Eight domains. Every level inside each one. Click a card for the ladder.
A hiring layer on top of the frameworks that already exist — NIST, ISO/IEC 42001, the IAPP. They define the work; this maps it to roles, levels and bands. It is a working document, not a standard, and the calls behind it are stated further down.
Eight domains, not eight jobs
Every domain below runs from individual contributor to C-level. The title on a requisition is the least stable part of this market — the domain and the level are what actually determine fit. Click a card to see the ladder.
Governance
Policy, program ownership and the approval gate for how AI gets built and shipped.
Risk
Model risk management and enterprise AI risk assessment. Deep overlap with banking model risk.
Compliance
Regulatory readiness against the state patchwork and customer contractual obligations.
Audit & Assurance
Independent testing and attestation that controls actually work. The function this practice is named for.
Privacy
Technical safeguards for user data inside ML systems. Blends engineering, privacy law and model design.
Security
ML security, LLM security architecture and AI red teaming. Prices against security bands, not compliance.
Safety & Trust
Trust and safety, bias mitigation, alignment. Concentrated at frontier labs; bias mitigation crosses into the enterprise.
Data Governance
Provenance, lineage and stewardship of training data. Upstream of every other domain here.
Safety & Trust behaves differently from the other seven
A smaller and differently-shaped population: AI Safety Researcher, AI Safety Engineer, Head of AI Safety, AI Alignment Researcher, Responsible AI Lead, AI Trust & Safety Analyst, AI Bias Mitigation Specialist.
Worth naming honestly — this domain concentrates almost entirely at frontier labs rather than across the general market. It is real, it is mappable, and it does not behave like the other seven. Candidates here are frequently motivated by research agenda over compensation, which changes the entire approach.
Bias mitigation is the exception that crosses over. It is the function most directly exposed to active EEOC enforcement on AI-driven hiring under Title VII, which makes it an enterprise hire as much as a lab one.
Where we focus
A specialist practice is defined as much by where it concentrates as by what it covers. These sit outside our focus, and we will happily refer them.
- General cybersecurity. SOC leadership, network security, general CISO searches with no AI system in scope.
- General privacy and data protection. GDPR and CCPA program work that does not touch model development or deployment.
- Core ML engineering. Research scientists, ML platform and MLOps roles without a security, privacy or governance mandate.
- AI transformation leadership. Chief AI Officer, Head of AI, VP AI Transformation. Adjacent, larger, and a different market — deliberately kept out of this taxonomy.
Five positions here worth arguing with
A taxonomy nobody disagrees with is not saying anything. These are the calls this map makes that a working practitioner might genuinely push back on, with the reasoning attached — so you can take issue with one without discarding the rest.
Tell us where it's wrong. That's how it gets better.
If you work in this field and the boundaries here don't match what you see, we want to hear it.