, calibration programs, testing guidance, and quality metrics.
  • Drive consistency in testing execution, evidence assessment, issue classification, and reporting.
  • Conduct periodic program reviews to identify opportunities for enhancement and increased maturity.

Drive Reporting and Management Insights
  • Translate testing results into meaningful executive-level insights, trends, and risk intelligence.
  • Prepare reporting for senior management, risk committees, executives, regulators, and oversight functions.
  • Identify recurring control themes, emerging risks, systemic weaknesses, and root causes.
  • Develop actionable recommendations that strengthen the control environment and improve risk outcomes.

Manage Issues and Remediation
  • Oversee identification, assessment, escalation, and tracking of control deficiencies and exceptions.
  • Partner with technology, cybersecurity, engineering, and business leaders to drive remediation activities.
  • Validate corrective actions and assess remediation effectiveness.
  • Monitor recurring issues and ensure lessons learned are integrated into future testing activities.

Build and Lead a High-Performing Team
  • Recruit, develop, coach, and mentor a team of high-performing testing professionals.
  • Establish a culture of accountability, continuous improvement, collaboration, and technical excellence.
  • Provide career development and technical training across testing, technology risk, cybersecurity, data analytics, and regulatory compliance disciplines.
  • Promote consistency in testing practices across all team members.


What You Will Need to succeed?

Experience
  • 10+ years of experience in technology risk, cybersecurity, IT audit, internal controls, operational risk, compliance, assurance, or related disciplines.
  • 5+ years of experience leading teams within technology risk, cyber risk, IT audit, controls assurance, or testing functions.
  • Demonstrated experience building or managing large-scale control testing, assurance, or audit programs.
  • Experience working within complex, highly regulated financial services environments.
  • Experience interacting with senior executives, regulators, internal audit, and second-line risk functions.

Technical Expertise

Strong knowledge of:
  • Technology risk management
  • Cybersecurity controls and frameworks
  • IT general controls (ITGCs)
  • Cloud security and technology operations
  • Identity and access management
  • Change management
  • Vulnerability management
  • Incident management
  • Operational resilience and disaster recovery
  • Third-party technology risk management
  • Data protection and cyber resilience


Experience with regulatory and industry frameworks such as:
  • OSFI B-13
  • OSFI E-21
  • NIST Cybersecurity Framework
  • COBIT
  • ISO 27001
  • CIS Controls
  • DORA
  • SOC reporting and assurance frameworks

Skills
  • Exceptional leadership and people management skills.
  • Strong executive communication and presentation capabilities.
  • Ability to influence and challenge senior stakeholders constructively.
  • Strong analytical, problem-solving, and critical thinking skills.
  • Excellent report writing and executive storytelling capabilities.
  • Ability to lead large-scale transformation and continuous improvement initiatives.
  • Advanced knowledge of testing methodologies, sampling techniques, controls evaluation, and quality assurance practices.


Preferred Qualifications
  • CPA, CIA, CISA, CISSP, CRISC, CISM, CBCP, or equivalent professional designation.
  • Experience establishing first-line assurance or control testing functions.
  • Experience with data analytics, visualization tools, workflow automation, and GRC platforms.
  • Master's degree in Business, Information Technology, Cybersecurity, Risk Management, or related discipline.


Reasons why you should join us under the sun?
  • A competitive salary and bonus program, based on market scale
  • A flexible group insurance program starting on your first day of work to meet your needs and those of your family.
  • Time off that allows you to focus on the moments that matter most. 20 vacation days per year.
  • Our Share Ownership Program gives you the opportunity to invest in Sun Life while benefiting from employer matching contributions.
  • We are proud to be included in Great Place to Work's 2025 list of Canada's Best Workplaces.
  • A warm, supportive, and inclusive culture


The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other factors. In addition to Base Pay, eligible Sun Life employees participate in various incentive plans, payment under which is discretionary and subject to individual and company performance. Certain sales focused roles have sales incentive plans based on individual or group sales results.

We are proud to be a hybrid organization that offers our employees the choice and flexibility to work from both the office and virtually based on the needs of the business, our Clients and you.

We may use artificial intelligence to support candidate sourcing, screening, interview scheduling.

Salary Range:
110,000/110 000 - 180,000/180 000

Job Category:
Procurement

Posting End Date:
30/09/2026

Similar Jobs

More Jobs at Sun Life Financial, Inc.

More Information Technology Jobs

Find similar Director, Technology & Cyber Control Testing jobs: