AI governance roles
The newest job family in GRC. These templates reflect how regulated enterprises are actually defining the work.
Chief Information Officer (CIO)
The senior executive accountable for enterprise IT strategy, operations, and technology governance, aligning systems and data with business objectives and managing technology risk.
Chief Data Officer (CDO)
The senior executive accountable for enterprise data strategy, governance, quality, and analytics, treating data as a strategic asset and ensuring it is used responsibly.
Chief Ethics Officer
The senior executive accountable for the organization's ethics and integrity program, owning the code of conduct, ethical culture, and conduct investigations.
Data Protection Officer (DPO)
The organization's independent authority on data protection, monitoring GDPR compliance, advising on processing, and serving as contact for regulators and data subjects.
VP of Enterprise Risk Management
The senior leader of the enterprise risk program, owning the ERM framework, risk appetite, and reporting that gives leadership a clear view of enterprise risk.
VP of Compliance
The senior leader of the enterprise compliance program, owning policies, monitoring, regulatory change, and compliance reporting to leadership and the Board.
Head of AI Governance
The senior leader of the enterprise AI governance program, owning the framework, policies, and oversight that keep AI systems responsible and compliant.
AI Ethics Officer
The steward of the organization's AI ethics principles, embedding fairness, transparency, and accountability into how AI is built and used.
Operational Risk Manager
The manager of the day-to-day operational risk program, running RCSA, loss events, Key Risk Indicators, and control monitoring across the business.
Enterprise Risk Analyst
The analyst supporting the enterprise risk program with risk assessments, register maintenance, Key Risk Indicators, analysis, and reporting.
Regulatory Compliance Manager
Runs the day-to-day compliance program, turning regulatory obligations into policies, controls, and monitoring across the business.
Third-Party Risk Manager
Owns the vendor and supplier risk program, from onboarding due diligence through ongoing monitoring and offboarding.
IT Auditor
Evaluates the design and operating effectiveness of technology controls across systems, applications, and infrastructure.
Cybersecurity Compliance Analyst
Helps the organization meet its security control obligations by mapping requirements, collecting evidence, and supporting audits and certifications.
AML Compliance Analyst
Reviews alerts, investigates suspicious activity, and files reports to help the organization meet its anti-money laundering obligations.
Healthcare Compliance Manager
Runs the healthcare compliance program, covering HIPAA privacy and security, fraud and abuse, and the elements of an effective compliance program.
Financial Crimes Compliance Analyst
Investigates fraud, money laundering, and other illicit activity to help the organization detect and disrupt financial crime.
Cloud Security Compliance Engineer
Builds and automates the controls that keep cloud environments secure and audit-ready, turning requirements into enforceable configuration and code.
AI Assurance Manager
Provides independent assurance that AI systems and the AI management system are governed, controlled, and compliant through audit and conformity assessment.
Trust and Safety Manager
Owns the policies, processes, and enforcement that keep a platform safe, from content moderation to abuse response and regulatory obligations.
Chief AI Officer (CAIO)
The senior executive who owns enterprise AI strategy, adoption, and responsible governance, turning business objectives into value while keeping AI safe and compliant.
Chief Compliance Officer (CCO)
The senior executive who owns the enterprise compliance and ethics program, keeping the organization aligned with law, regulation, and its own standards of conduct.
Chief Privacy Officer (CPO)
The senior executive who owns the enterprise privacy program, protecting personal data and keeping the organization compliant with data protection law worldwide.
Chief Risk Officer (CRO)
The senior executive who owns enterprise risk management, setting appetite and governance so the organization understands and controls the risks it takes.
Chief Audit Executive (CAE)
The senior executive who leads internal audit, giving the Board and leadership independent, objective assurance over governance, risk management, and control.
AI Auditor
An independent assurance specialist who audits AI systems and governance controls against recognized frameworks and reports findings to management.
AI Governance Manager
The manager who operates an organization's AI governance program, turning policy into working intake, review, oversight, and reporting processes.
AI Security Architect
The architect who designs security controls that protect AI models, data, and pipelines from adversarial and conventional threats across the lifecycle.
AI Policy Analyst
The analyst who tracks AI laws, standards, and policy and translates them into practical guidance and internal control mappings.
Ethical AI Specialist
A responsible AI specialist who assesses AI systems for fairness, transparency, and harm and guides teams toward ethical design choices.
AI Risk Manager
The manager who identifies, assesses, and mitigates AI risk across models and use cases and keeps it within the organization's risk appetite.
AI Privacy & Compliance Analyst
The analyst who reviews how AI systems use personal data and tests them against privacy law and compliance obligations across the lifecycle.
Technology Policy Advisor
The advisor who analyzes technology and AI policy, shapes organizational positions, and supports engagement with policymakers and stakeholders.
Compliance Analyst
The analyst who tracks regulatory obligations, tests compliance controls, maintains policies, and prepares the reporting that keeps the organization examination-ready.
Compliance Manager
The owner of the operating compliance program who turns regulatory obligations into policy, controls, monitoring, and training, and leads the team that runs it.
Risk Analyst
The analyst who identifies, measures, and monitors organizational risk, maintains the risk register, and turns analysis into clear reporting for decision makers.
Risk Manager
The owner of the operating risk program who sets methodology and appetite, drives assessment and monitoring, and leads the analysts who run it.
Internal Auditor
The professional who provides independent assurance over controls, risks, and processes through audit planning, testing, evidence, and clear reporting.
Data Governance Lead
The owner of the data governance program who sets policy, ownership, and quality standards so data stays trustworthy for decisions, analytics, and AI.
Privacy Counsel
The organization's legal advisor on privacy and data protection, guiding how personal data is collected, used, shared, and protected in line with the law.
Chief AI Risk Officer (CAIRO)
The senior executive owning enterprise AI risk: strategy, governance, regulatory compliance, and Board reporting across the model lifecycle.
AI Governance Analyst
The operational backbone of an AI governance program: inventories, intake review, risk classification, and control monitoring.
Chief Technology Officer (CTO)
Executive ownership of technology strategy and engineering, including the governance, risk, and security posture of the company's technology and AI systems.
AI Risk Officer
Second-line ownership of AI risk appetite, assessment methodology, and escalation for high-risk use cases.
AI Compliance Lead
Translates the EU AI Act, state AI laws, and sector rules into controls, evidence, and audit readiness.
Responsible AI Lead
Principles into practice: fairness testing, transparency standards, and review boards that actually function.
Model Risk Manager
SR 11-7 heritage meets machine learning: validation, documentation, and ongoing monitoring for models in production.
GRC and security leadership
Core governance, risk, and security roles, written with the AI-era responsibilities employers now expect.
GRC Manager
Owns the control framework, audit calendar, and risk register across security, privacy, and now AI.
Privacy Engineer
Builds privacy into systems: data mapping, minimization, DPIA tooling, and privacy-preserving techniques.
Chief Information Security Officer
Executive security leadership with board reporting, program strategy, and accountability for AI security posture.
Ready to hire?
Every posting on GRC Careers is hand reviewed and reaches specialists in AI governance, risk, and compliance. Most roles go live within one business day.