Purpose:At Athene, we're transforming retirement services through innovation, technology, and disciplined risk management. As a Senior Governance, Risk & Compliance (GRC) Analyst, you'll play a key role in strengthening our technology risk, cybersecurity governance, and regulatory compliance programs while helping protect one of the industry's fastest-growing financial services organizations.
Working across Cybersecurity, Technology, Enterprise Risk, Legal, Compliance, and Internal Audit, you'll influence enterprise-wide decisions, improve governance, and help shape the responsible adoption of emerging technologies-including AI. This is an opportunity for a collaborative, curious professional who enjoys solving complex challenges, driving continuous improvement, and making a measurable business impact.
Accountabilities:KEY DELIVERABLES- Lead technology, cybersecurity, and AI risk assessments to identify risks, strengthen controls, and drive continuous improvement across the enterprise.
- Partner with business and technology leaders to enhance governance frameworks, policies, and controls that support regulatory compliance and operational resilience.
- Manage the enterprise technology risk register, monitor remediation efforts, and deliver meaningful metrics, dashboards, and executive reporting that enable informed decision-making.
- Support internal audits, regulatory examinations, third-party risk assessments, and customer security reviews while strengthening compliance with industry and regulatory expectations.
- Advance Athene's GRC program by improving governance processes, automating workflows, enhancing reporting, and increasing visibility into enterprise technology risk.
- Collaborate across teams to promote security awareness, strengthen incident preparedness, and support the responsible governance of emerging technologies and AI.
Qualifications and Experience:WHAT YOU'LL NEED TO BRING- 5+ years of relevant experience in IT risk management, cybersecurity governance, IT audit, governance, risk & compliance (GRC), technology consulting, or related experience. Experience assessing technology and cybersecurity risks, evaluating control effectiveness, and partnering with stakeholders to implement practical risk mitigation strategies.
- Strong understanding of technology governance, internal controls, and regulatory frameworks such as SOX, NIST, ISO 27001, COBIT, NYDFS, BMA, or similar.
- Excellent communication, critical thinking, and relationship-building skills with the ability to influence technical and business stakeholders while managing multiple priorities in a fast-paced environment.
- Professional certifications such as CRISC, CISA, CISSP, or equivalent are preferred. Experience with AI governance, ServiceNow IRM/GRC, or similar governance platforms is a plus.
- Bachelor's degree in Accounting, Management Information Systems, Computer Science, Cybersecurity, or a related field, or equivalent experience.