AI governance roles
The newest job family in GRC. These templates reflect how regulated enterprises are actually defining the work.
Chief AI Officer (CAIO)
The senior executive who owns enterprise AI strategy, adoption, and responsible governance, turning business objectives into value while keeping AI safe and compliant.
Chief Compliance Officer (CCO)
The senior executive who owns the enterprise compliance and ethics program, keeping the organization aligned with law, regulation, and its own standards of conduct.
Chief Privacy Officer (CPO)
The senior executive who owns the enterprise privacy program, protecting personal data and keeping the organization compliant with data protection law worldwide.
Chief Risk Officer (CRO)
The senior executive who owns enterprise risk management, setting appetite and governance so the organization understands and controls the risks it takes.
Chief Audit Executive (CAE)
The senior executive who leads internal audit, giving the Board and leadership independent, objective assurance over governance, risk management, and control.
AI Auditor
An independent assurance specialist who audits AI systems and governance controls against recognized frameworks and reports findings to management.
AI Governance Manager
The manager who operates an organization's AI governance program, turning policy into working intake, review, oversight, and reporting processes.
AI Security Architect
The architect who designs security controls that protect AI models, data, and pipelines from adversarial and conventional threats across the lifecycle.
AI Policy Analyst
The analyst who tracks AI laws, standards, and policy and translates them into practical guidance and internal control mappings.
Ethical AI Specialist
A responsible AI specialist who assesses AI systems for fairness, transparency, and harm and guides teams toward ethical design choices.
AI Risk Manager
The manager who identifies, assesses, and mitigates AI risk across models and use cases and keeps it within the organization's risk appetite.
AI Privacy & Compliance Analyst
The analyst who reviews how AI systems use personal data and tests them against privacy law and compliance obligations across the lifecycle.
Technology Policy Advisor
The advisor who analyzes technology and AI policy, shapes organizational positions, and supports engagement with policymakers and stakeholders.
Compliance Analyst
The analyst who tracks regulatory obligations, tests compliance controls, maintains policies, and prepares the reporting that keeps the organization examination-ready.
Compliance Manager
The owner of the operating compliance program who turns regulatory obligations into policy, controls, monitoring, and training, and leads the team that runs it.
Risk Analyst
The analyst who identifies, measures, and monitors organizational risk, maintains the risk register, and turns analysis into clear reporting for decision makers.
Risk Manager
The owner of the operating risk program who sets methodology and appetite, drives assessment and monitoring, and leads the analysts who run it.
Internal Auditor
The professional who provides independent assurance over controls, risks, and processes through audit planning, testing, evidence, and clear reporting.
Data Governance Lead
The owner of the data governance program who sets policy, ownership, and quality standards so data stays trustworthy for decisions, analytics, and AI.
Privacy Counsel
The organization's legal advisor on privacy and data protection, guiding how personal data is collected, used, shared, and protected in line with the law.
Chief AI Risk Officer (CAIRO)
The senior executive owning enterprise AI risk: strategy, governance, regulatory compliance, and Board reporting across the model lifecycle.
AI Governance Analyst
The operational backbone of an AI governance program: inventories, intake review, risk classification, and control monitoring.
Chief Technology Officer (CTO)
Executive ownership of technology strategy and engineering, including the governance, risk, and security posture of the company's technology and AI systems.
AI Risk Officer
Second-line ownership of AI risk appetite, assessment methodology, and escalation for high-risk use cases.
AI Compliance Lead
Translates the EU AI Act, state AI laws, and sector rules into controls, evidence, and audit readiness.
Responsible AI Lead
Principles into practice: fairness testing, transparency standards, and review boards that actually function.
Model Risk Manager
SR 11-7 heritage meets machine learning: validation, documentation, and ongoing monitoring for models in production.
GRC and security leadership
Core governance, risk, and security roles, written with the AI-era responsibilities employers now expect.
GRC Manager
Owns the control framework, audit calendar, and risk register across security, privacy, and now AI.
Privacy Engineer
Builds privacy into systems: data mapping, minimization, DPIA tooling, and privacy-preserving techniques.
Chief Information Security Officer
Executive security leadership with board reporting, program strategy, and accountability for AI security posture.
Ready to hire?
Every posting on GRC Careers is hand reviewed and reaches specialists in AI governance, risk, and compliance. Most roles go live within one business day.