Governance, Risk and Compliance Sr. Specialist
American Century InvestmentsAbout the role
About Us
American Century Investments® is a leading global asset manager with over 65 years of experience helping a broad base of clients achieve their financial goals. Our expertise spans global equities and fixed income, multi-asset strategies, ETFs, and private investments.
Privately controlled and independent, we focus solely on investment management. But there’s an unexpected side to us, too. We direct over 40% of our profits every year—more than $2 billion since 2000—to the Stowers Institute for Medical Research. Our ongoing financial support drives the Institute’s breakthrough work and mission of defeating life-threatening diseases like cancer and Alzheimer’s. So, the better we do for our clients, the more we can do for everyone.
All 1,400 of us across the globe are inspired every day by the unique difference our hard work can make in so many lives. It shows in the curiosity we bring to every initiative, the deep relationships we build with our clients, and the way we treat each other in the hallway. If you’re excited to learn more about us, we can’t wait to learn more about you.
Role Summary
We are seeking a dedicated Governance, Risk and Compliance/GRC Sr. Specialist to join our Governance, Risk, Compliance, and Resiliency team in a full-time, in-house capacity. This role is an integral part of our Information Technology team and is responsible for driving our Governance, Risk, Compliance, and Security Assurance programs. The primary responsibility of the GRC Sr, Specialist, is to maintain our controls frameworks, policy warehouse, risk management framework, and continually assess those programs.
This hybrid position will be based out of our Kansas City, Missouri office.
This position is not eligible for visa sponsorship. Applicants must be authorized to work in the U.S. without visa sponsorship, now or in the future.
How You Will Make an Impact
- Assist in executing the risk assessment program to ensure compliance with organizational and regulatory requirements, collaborating with cross-functional teams (such as legal, compliance, IT and business units).
- Perform detailed risk assessments, evaluate security policies, procedures, and controls, and propose mitigation strategies.
- Maintain accurate records of assessments, findings, and recommendations, and prepare reports for internal stakeholders.
- Stand up and monitor compliance programs to meet regulatory and contractual obligations, ensuring documentation is maintained for all key GRC activities.
- Act as the relationship manager for internal and external audits, performing readiness assessments of ongoing business initiatives.
- Ensure documentation is maintained for all key GRC activities, including risk registers, audit logs, and compliance status reports.
- Manage the policy lifecycle of updates, reviews, approvals, and change communication.
- Evaluate third-party vendors’ controls and evaluate associated risk.
What You Bring to the Team (Required)
- A Bachelor's degree in cybersecurity, information systems or related field, or a combination of education and related work experience.
- At least 7 years validated experience working in cybersecurity, audit, risk and compliance or GRC role.
- Strong understanding of GRC processes, including policy management, risk assessment, controls compliance, and IT audit.
- Exceptional verbal and written communication skills, with validated expertise in managing timelines and deliverables effectively.
- General knowledge of IT, information security, network, facilities management, and physical security & safety.
- Motivated and organized self-starter with strong attention to detail and the ability to manage multiple priorities independently.
- General knowledge of privacy and information security frameworks (e.g., NIST, ISO) and relevant regulatory requirements (e.g., GDPR, CPRA).
- Demonstrates the American Century Investments Winning Behaviors: Client Focused, Courageous and Accountable, Collaborative, Curious and Adaptable, Competitively Driven.
Additional Assets (Preferred)
- GRC or Privacy certifications (e.g., CISA, CIPP).
- Experience in the financial services industry.
The above statements are not intended to be a complete list of all responsibilities, duties, and skills required.
What We Offer
- Competitive compensation package with bonus plan
- Generous PTO and competitive benefits
- 401k with 5% company match plus annual performance-based discretionary contribution
- Tuition reimbursement, formal mentorship program, live and online learning
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds. Free account required — sign up in 30sApply for this role