Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Director, Technology & Cyber Control Testing role.
Rezi rewrites your resume against Sun Life's job description. Free.

Tailor your resume to this Director, Technology & Cyber Control Testing role.
Rezi rewrites your resume against Sun Life's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Director, Technology & Cyber Control Testing posting at Sun Life — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Director, Technology & Cyber Control Testing posting at Sun Life — free, in seconds.
About the Role
Sun Life is seeking a Director, Technology & Cyber Control Testing to lead the execution and continuous evolution of its first-line Technology & Cyber Control Testing Program. This role will establish and operate a risk-based control testing function providing independent challenge and assurance over technology and cyber controls within the Digital Business & Technology Solutions (DBTS) organization. The position is critical for advancing Sun Life's technology risk management capabilities and strengthening compliance with regulatory expectations.
Responsibilities
- Lead the Technology & Cyber Control Testing Program, establishing and managing an enterprise-scale program across DBTS.
- Develop multi-year testing strategies and annual testing plans aligned to technology, cyber, operational resilience, regulatory, and business risks.
- Maintain the control testing universe and ensure testing coverage aligns with material risk areas and control requirements.
- Drive risk-based prioritization, scoping, and testing frequency decisions across technology and cyber domains.
- Oversee the end-to-end lifecycle of control testing activities, including planning, execution, review, reporting, and remediation validation.
- Ensure testing is conducted using standardized methodologies, procedures, templates, sampling approaches, and evidence standards.
- Lead teams performing design effectiveness and operating effectiveness assessments.
- Provide oversight for thematic reviews, targeted reviews, process adequacy assessments, and substantive testing activities.
- Ensure testing conclusions are evidence-based, traceable, and defensible.
- Develop operating models, workflows, governance processes, tooling, and repositories for consistent testing at scale.
- Drive automation opportunities and data-driven approaches to improve testing efficiency and coverage.
- Establish coordinated testing cycles and monitor execution performance against annual plans.
- Manage resource capacity, delivery timelines, and stakeholder engagement across multiple concurrent testing activities.
- Build and oversee a formal quality assurance framework for technology and cyber control testing.
- Establish reviewer standards, calibration programs, testing guidance, and quality metrics.
- Drive consistency in testing execution, evidence assessment, issue classification, and reporting.
- Conduct periodic program reviews to identify opportunities for enhancement and increased maturity.
- Translate testing results into meaningful executive-level insights, trends, and risk intelligence.
- Prepare reporting for senior management, risk committees, executives, regulators, and oversight functions.
- Identify recurring control themes, emerging risks, systemic weaknesses, and root causes.
- Develop actionable recommendations to strengthen the control environment and improve risk outcomes.
- Oversee identification, assessment, escalation, and tracking of control deficiencies and exceptions.
- Partner with technology, cybersecurity, engineering, and business leaders to drive remediation activities.
- Validate corrective actions and assess remediation effectiveness.
- Monitor recurring issues and ensure lessons learned are integrated into future testing activities.
- Recruit, develop, coach, and mentor a team of high-performing testing professionals.
- Establish a culture of accountability, continuous improvement, collaboration, and technical excellence.
- Provide career development and technical training across testing, technology risk, cybersecurity, data analytics, and regulatory compliance disciplines.
- Promote consistency in testing practices across all team members.
Requirements
- 10+ years of experience in technology risk, cybersecurity, IT audit, internal controls, operational risk, compliance, assurance, or related disciplines.
- 5+ years of experience leading teams within technology risk, cyber risk, IT audit, controls assurance, or testing functions.
- Demonstrated experience building or managing large-scale control testing, assurance, or audit programs.
- Experience working within complex, highly regulated financial services environments.
- Experience interacting with senior executives, regulators, internal audit, and second-line risk functions.
Skills
- Technology risk management
- Cybersecurity controls and frameworks
- IT general controls (ITGCs)
- Cloud security and technology operations
- Identity and access management
- Change management
- Vulnerability management
- Incident management
- Operational resilience and disaster recovery
- Third-party technology risk management
- Data protection and cyber resilience
- OSFI B-13
- OSFI E-21
- NIST Cybersecurity Framework
- COBIT
- ISO 27001
- CIS Controls
- DORA
- SOC reporting and assurance frameworks
- Exceptional leadership and people management skills
- Strong executive communication and presentation capabilities
- Ability to influence and challenge senior stakeholders constructively
- Strong analytical, problem-solving, and critical thinking skills
- Excellent report writing and executive storytelling capabilities
- Ability to lead large-scale transformation and continuous improvement initiatives
- Advanced knowledge of testing methodologies, sampling techniques, controls evaluation, and quality assurance practices
- Experience with data analytics, visualization tools, workflow automation, and GRC platforms.
Location
- Canada
Work Type
- Hybrid
Experience Level
- 10+ years
- 5+ years
Education Level
- Master's degree in Business, Information Technology, Cybersecurity, Risk Management, or related discipline.
- CPA, CIA, CISA, CISSP, CRISC, CISM, CBCP, or equivalent professional designation.
Salary/Compensations
- 110,000 - 180,000
Benefits
- Competitive salary and bonus program
- Flexible group insurance program
- 20 vacation days per year
- Share Ownership Program with employer matching contributions
About the Company
- Sun Life is driven by its Purpose: helping Clients achieve lifetime financial security and live healthier lives.
- Values: caring, authentic, bold, inspiring, and impactful.
- We are proud to be included in Great Place to Work's 2025 list of Canada's Best Workplaces.
- We are a hybrid organization offering flexibility to work from both the office and virtually.
- We may use artificial intelligence to support candidate sourcing, screening, interview scheduling.
Equal Opportunity
- Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.
- Persons with disabilities who need accommodation in the application process, or those needing job postings in an alternative format, may e-mail a request to thebrightside@sunlife.com.