You have exposure. Let's work out what that means as a job.
Most of these searches begin with a problem, not a requisition. That is the right place to start, and it is where the useful work happens.
The four ways this lands on your desk
An enterprise customer sent a vendor security questionnaire nobody could answer. An auditor asked who signs off on model changes and the room went quiet. A board member read something and asked a direct question. Or a state statute arrived with a date attached.
All four produce the same next step: someone is told to "hire an AI governance person," with no clear sense of whether that means a policy leader, an engineer, or someone who can sit in a customer's security review and win it.
Getting that wrong is expensive twice — once in the wasted search, and again in the six months you spent believing the problem was covered.
Five steps, and the first one isn't sourcing
The scoping call does the heaviest lifting. Several of these engagements have ended there, with a client who no longer needed the hire they thought they needed.
Scope the exposure, not the title
We work backwards from what actually triggered this — the audit finding, the stalled deal, the statute. That determines which of the eight functions you are really hiring, what the role can be held accountable for, and who it has to report to in order to have any authority at all.
Define the role against the market
You get a written role definition with a comp band grounded in live posting data, plus an honest read on which adjacent backgrounds convert well and which look right on paper and fail in practice. Privacy counsel moving into AI governance usually works. Generalist compliance managers usually do not.
Map the population before contacting anyone
Credential holders, framework authors, OWASP GenAI Security Project contributors (publishers of the LLM Top 10), Cloud Security Alliance working-group contributors, and practitioners with real deployment scars. Named, mapped, and ranked before a single message goes out — which is the only way to run outreach in a market this small without burning it.
Approach as a peer, not a pitch
These candidates get contacted constantly and screen recruiters hard. Outreach references the specific work — a framework they wrote, a talk they gave, a problem their team owns. Everything is confidential by default; most of these people are not telling anyone they took the call.
Submit with the reasoning attached
Every submission carries what was verified, what is inferred, and what we could not confirm — stated plainly. You should be able to disagree with our read, and to see exactly where the evidence stops and the judgment starts.
Market intelligence, whether or not you hire
- A written role definition you can circulate internally — including what this role cannot be held accountable for.
- Live comp banding from current US posting data, not a national salary survey from last year.
- A named population map — how many people in the country credibly do this, and how many are reachable for you specifically.
- Competitive read on who else is hiring the same profile right now and what they are paying for it.
- A direct answer on feasibility. If the role as written cannot be filled at that band, you will hear it on the first call.
Most know they have exposure. They don't know what to hire for. Translating a compliance problem into a role definition, a comp band and three names worth talking to — that is the job.
Bring the problem. The requisition can wait.
Thirty minutes. You will leave with a role definition and a comp band whether or not we work together.