AVP, Technology & Cyber Risk Management US

Sun Life

Hartford (CT)

On-site

USD 167,000 - 267,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits

Job summary

Sun Life U.S. seeks an AVP, Technology & Cyber Risk Management to lead second-line risk oversight for the US business group, embedding challenge practices with first-line leaders.

Own risk reporting to committees, refresh KRIs and incident management, and drive governance that aligns with regulatory expectations and business growth.

Requires 10+ years of relevant experience and professional certifications; Sun Life offers strong benefits and a collaborative, growth‑oriented culture.

Qualifications

  • University degree required plus professional designation.
  • Professional technology or information-security certification required.
  • Deep knowledge of global technology and cyber standards including the NIST CSF.
  • Experience with Risk and Control Self-Assessments, Operational Risk Events, KRIs, and scenario analysis.
  • Executive-level presentation, communication, negotiation, and conflict-management skills.
  • Proven ability to influence senior stakeholders across technology and risk domains.

Responsibilities

  • Own US technology and cyber risk oversight and develop the second-line program.
  • Challenge risk policies, standards and supporting directives; refresh KRIs.
  • Lead risk reporting to risk committees and boards on a quarterly basis.
  • Assess effectiveness of management's processes to identify, measure, manage, monitor, and report risk.
  • Drive strategy to address evolving regulatory expectations and business growth.

Skills

Executive communication
Stakeholder influence
Strategic planning
Change leadership
Risk management

Education

University degree and professional designation
Cybersecurity certifications (CISSP/CISM/CISA/ITIL)

Tools

NIST Cybersecurity Framework

Job description

Sun Life U.S. is one of the largest providers of employee and government benefits, helping approximately 50 million Americans access the care and coverage they need. Through employers, industry partners and government programs, Sun Life U.S. offers a portfolio of benefits and services, including dental, vision, disability, absence management, life, supplemental health, medical stop-loss insurance, and healthcare navigation. We have more than 6,400 employees and associates in our partner dental practices and operate nationwide.

At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.

When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.

Visit our website to discover how Sun Life is making life brighter for our customers, partners and communities.

Job Description:

The AVP, Technology & Cyber Risk Management - US leads second-line technology and cyber risk oversight for the US business group. The role shifts oversight from a primarily reactive, data-driven approach to proactive, embedded challenge-partnering with first-line leaders to provide timely insight on key initiatives, processes, controls, incidents, and emerging risks.

This leader ensures that challenge activities and governance artifacts give executive management and boards clear assurance regarding the effectiveness of the technology and cyber program, the organization's risk posture, and alignment with risk appetite.

KEY ACCOUNTABILITIES

Own US technology and cyber risk oversight (25%)

  • Develop, execute, and maintain the independent second-line oversight program for the US business group.
  • Challenge technology and security risk policies, standards, and supporting directives.
  • Apply subject-matter expertise to challenge Risk and Control Self-Assessments (RCSAs).
  • Partner with the first line of defense to establish and refresh Key Risk Indicators (KRIs).
  • Challenge and report on significant technology and cyber incidents and Operational Risk Events (OREs).
  • Monitor key indicators of compliance with policy and provide proactive, consultative challenge to first-line leaders.

Deliver risk reporting and committee assurance (15%)

  • Report quarterly on the US technology risk profile to the Operational Risk and Compliance Committee and Risk Review Committee.
  • Support annual reporting to the Risk Committee on compliance with technology risk policy.
  • Provide reporting to regional risk committees in support of the US Business Group Chief Risk Officer's mandate.

Lead and enhance the US risk program (50%)

  • Lead the execution, maintenance, and continuous improvement of the US technology and cyber risk program.
  • Independently assess the effectiveness of management's processes to identify, measure, manage, monitor, and report technology and cyber risk.
  • Establish the vision and strategy needed to address evolving regulatory expectations, business growth, digital engineering practices, and emerging business models.

