Vous êtes aussi unique que votre parcours, votre expérience et votre point de vue. Ici, vous serez encouragé, habilité et défié à être à votre meilleur. Vous travaillerez avec des collègues dynamiques – des experts dans leurs domaines – qui sont désireux de partager leurs connaissances avec vous. Vos leaders vous inspireront et vous aideront à atteindre votre potentiel et à vous envoler vers de nouveaux horizons. Chaque jour, vous aurez de nouvelles et passionnantes occasions de rendre la vie plus brillante pour nos Clients – qui sont au cœur de tout ce que nous faisons.
Chez Sun Life, nous sommes guidés par notre Raison d'être : aider nos Clients à réaliser la sécurité financière à vie et à vivre une vie plus saine. Nos valeurs façonnent notre façon de travailler : bienveillance, authenticité, audace, inspiration et impact.
Quand vous vous joignez à Sun Life, vous travaillez avec des collègues passionnés et des leaders habilitants qui soutiennent votre croissance et célèbrent vos contributions, afin que vous puissiez faire une différence significative dans la vie de nos Clients.
Découvrez comment vous pouvez faire une différence dans la vie des personnes, des familles et des communautés du monde entier.
Description de poste:
Role Summary
Sun Life is seeking a highly experienced and strategic Director, Technology & Cyber Control Testing to lead the execution and continuous evolution of our first-line Technology & Cyber Control Testing Program.
Reporting to the AVP, Technology Risk & Compliance, the Director will be responsible for establishing and operating a scalable, risk-based control testing function that provides independent challenge and assurance over the design and operating effectiveness of technology and cyber controls across the Digital Business & Technology Solutions (DBTS) organization.
This role will play a critical leadership position in advancing Sun Life's technology risk management capabilities and strengthening compliance with regulatory expectations, including OSFI, industry frameworks, and internal policies. The successful candidate will build and lead a team responsible for control testing strategy, methodology execution, testing operations, quality assurance, issue reporting, remediation validation, and continuous improvement.
What You Will Do?
Lead the Technology & Cyber Control Testing Program
- Establish and manage an enterprise-scale technology and cyber control testing program across DBTS.
- Develop multi-year testing strategies and annual testing plans aligned to technology, cyber, operational resilience, regulatory, and business risks.
- Maintain the control testing universe and ensure testing coverage is aligned to material risk areas and control requirements.
- Drive risk-based prioritization, scoping, and testing frequency decisions across technology and cyber domains.
Direct Control Testing Execution
- Oversee the end-to-end lifecycle of control testing activities including planning, execution, review, reporting, and remediation validation.
- Ensure testing is conducted using standardized methodologies, procedures, templates, sampling approaches, and evidence standards.
- Lead teams performing design effectiveness and operating effectiveness assessments.
- Provide oversight for thematic reviews, targeted reviews, process adequacy assessments, and substantive testing activities.
- Ensure testing conclusions are evidence-based, traceable, and defensible.
Build Scalable Testing Operations
- Develop operating models, workflows, governance processes, tooling,
and repositories that enable consistent testing at scale.
- Drive automation opportunities and data-driven approaches to improve testing efficiency and coverage.
- Establish coordinated testing cycles and monitor execution performance against annual plans.
- Manage resource capacity, delivery timelines, and stakeholder engagement across multiple concurrent testing activities.
Lead Quality Assurance and Program Governance
- Build and oversee a formal quality assurance framework for technology and cyber control testing.
- Establish reviewer standards, calibration programs, testing guidance, and quality metrics.
- Drive consistency in testing execution, evidence assessment, issue classification, and reporting.
- Conduct periodic program reviews to identify opportunities for enhancement and increased maturity.
Drive Reporting and Management Insights
- Translate testing results into meaningful executive-level insights, trends, and risk intelligence.
- Prepare reporting for senior management, risk committees, executives, regulators, and oversight functions.
- Identify recurring control themes, emerging risks, systemic weaknesses, and root causes.
- Develop actionable recommendations that strengthen the control environment and improve risk outcomes.
Manage Issues and Remediation
- Oversee identification, assessment, escalation, and tracking of control deficiencies and exceptions.
- Partner with technology, cybersecurity, engineering, and business leaders to drive remediation activities.
- Validate corrective actions and assess remediation effectiveness.
- Monitor recurring issues and ensure lessons learned are integrated into future testing activities.
Build and Lead a High-Performing Team
- Recruit, develop, coach, and mentor a team of high-performing testing professionals.
