Analysis and documents on a working desk
Coverage map

Eight domains. Every level inside each one. Click a card for the ladder.

A hiring layer on top of the frameworks that already exist — NIST, ISO/IEC 42001, the IAPP. They define the work; this maps it to roles, levels and bands. It is a working document, not a standard, and the calls behind it are stated further down.

The taxonomy

Eight domains, not eight jobs

Every domain below runs from individual contributor to C-level. The title on a requisition is the least stable part of this market — the domain and the level are what actually determine fit. Click a card to see the ladder.

01

Governance

Policy, program ownership and the approval gate for how AI gets built and shipped.

$95K – $400K+
See the ladder
02

Risk

Model risk management and enterprise AI risk assessment. Deep overlap with banking model risk.

$100K – $320K+
See the ladder
03

Compliance

Regulatory readiness against the state patchwork and customer contractual obligations.

$90K – $300K+
See the ladder
04

Audit & Assurance

Independent testing and attestation that controls actually work. The function this practice is named for.

$100K – $310K+
See the ladder
05

Privacy

Technical safeguards for user data inside ML systems. Blends engineering, privacy law and model design.

$110K – $290K+
See the ladder
06

Security

ML security, LLM security architecture and AI red teaming. Prices against security bands, not compliance.

$120K – $340K+
See the ladder
07

Safety & Trust

Trust and safety, bias mitigation, alignment. Concentrated at frontier labs; bias mitigation crosses into the enterprise.

$95K – $300K+
See the ladder
08

Data Governance

Provenance, lineage and stewardship of training data. Upstream of every other domain here.

$90K – $270K+
See the ladder
Governance — the ladder
ICAI Governance Analyst
ManagerAI Governance Manager
Head / DirectorDirector of AI Governance, Responsible AI Lead
VPVP of AI Governance
C-levelChief AI Officer, Chief AI Governance Officer
Risk — the ladder
ICAI Risk Analyst
ManagerAI Risk Manager
Head / DirectorDirector of AI Risk, Head of Model Risk
VPVP of AI Risk Management
C-levelChief Risk Officer (AI mandate)
Compliance — the ladder
ICAI Compliance Analyst
ManagerAI Compliance Manager
Head / DirectorAI Compliance Lead, Director of AI Compliance
VPVP of Compliance (AI mandate)
C-levelChief Compliance Officer
Audit & Assurance — the ladder
ICAI Auditor, IT Audit Analyst (AI scope)
ManagerAI Audit Manager
Head / DirectorHead of AI Audit, Director of Assurance
VPVP of Internal Audit (AI mandate)
C-levelChief Audit Executive
Privacy — the ladder
ICAI Privacy Engineer
ManagerAI Privacy Manager
Head / DirectorDirector of AI Privacy Engineering
VPVP of Privacy Engineering
C-levelChief Privacy Officer
Security — the ladder
ICML Security Engineer, AI Red Teamer
ManagerAI Security Engineering Manager
Head / DirectorLLM Security Architect, Director of AI Security
VPVP of AI Security, Field CISO
C-levelCISO (AI mandate)
Safety & Trust — the ladder
ICAI Trust & Safety Analyst, AI Safety Researcher
ManagerAI Bias Mitigation Specialist, Safety Engineering Manager
Head / DirectorHead of AI Safety, Responsible AI Lead
VPVP of Trust & Safety
C-levelChief Trust & Safety Officer — rare, mostly frontier labs
Data Governance — the ladder
ICData Governance Analyst (AI)
ManagerData Governance Manager (AI)
Head / DirectorDirector of Data Governance
VPVP of Data Governance
C-levelChief Data Officer (AI mandate)
One domain, worth a closer look

Safety & Trust behaves differently from the other seven

A smaller and differently-shaped population: AI Safety Researcher, AI Safety Engineer, Head of AI Safety, AI Alignment Researcher, Responsible AI Lead, AI Trust & Safety Analyst, AI Bias Mitigation Specialist.

Worth naming honestly — this domain concentrates almost entirely at frontier labs rather than across the general market. It is real, it is mappable, and it does not behave like the other seven. Candidates here are frequently motivated by research agenda over compensation, which changes the entire approach.

Bias mitigation is the exception that crosses over. It is the function most directly exposed to active EEOC enforcement on AI-driven hiring under Title VII, which makes it an enterprise hire as much as a lab one.

Professional working at a laptop
Boundaries

Where we focus

A specialist practice is defined as much by where it concentrates as by what it covers. These sit outside our focus, and we will happily refer them.

  • General cybersecurity. SOC leadership, network security, general CISO searches with no AI system in scope.
  • General privacy and data protection. GDPR and CCPA program work that does not touch model development or deployment.
  • Core ML engineering. Research scientists, ML platform and MLOps roles without a security, privacy or governance mandate.
  • AI transformation leadership. Chief AI Officer, Head of AI, VP AI Transformation. Adjacent, larger, and a different market — deliberately kept out of this taxonomy.
Contested calls

Five positions here worth arguing with

A taxonomy nobody disagrees with is not saying anything. These are the calls this map makes that a working practitioner might genuinely push back on, with the reasoning attached — so you can take issue with one without discarding the rest.

Security
A Field CISO is not a CISO. The title carries a C; the mandate does not. No internal security operations, no incident-response ownership, no line to the board. The role sits in or beside go-to-market and is measured the way go-to-market is measured — pipeline, deal velocity, win rate. Read as an executive security hire, it produces a shortlist of people who would be miserable in the job within a quarter.
Governance
A governance seat without authority to stop a launch is a documentation seat. That can still be useful work. It is not the work most companies believe they are buying when an audit finding lands. What decides this is where the role sits on the org chart, not what it is called — which is why the reporting line is worth pinning down ahead of the title or the band.
Sourcing
Red teaming converts from offensive security, rarely from audit. Both disciplines exist to find what is broken, and on paper the output looks similar enough that companies treat the backgrounds as interchangeable. Only one carries the instinct to break the thing first. That instinct does not arrive with a controls-testing history, and hiring as though it does is the most common way one of these searches stalls.
Risk
Banking model risk is the strongest feeder into AI risk. Validation, effective challenge, independent review, documentation standards — all of it has existed there as a formal discipline for roughly two decades. The models changed; the method did not. These candidates are routinely screened out for lacking "AI experience" while being the closest thing this market has to a trained population.
Supply
The credential is a floor, not a ceiling. Roughly four thousand people hold the field's anchor credential (AIGP), the number cited at the top of this page. It is a real qualification and a genuinely useful signal — but it is not the only one. A meaningful share of the strongest practitioners built governance functions from nothing before there was anything to sit for, or moved in from banking model risk, security research, or privacy law without certifying. Screening on the certificate alone removes some of the strongest talent who could easily take and pass the AIGP exam.
Low angle view of office towers
Disagree with the map?

Tell us where it's wrong. That's how it gets better.

If you work in this field and the boundaries here don't match what you see, we want to hear it.