Strengthen regional risk capability and alignment (10%)

  • Advise and support US business-group risk professionals responsible for technology and cyber risk management.
  • Build maturity and consistency across regional practices, including alignment in tone, risk appetite, methods, and outcomes with the corporate risk function.
LEADERSHIP & DECISION-MAKING
  • Operate with minimal day-to-day direction and define the challenge strategy for technology and cyber risk management in the US business group.
  • Exercise sound independent judgment when determining challenge approaches, conclusions, and escalation paths.
  • Lead one direct report and coordinate with indirect resources and geographically dispersed risk partners.
  • Escalate significant policy, control, risk-acceptance, or management-judgment concerns to the VP, Technology & Cyber Risk Management.
  • Drive process improvement, innovation, and consistent execution across the second-line risk function.
REQUIRED QUALIFICATIONS
  • University degree and professional designation, with more than 10 years of relevant experience, or an equivalent combination of education and experience.
  • Professional technology or information-security certification such as CISSP, CISM, CISA, or ITIL.
  • Deep knowledge of global technology and cyber standards, regulatory expectations, and industry practices, including the NIST Cybersecurity Framework.
  • Demonstrated experience with Risk and Control Self-Assessments, Operational Risk Events, Key Risk Indicators, and scenario analysis.
  • Strong understanding of first-line technology processes, controls, and systems, including risk management, change management, problem management, and incident management.
  • Executive-level presentation, communication, negotiation, and conflict-management skills.
  • Proven ability to build credibility and influence senior business, technology, security, and risk stakeholders.
  • Strong change-leadership, relationship-management, and strategic-planning capabilities.

Salary Range: $166,600 - $266,600

At our company, we are committed to pay transparency and equity. The salary range for this role is competitive nationwide, and we strive to ensure that compensation is fair and equitable. Your actual base salary will be determined based on your unique skills, qualifications, experience, education, and geographic location. In addition to your base salary, this position is eligible for a discretionary annual incentive award based on your individual performance as well as the overall performance of the business. We are dedicated to creating a work environment where everyone is rewarded for their contributions.

We are committed to fostering an inclusive environment where all employees feel they belong, are supported and empowered to thrive. We encourage applications from qualified individuals from all backgrounds.

At Sun Life, we prioritize your well-being with comprehensive benefits, including generous vacation and sick time, market-leading paid family, parental and adoption leave, medical coverage, company paid life and AD&D insurance, disability programs and a partially paid sabbatical program. Plan for your future with our 401(k) employer match, stock purchase options and an employer-funded retirement account. Enjoy a flexible, inclusive and collaborative work environment that supports career growth. We're proud to be recognized in our communities as a top employer. Proudly Great Place to Work Certified in Canada and the U.S., we've also been recognized as a "Top 10" employer by the Boston Globe's "Top Places to Work" for two years in a row. Visit our website to learn more about our benefits and recognition within our communities.

We will make reasonable accommodation to the known physical or mental limitation(s) of otherwise-qualified individuals with disabilities or special disabled veterans, unless the accommodation would impose an undue hardship on the operation of our business. Please email thebrightside@sunlife.com to request an accommodation.

For applicants residing in California, please read our employee California Privacy Policy and Notice.

We do not require or administer lie detector tests as a condition of employment or continued employment.

Sun Life will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including applicable fair chance ordinances.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Job Category:

Risk Management

Posting End Date:

19/11/2026

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Sun Life • Kansas City (MO)

On-site
USD 167,000 - 267,000
Vacation & sick time
401(k) match
Stock purchase plan
+2
AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Sun Life • Wellesley (MA)

On-site
USD 167,000 - 267,000
Vacation and sick time
Family leave
Medical coverage
+4
AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Koitecc Solutions • Wellesley (MA), Northern (KY)

Hybrid
USD 167,000 - 267,000
401(k) match
Stock purchase plan
Paid vacation
AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Koitecc Solutions • Hartford (CT)

On-site
USD 167,000 - 267,000
AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Koitecc Solutions • Kansas City (MO)

On-site
USD 167,000 - 267,000
AVP, Technology & Cyber Risk Management US
AVP, Technology & Cyber Risk Management US

Sun Life Financial • Wellesley (MA)

On-site
USD 167,000 - 267,000
AVP, Tech & Cyber Risk — US Second Line
AVP, Tech & Cyber Risk — US Second Line

Sun Life • Hartford (CT)

On-site
USD 167,000 - 267,000
Comprehensive benefits
Senior Technology & Cyber Risk Leader, US
Senior Technology & Cyber Risk Leader, US

Koitecc Solutions • Kansas City (MO)

On-site
USD 167,000 - 267,000
AVP, Technology & Cyber Risk — US Oversight Leader
AVP, Technology & Cyber Risk — US Oversight Leader

Koitecc Solutions • Hartford (CT)

On-site
USD 167,000 - 267,000
AVP, Tech & Cyber Risk Strategy
AVP, Tech & Cyber Risk Strategy

Sun Life • Wellesley (MA)

On-site
USD 167,000 - 267,000
Vacation and sick time
Family leave
Medical coverage
+4