- Establish a culture of accountability, continuous improvement, collaboration, and technical excellence.
- Provide career development and technical training across testing, technology risk, cybersecurity, data analytics, and regulatory compliance disciplines.
- Promote consistency in testing practices across all team members.
What You Will Need to succeed?
Experience
- 10+ years of experience in technology risk, cybersecurity, IT audit, internal controls, operational risk, compliance, assurance, or related disciplines.
- 5+ years of experience leading teams within technology risk, cyber risk, IT audit, controls assurance, or testing functions.
- Demonstrated experience building or managing large-scale control testing, assurance, or audit programs.
- Experience working within complex, highly regulated financial services environments.
- Experience interacting with senior executives, regulators, internal audit, and second-line risk functions.
Technical Expertise
Strong knowledge of:
- Technology risk management
- Cybersecurity controls and frameworks
- IT general controls (ITGCs)
- Cloud security and technology operations
- Identity and access management
- Change management
- Vulnerability management
- Incident management
- Operational resilience and disaster recovery
- Third-party technology risk management
- Data protection and cyber resilience
Experience with regulatory and industry frameworks such as:
- OSFI B-13
- OSFI E-21
- NIST Cybersecurity Framework
- COBIT
- ISO 27001
- CIS Controls
- DORA
- SOC reporting and assurance frameworks
Skills
- Exceptional leadership and people management skills.
- Strong executive communication and presentation capabilities.
- Ability to influence and challenge senior stakeholders constructively.
- Robust analytical, problem-solving, and critical thinking skills.
- Excellent report writing and executive storytelling capabilities.
- Ability to lead large-scale transformation and continuous improvement initiatives.
- Advanced knowledge of testing methodologies, sampling techniques, controls evaluation, and quality assurance practices.
Preferred Qualifications
- CPA, CIA, CISA, CISSP, CRISC, CISM, CBCP, or equivalent professional designation.
- Experience establishing first-line assurance or control testing functions.
- Experience with data analytics, visualization tools, workflow automation, and GRC platforms.
- Master's degree in Business, Information Technology, Cybersecurity, Risk Management, or related discipline.
Reasons why you should join us under the sun?
- A competitive salary and bonus program, based on market scale
- A flexible group insurance program starting on your first day of work to meet your needs and those of your family.
- Time off that allows you to focus on the moments that matter most. 20 vacation days per year.
- Our Share Ownership Program gives you the opportunity to invest in Sun Life while benefiting from employer matching contributions.
- We are proud to be included in Great Place to Work's 2025 list of Canada's Best Workplaces.
- A warm, supportive, and inclusive culture
L'étendue du salaire de base s'applique au lieu principal pour lequel l'emploi est affiché. Elle peut varier en fonction du lieu de travail du candidat retenu ou d'autres facteurs. En plus du salaire de base, les employés admissibles de Sun Life participent à divers régimes d'encouragement dont le paiement est discrétionnaire et assujetti au rendement individuel et à celui de l'entreprise. Certains rôles axés sur les ventes comportent des régimes d'encouragement à la vente basés sur les résultats des ventes individuelles ou de groupe.
La diversité et l'inclusion ont toujours été au cœur de nos valeurs chez Sun Life. Une main-d'œuvre diversifiée avec des perspectives variées et des idées créatives profite à nos Clients, aux communautés où nous opérons et à nous tous comme collègues. Nous accueillons les demandes de personnes qualifiées de tous les milieux.
Les personnes handicapées qui ont besoin d'accommodements dans le processus de demande ou celles qui ont besoin d'offres d'emploi dans un format différent peuvent envoyer une demande par courriel à
[email protected] .
Nous sommes fiers d'être une organisation hybride qui offre à nos employés le choix et la flexibilité de travailler à la fois au bureau et virtuellement en fonction des besoins de l'entreprise, de nos Clients et de vous.
Nous pouvons utiliser l'intelligence artificielle pour soutenir la recherche de candidats, le filtrage et la planification des entrevues.
Nous remercions tous les candidats d'avoir manifesté de l'intérêt pour ce poste. Seuls les candidats sélectionnés pour une entrevue seront contactés.
Échelle salariale :
110,000/110 000 - 180,000/180 000
Catégorie d'emploi :
Approvisionnement
Fin de l'affichage :
30/09/2026
📌 Director, Technology & Cyber Control Testing (Toronto)
🏢 Sun Life
📍 Toronto