GRC Careers: Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Home › AI Governance Insights › What the job actually is: why a job title tells you less than you think

What the job actually is: why a job title tells you less than you think

By Jonathan Malchow Vega, Director of Digital Strategy, GRC Careers · October 7, 2026 · 9 min read

My last essay ended on a question: which word do you type? Five employers advertised what was more or less the same job under five different titles, and two of those titles never used the words "AI governance" at all. Search the titles for that phrase and you would miss them.

The obvious fix is to tell the search engine that those titles mean the same thing. Librarians have done that for more than a century. I do think it is worth explaining how, because the fix only goes so far, and the next step is where things get interesting.

How a library finds a book you can't name

Walk into a library looking for something on heart disease. The book you need might be titled The Broken Heart, or Cardiac Care, or something with no medical words in it at all. You will still find it. Why?

Because somebody, a cataloger, read the book and gave it a subject heading. Every book about heart disease gets the same heading, whatever the author called it. The title is the author's choice. The heading is the library's description of what the book is actually about. Search the heading and you get all of them.

That is the controlled vocabulary I wrote about last time. Pick one agreed term, point all the variations at it, and nobody has to guess the right word.

It works. It also has a limit. At its simplest, it tells you which words mean the same thing. It doesn't tell you how the work behind them differs.

A title, a job opening and a role are three different things

Here is the distinction that changes how you read a job posting. When we say "the job," we usually mean three things at once.

  • The opening. A specific vacancy, at a specific company, posted on a specific date. It closes.
  • The title. The words in the title bar. It is the first thing a job seeker searches for and the first thing they see.
  • The role. The kind of work that shows up again and again across different employers. Nobody posts "the role," because it isn't a vacancy. It is what all the vacancies have in common.

Underneath the role is the work itself: the tasks a person does every day, and the things those tasks produce. In AI governance those things are concrete. A list of every AI system the company uses. A checklist for assessing new ones. A folder of evidence ready for when an auditor asks. Those are what gets inspected when someone asks for proof, so they are a better guide to the job than any title.

Once you pull those apart, you can compare two postings by what the job involves, not by what the company decided to call it.

The verb is the hard part

This is where it gets more demanding than it sounds.

Back to the five postings. Four of the tasks look almost the same: keeping a company's list of AI systems, reviewing other organizations' lists, recommending what paperwork should exist, and helping collect evidence for an audit. Read quickly, they are all one job. They are not.

Keeping a list is not checking somebody else's list. Recommending that paperwork exist is not writing it. Helping collect evidence is not being the one responsible for it.

Think of a company's money. The bookkeeper keeps the books. The auditor checks them. The consultant recommends how they should be kept. All three work "in finance," and nobody would hire an auditor to do the bookkeeping. AI governance borrows a great deal from that world of audit and controls, so the comparison is closer than it looks.

So when I describe a posting, the verb has to match what the posting actually says. Take two real examples. The White House budget office's posting describes reviewing government agencies' lists of AI uses; I checked that against the original announcement on USAJOBS. TransUnion asks its analyst to manage its own list. Both are inventory work, so someone searching for one should find the other. They are still different jobs, and the description shouldn't pretend otherwise. The verb doesn't get upgraded because the upgrade would be convenient.

Where the tasks come from

A list of tasks taken only from job postings tells you what employers happen to write this year. That is useful. It isn't the last word.

The last word sits in the rules and standards the work exists to satisfy. In AI governance there are three big ones:

  • The NIST AI Risk Management Framework, released in January 2023. It is voluntary, and it is built around four functions: govern, map, measure and manage.
  • ISO/IEC 42001, published in December 2023, the international standard for running an AI management system.
  • The EU AI Act, in force since August 2024, with most of its rules applying from August 2026. For high-risk systems it requires risk management, technical documentation, record-keeping and quality management.

