Avp, Cyber Risk Management

2 weeks ago


Montréal, Canada Sun Life Full time

You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do. Discover how you can make a difference in the lives of individuals, families and communities around the world.

**About the job**
- The increasing scope, scale, complexity of the cyber environment and regulatory emphasis upon Second Line oversight and in particular updates to OSFI B13 and E21, require us to increase our focus and resourcing for leadership roles across the Technology and Cyber Security domains.
- This role will hold be responsible for second line cyber challenge activities globally, including maintaining a relationship with our Business Group Risk Teams focused upon Cyber Risk Management.
- Key areas of focus will be:

- Adopting an approach that is proactive, embedded with first line leadership and able to provide real-time challenge across key initiatives and processes such as Cyber Incident Management.
- Ensuring that challenge processes and artifacts provide management with the appropriate insight to provide the Executive Team and Boards with the required assurance as to our Cyber Security Program and risk posture vs. our risk appetite.
- Ensuring that the Cyber Second Line practice adapt and support the SLF growth trajectory, changing business through the rapid adopting of Digital Enterprise practices and addressing new and emerging business types.

**What you'll be doing**
- Lead the execution, maintenance, and ongoing enhancement of an independent Security Risk program. Independently confirming the effectiveness of DBTS's management of security risks to identify, measure, manage, monitor and report on SLF's Security Risk profile.
- Quarterly reporting to the Operational Risk and Compliance Committee (ORCC) and Risk Review Committee (RC) on Sun Life’s Cyber Security Risk profile. Annually reporting to the Risk Committee on the enterprise-wide state of compliance with the Security Risk Policy.
- Actively support and liaise with BG located risk professionals with responsibility for Cyber Risk Management. Support the growth and advancement of these practices to ensure they develop a level of maturity consistent with the Corporate team. Ensure these teams operate in a manner which is consistent in practice, tone, risk appetite and approach aligned with the Corporate team, with particular focus upon the US and Asia teams.
- Lead the development, execution and maintenance of an independent Cyber Risk oversight program:

- Perform annual challenge of Security Risk Policy, EOG and supporting Directives
- Partner with 1LOD to establish and renew Key Risk Indicators (KRIs)
- Challenge and report on notable Cyber Risk related incidents and Operational Risk Events (OREs)
- Provide proactive challenge services to 1LOD ensuring effective management of our Cyber Risk posture through regular, interactive challenge and consulting to 1LOD.

**What you'll need to succeed**
- In-depth understanding of global information security standards and requirements (e.g., regulatory) and industry best practices, including the NIST Cyber Security Framework.
- In-depth understanding of first line of defense information security processes (e.g., risk management, pen testing, vulnerability scanning), controls (e.g., IDS, SIEM, anti-malware, system hardening), and systems at Sun Life is an asset.
- In-depth understanding and direct experience with the execution of:

- RCSAs
- Operational Risk Events or their external equivalent
- Key Risk Indicators
- Scenario Analysis
- Effective presentation, communication, negotiation, and conflict management skills.
- Strong relationship management skills and a proven ability to gain and maintain credibility with key front-line stakeholders.
- Effective change management, through strong impact and influence skills.

**Education/Accreditations**
- University degree and professional designation with over 10 years of experience or an equivalent combination of education and experience.
- Information security professional certification, such as the CISSP, CISM, or CISA

LI-Remote

At Sun Life we strive to create a flexible work environment where our employees are empowered to do their best work. Several flexible work options are available and can be discussed throughout the selection process depending on the role requirements and individual needs.

We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.

**Salary Range**:
125,500/125 500 - 207,100/207 100

**Job Category**:
Risk Management

**Posting End Date**:
18/05/2023



  • Montréal, Canada Business Development Bank of Canada Full time

    We are banking at another level. Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to...

  • Cyber Security Expert

    4 weeks ago


    Montréal, Canada Equans Full time

    **Requisition ID**: 53969 **Domain**: Digital and IT/Cybersecurity **Contract type**: Permanent **Schedule**: Full-Time **_Equans is looking for a cybersecurity Expert!_** The Equans group is a world leader in the energy and services industry. The Group operates in 20 countries, with 90,000 employees working on 5 continents. Equans is a Bouygues group...


  • Montréal, Canada Kruger Inc. Full time

    *** The Cyber Compliance Analyst is responsible for evaluating, implementing, and maintaining cybersecurity policies, procedures, and controls to ensure compliance with regulatory requirements and industry standards. This role involves conducting assessments, monitoring security systems, and collaborating with internal teams to address compliance gaps and...


  • Montréal, QC, Canada AtkinsRéalis Full time

    Spécialiste en cyber sécurité (ICS/OT) Vous êtes à la recherche d’une opportunité enrichissante en tant que spécialiste en cyber sécurité (ICS/OT)? Ce rôle correspond à la mission de AtkinsRéalis de transformer, d'adopter les technologies numériques et de garantir la croissance continue de ses capacités en cybersécurité industrielle dans...


