Governance, Risk and Compliance Sr. Specialist
Tower One, United States
American Century Investments
Learn how you can plan, invest and manage your investments for all of your financial goals with American Century Investments.About Us
American Century Investments® is a leading global asset manager with over 65 years of experience helping a broad base of clients achieve their financial goals. Our expertise spans global equities and fixed income, multi-asset strategies, ETFs, and private investments.
Privately controlled and independent, we focus solely on investment management. But there’s an unexpected side to us, too. We direct over 40% of our profits every year—more than $2 billion since 2000—to the Stowers Institute for Medical Research. Our ongoing financial support drives the Institute’s breakthrough work and mission of defeating life-threatening diseases like cancer and Alzheimer’s. So, the better we do for our clients, the more we can do for everyone.
All 1,400 of us across the globe are inspired every day by the unique difference our hard work can make in so many lives. It shows in the curiosity we bring to every initiative, the deep relationships we build with our clients, and the way we treat each other in the hallway. If you’re excited to learn more about us, we can’t wait to learn more about you.
Role Summary
We are seeking a dedicated Governance, Risk and Compliance/GRC Sr. Specialist to join our Governance, Risk, Compliance, and Resiliency team in a full-time, in-house capacity. This role is an integral part of our Information Technology team and is responsible for driving our Governance, Risk, Compliance, and Security Assurance programs. The primary responsibility of the GRC Sr, Specialist, is to maintain our controls frameworks, policy warehouse, risk management framework, and continually assess those programs.
This hybrid position will be based out of our Kansas City, Missouri office.
This position is not eligible for visa sponsorship. Applicants must be authorized to work in the U.S. without visa sponsorship, now or in the future.
How You Will Make an Impact
- Assist in executing the risk assessment program to ensure compliance with organizational and regulatory requirements, collaborating with cross-functional teams (such as legal, compliance, IT and business units).
- Perform detailed risk assessments, evaluate security policies, procedures, and controls, and propose mitigation strategies.
- Maintain accurate records of assessments, findings, and recommendations, and prepare reports for internal stakeholders.
- Stand up and monitor compliance programs to meet regulatory and contractual obligations, ensuring documentation is maintained for all key GRC activities.
- Act as the relationship manager for internal and external audits, performing readiness assessments of ongoing business initiatives.
- Ensure documentation is maintained for all key GRC activities, including risk registers, audit logs, and compliance status reports.
- Manage the policy lifecycle of updates, reviews, approvals, and change communication.
- Evaluate third-party vendors’ controls and evaluate associated risk.
What You Bring to the Team (Required)
- A Bachelor's degree in cybersecurity, information systems or related field, or a combination of education and related work experience.
- At least 7 years validated experience working in cybersecurity, audit, risk and compliance or GRC role.
- Strong understanding of GRC processes, including policy management, risk assessment, controls compliance, and IT audit.
- Exceptional verbal and written communication skills, with validated expertise in managing timelines and deliverables effectively.
- General knowledge of IT, information security, network, facilities management, and physical security & safety.
- Motivated and organized self-starter with strong attention to detail and the ability to manage multiple priorities independently.
- General knowledge of privacy and information security frameworks (e.g., NIST, ISO) and relevant regulatory requirements (e.g., GDPR, CPRA).
- Demonstrates the American Century Investments Winning Behaviors: Client Focused, Courageous and Accountable, Collaborative, Curious and Adaptable, Competitively Driven.
Additional Assets (Preferred)
- GRC or Privacy certifications (e.g., CISA, CIPP).
- Experience in the financial services industry.
The above statements are not intended to be a complete list of all responsibilities, duties, and skills required.
What We Offer
- Competitive compensation package with bonus plan
- Generous PTO and competitive benefits
- 401k with 5% company match plus annual performance-based discretionary contribution
- Tuition reimbursement, formal mentorship program, live and online learning
Learn more about our benefits and perks.
Employees are required to be in the office on a scheduled frequency. Adherence to this schedule is essential to fulfilling the expectations of the role.
American Century Investments is committed to complying with the Americans with Disabilities Act and all other applicable Equal Employment Opportunity laws and regulations. As such, American Century strives to provide a reasonable accommodation to any qualified individual under the ADA to perform essential job functions.
We encourage people of all backgrounds to join us on our mission. If you require reasonable accommodation for any aspect of the recruitment process, please send a request to HR-Talent_Acquisition@americancentury.com. All requests for accommodation will be addressed as confidentially as practicable.
American Century Investments believes all individuals are entitled to equal employment opportunity and advancement opportunities without regard to race, religious creed, color, sex, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, gender, gender identity, gender expression, age for individuals forty years of age and older, military and veteran status, sexual orientation, and any other basis protected by applicable federal, state and local laws. ACI does not discriminate or adopt any policy that discriminates against an individual or any group of individuals on any of these bases.
#LI-Hybrid
American Century Proprietary Holdings, Inc. All rights reserved.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CIPP CISA Compliance GDPR Governance NIST Privacy Risk assessment Risk management RMF
Perks/benefits: 401(k) matching Career development Competitive pay Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.