The useful move is to tie each task back to the rule that requires it. When all three demand the same task, it doesn't matter much what title is attached to it. That is about the best evidence you can get that you are looking at a real job and not just one company's naming habit.

Linking things this way is what an ontology does: the title to the role, the role to its tasks, and each task to the evidence it produces and the standard that requires it. A controlled vocabulary mostly tells you which words mean the same thing, and which are broader or narrower. An ontology says exactly how things connect. A map instead of a dictionary.

A wooden card-catalog drawer whose index cards turn into a network of connected points, under the title What the job actually is.

Three answers, not two

The part I care about most is what a search says when it finds nothing.

There are really three possible answers. Yes, here it is. No, we looked in this collection, on this date, and it isn't there. Or: nobody has looked yet.

Most systems squash the last two together into one empty screen, and to a job seeker an empty screen reads as "this doesn't exist." That isn't honest. If nobody has looked, the search should say so.

Any archivist will tell you this is basic. A finding aid tells you what a collection holds, and a good one also tells you what is missing and what hasn't been processed yet. It would change how a job board behaves, because "no results" would become a statement somebody could actually check.

The honest objection

Here is the objection I take seriously. If two jobs share a task, am I saying they are the same job? That would help job seekers at employers' expense.

It would, if I said it. I am not saying it.

Two jobs sharing a task means a search for one should show you the other. It does not mean they have the same seniority, the same authority or the same pay. The budget office role is a supervisory GS-15 post, the top grade of the federal General Schedule. TransUnion's was advertised at about $79,000 to $131,000, and inside the company the same job is called Consultant, Risk Management, which is a sixth name for work already carrying five.

Finding something and being equal to it are two different claims. A search tool that mixes them up is worse than no tool at all, because it tells people they qualify for jobs they don't.

What I am building

The five postings in my first essay showed the problem. The work now is building something that solves it.

I am putting all of this into a working model, a research prototype for now. It has four parts. A vocabulary that maps the many job titles to agreed terms, the way a catalog maps book titles to subject headings. An ontology that links each title to its tasks, the evidence those tasks produce and the standards behind them. Rules for checking every entry, so a task isn't recorded as "keeping" the list when the posting only says "reviewing" it. And a set of plain questions the model has to answer correctly, such as "show me every job that involves the AI inventory, whatever it is called."

Every decision about how a posting is described is set up to go through a review step, the same way a cataloger's record gets checked before it goes into the catalog. A first batch of twenty postings is already collected straight from employers' own announcements, with a written record of how each one was found.

The next step is the one I am most looking forward to: testing it on postings it has never seen, with a second reader checking a share of the work independently, to measure how much better it finds the right jobs. When I have that number, I will share it here.

What I would ask a hiring manager

Write the tasks before you write the title.

If the person will keep the list of AI systems, say keep. If they will check a list somebody else keeps, say check. If they will recommend that paperwork exist and someone else will write it, say recommend. Then name the rule the task answers to.

After that, use whatever title your org chart needs. It won't matter as much, because the description will be doing the job the title was failing to do.

Sources. Postings as cited in "One job, five titles": the White House Office of Management and Budget, USAJOBS announcement 873842400 (open 23 to 30 June 2026); TransUnion's posting, advertised at $78,750 to $131,250 (rounded in both essays to $79,000 to $131,000), internal title Consultant, Risk Management; AlphaSense requisition 8648659002; New York Power Authority; Carrington Mortgage Services. Frameworks: NIST AI RMF 1.0, released 26 January 2023; ISO/IEC 42001, published 18 December 2023; EU AI Act, in force 1 August 2024 and generally applicable 2 August 2026.

Who's Hiring AI Governance Professionals?

Explore current openings in:

AI Governance Jobs · Responsible AI · AI Risk · AI Compliance · AI Audit · AI Policy · Privacy · Cybersecurity · Public Policy

Search the latest opportunities at GRC Careers › · nonprofit GRC jobs ›