  • Montréal, Canada Atlantis IT group Full time

    **Cyber Security Specialist** **Montreal, QC ( Hybrid Role )** **Long Term Contract** **Overview** The Cyber Security Specialist is responsible for creating, demonstrating, and mentoring to ensure a secure computing environment that protects against unauthorized access modification or destruction. This role will be part of Hyland's Security Operations...


  • Montréal, Canada Laurentian Bank Full time

    Seeing beyond numbers **TM** At Laurentian Bank, we believe we can change banking for the better. Founded in Montreal in 1846, Laurentian Bank helps families, businesses and communities thrive. Today, we have over 3,000 employees working together as One Team, to provide a broad range of financial services and advice-based solutions for customers across...


  • Montréal, QC, Canada Cyber Crime Full time

    Ubisoft Welcome to the official website for Ubisoft, creator of Assassin's Creed, Just Dance, Tom Clancy's video game series, Rayman, Far Cry, Watch Dogs and many others. Learn more about our breathtaking games here! View company page The incumbent will play a pivotal role in ensuring the safety and security of our Pan-Canadian Studios;...


  • Montréal, QC, Canada Reinsurance Group of America Inc Full time

    The Director Enterprise Risk Management, as a member of Enterprise Risk Analytics team, is responsible for enterprise wide risk management processes and process management for operations integration. Responsibilities Manages business continuity framework, operational resilience strategy, third-party risk management, and other RGA Canada-wide processes. ...


  • Montréal, QC, Canada Reinsurance Group of America Inc Full time

    The Director Enterprise Risk Management, as a member of Enterprise Risk Analytics team, is responsible for enterprise wide risk management processes and process management for operations integration. Manages business continuity framework, operational resilience strategy, third-party risk management, and other RGA Canada-wide processes. Monitor, assess,...


  • Montréal, QC, Canada AtkinsRéalis Full time

    Spécialiste en cyber sécurité (ICS/OT) Vous êtes à la recherche d’une opportunité enrichissante en tant que spécialiste en cyber sécurité (ICS/OT)? Ce rôle correspond à la mission de AtkinsRéalis de transformer, d'adopter les technologies numériques et de garantir la croissance continue de ses capacités en cybersécurité industrielle...

  • Cyber-Security Expert

    4 weeks ago


    Montréal, QC, Canada Noverka Conseil Full time

    At Noverka, our values illustrate who we are and define our convictions: Human, Transparent, Passionate. We are driven by innovation and success, both in our relationships and in our practices. Finding the right job for the right person is what we do best! Our client, an organization in the banking sector is looking for a Cyber-Security Expert – Expert....

  • Risk manager

    4 weeks ago


    Montréal, QC, Canada Noverka Conseil Full time

    At Noverka, our values illustrate who we are and define our beliefs: Human, Transparent, Passionate. We are driven by innovation and success, both in our relationships and in our practices. Finding the right job for the right person is what we do best! Our client, an organization in the Technologie industry is looking for a Risk manager. Job description ...


  • Montréal, Canada Business Development Bank of Canada Full time

    We are banking at another level. Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to...


  • Montréal, QC, Canada Crédit Agricole SA Full time

    Types of Jobs - Risk Management / Control Job title Contract type Permanent Contract Job summary Operational Risk professional (1LoD or 2LoD) with at least 7 years of experience, knows and understands well Corporate Investment Banking (CIB) products and services, has experience dealing with regulators, and ability to lead and drive change for effective...


  • Montréal, Canada Desjardins Full time

    At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should...


  • Montréal, Canada Fivesky Full time

    **Who you are**: - 3-5 years of experience in technology and security administration with a cybersecurity/identity and access management focus. - Familiarity with identity and access management governance, policies, and solutions. - Great technical and analytical skills, with a background in identity and access management. - Knowledge of user authentication...


  • Montréal, Canada Payments Canada Full time

    Thursday, April 25, 2024 Payments Canada's purpose is to make payments easier, smarter and safer for all Canadians. We care deeply about our employees' well-being and are committed to providing a flexible, hybrid work environmentthat supports in-person connection and remote work. Get to Know Us We are a unique organization situated at the centre of...


  • Montréal, Canada Payments Canada Full time

    Thursday, April 25, 2024 Payments Canada's purpose is to make payments easier, smarter and safer for all Canadians. We care deeply about our employees' well-being and are committed to providing a flexible, hybrid work environmentthat supports in-person connection and remote work. Get to Know Us We are a unique organization situated at the...


  • Montréal, Canada Payments Canada Full time

    Thursday, April 25, 2024 Payments Canada's purpose is to make payments easier, smarter and safer for all Canadians. We care deeply about our employees' well-being and are committed to providing a flexible, hybrid work environmentthat supports in-person connection and remote work. Get to Know Us We are a unique organization situated at the centre of...

  • Strategic Advisor

    4 weeks ago


    Montréal, Canada Desjardins Full time

    At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should...