Hybrid AVP, Threat and Vulnerability Management

Posted last month

Apply now

About the role

  • AVP, Global Threat & Vulnerability Management driving cyber resilience at Sun Life. Overseeing vulnerability management, red teaming, and incident management across the enterprise.

Responsibilities

  • You will lead Sun Life’s global capability for identifying, assessing, prioritizing, and mitigating cyber vulnerabilities and threats across the enterprise.
  • Oversee multiple sub-disciplines—vulnerability management, red teaming, threat intelligence, defensive security (blue team), application security platform & testing, and incident management & process development.
  • Produce Senior Leadership and Executive Reporting for all areas of Vulnerability Management.
  • Lead the Cyber Threat Intelligence (CTI) and Cyber Threat Hunting (CTH) function.
  • Oversee the Offensive Security (Red Team) program and ensure offensive testing aligns with threat intelligence.
  • Lead the Defensive Security (Blue Team) program to respond to detections from security controls.
  • Oversee application security scanning capabilities and provide secure development guidance.
  • Define KPIs, KRIs, and dashboards that measure vulnerability exposure, application security maturity, remediation performance, and threat trends.

Requirements

  • 15+ years of cybersecurity experience, with deep expertise in vulnerability management, threat intelligence, application security, or offensive/defensive security.
  • Proven leadership experience managing technical teams and enterprise-scale security programs.
  • Strong understanding of vulnerability scanning tools, AppSec testing platforms, cloud security, and threat intelligence technologies.
  • Demonstrated expertise in Red and Blue Team operations, including hands-on knowledge of adversary emulation, penetration testing (web, network, cloud), threat hunting, incident detection and response, malware analysis, and validation of security controls across complex enterprise environments.
  • Deep understanding of secure coding practices, shift left practices, application security capabilities, CI/CD pipelines, and DevSecOps principles.
  • Experience working in regulated industries and supporting audits, regulators, and client assurance programs.
  • Excellent communication skills with the ability to influence senior executives and technical teams.
  • Demonstrated ability to lead through complexity, ambiguity, and rapid change.
  • Certifications such as CISSP, CISM, GIAC, OSCP, GCTI, or CSSLP.
  • Experience with automation, secure SDLC, and large-scale application security programs.
  • Background in cyber risk quantification or exposure analytics.
  • Experience with cloud-native security tooling and modern application architectures.

Benefits

  • Flexible hybrid work model.
  • Pension, stock and savings programs to help build and enhance your future financial security.
  • Work and professional development that is united by our Purpose: to help Clients and Employees achieve lifetime financial security and live healthier lives.
  • A friendly, collaborative and inclusive culture.
  • Be part of our continuous improvement journey in developing the next greatest digital enterprise experience.
  • Competitive salary and bonus structure influenced by market range data.
  • The opportunity to move along a variety of career paths with amazing networking potential.

Job title

AVP, Threat and Vulnerability Management

Job type

Experience level

Lead

Salary

CA$145,000 - CA$235,000 per year

Degree requirement

Postgraduate Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job