Professionals walking toward an office building
AI Governance, Risk & Compliance Search

Most companies know they have AI exposure.
We source the talent to close the gap.

Whether you need a senior leader to own your AI governance, risk, and compliance function or a specialist within one of these domains, we find professionals who have done the work.

14,000+
Open US roles carrying an AI governance title
71 / week
Net-new US postings, flat through 2026 — no seasonal dip
~4,000
AIGP credential holders worldwide
8
Distinct domains often bundled into a single requisition
The actual problem

The reason your requisition isn't working

Three years ago most of these jobs did not exist. The work has since pulled people out of security, privacy, legal, audit and model risk — each arriving with its own established vocabulary. Plenty of companies have defined these roles clearly for themselves. What almost nobody has is a map that translates between them.

That matters more than it sounds. A requisition written in one company's vocabulary still has to reach candidates who describe the same work in another's. Where that translation is missing, the post goes up anyway — and the pipeline fills with privacy generalists and security engineers who have never been near a model. Ninety days later the role is still open and the audit date has not moved.

We did not invent these categories. NIST's AI Risk Management Framework, ISO/IEC 42001 and the IAPP already define the work. What none of them settle is whether it is one hire or four, what to title them, what each one costs, or which adjacent backgrounds actually convert — the IAPP's own profession research finds no clear best practice for how these teams get built. That hiring layer is what we built: eight domains, the boundary lines between them, and what each one is worth. It sits behind every search we run. If your team already has it mapped, say so on the first call and we will work from your definitions rather than ours.

Reviewing documents and analysis at a desk
3:1
Demand-to-supply gap — before accounting for how many credential holders are practising full time.
Supply & demand

A thin market, and thinner than the headline number

Roughly four thousand people worldwide hold the field's anchor credential. More than fourteen thousand US roles are open against it. The gap is the whole business case for a specialist.

Open US rolesAI governance titles
14,000+
Credentialed supplyAIGP holders, worldwide
~4,000

AIGP figure recurs across sources but is not published by IAPP directly — treat as directional. Certification is not the only qualification; the true practitioner pool is larger. It remains thin by any measure.

Two markets, not one

These roles get created for two completely different reasons

Same titles on paper. Different budget holder, different urgency, different definition of a good hire. Most search firms only notice the first one.

Channel one

The enterprise deploying AI

Hires to stay out of trouble. The trigger is an audit finding, a board question, a customer's vendor questionnaire, or a state statute with a date attached to it.

This buyer usually knows they have exposure and does not yet know what to call the person who fixes it. Half of the work is translating a risk problem into a role definition, a comp band, and three names worth talking to.

BudgetLegal, Risk, Privacy, or the CISO
TriggerAudit, board exposure, regulatory date
Measured onControl coverage and defensibility
Channel two

The AI vendor selling into that enterprise

An AI vendor's deal rarely dies in the product evaluation. It dies in the security review that comes afterward. Someone has to own that room, and increasingly that someone is a dedicated hire.

The clearest expression is the Field CISO — a role that runs no internal security operations at all. It exists to enable sales, and it is measured the way sales is measured: pipeline, deal velocity, win rate. It is a revenue function wearing a security title.

BudgetGo-to-market leadership
TriggerEnterprise deals stalling in vendor review
Measured onPipeline, velocity, win rate
The taxonomy

Eight domains. Every seniority level inside each one.

Clients frequently arrive describing a single hire, defined by a title. Titles travel badly between companies — the domain and the level underneath are what actually determine who fits.

01

Governance

Policy, program ownership and the approval gate for how AI gets built and shipped. Runs from analyst to Chief AI Officer.

$95K – $400K+
02

Risk

Model risk management and enterprise AI risk assessment. Strong overlap with banking model risk, at every level.

$100K – $320K+
03

Compliance

Regulatory readiness against the state patchwork and customer contracts. IC through compliance executive.

$90K – $300K+
04

Audit & Assurance

Independent testing and attestation that controls actually work. The function this practice is named for.

$100K – $310K+
05

Privacy

Privacy engineering and data protection inside ML systems. Blends engineering, law and model design.

$110K – $290K+
06

Security

ML security, LLM security architecture and AI red teaming. Prices against security bands, not compliance.

$120K – $340K+
07

Safety & Trust

Trust and safety, bias mitigation, alignment. Concentrated at frontier labs, with bias mitigation the enterprise crossover.

$95K – $300K+
08

Data Governance

Provenance, lineage and stewardship of training data. Upstream of every other function on this map.

$90K – $270K+
Why now, in the US

The forcing function isn't one law. It's liability.

There is no single American statute playing the role the EU AI Act plays in Europe. What exists instead is a live state patchwork — Texas's TRAIGA and California's SB 53 and AB 2013 all in force since January 2026, Colorado's original framework repealed and rewritten — layered under a federal effort to preempt state AI law entirely.

Betting a hiring thesis on any one of those surviving would be foolish. The durable driver sits underneath all of it: enforcement under laws that already exist. Thirty documented federal AI enforcement actions as of July 2026 across the FTC, SEC, DOJ, EEOC and FCC. A $17M FTC settlement over deceptive AI claims. Active EEOC pursuit of AI-driven hiring discrimination under Title VII. D&O policies beginning to carve out AI exposure.

That is board-level liability, and it does not depend on one bill surviving one political fight.

Low angle view of corporate high-rise buildings
Chris Jensen
Chris Jensen
Founder · AI Assurance Talent
Who you're actually working with

Eleven years hiring into AI companies, before it was a category

I have spent eleven years building go-to-market teams for AI startups — US and international — including one working on agentic systems well before anyone had a name for that. Most of that time was spent on the hidden market: the people who are good enough that they are never actually on the market.

Some of that work put me in the middle of enterprise security reviews, coordinating between our engineers and the security teams at brands like Cigna, Amazon, Meta and Omnicom. Often the pilots went well and the relationships were heading toward enterprise licenses until they stalled — not because we could not answer the questions, but because we lacked the talent who understood these were non-negotiable and could actually execute a plan to address each item while the deal was still live.

That skill transfers directly, because this is a passive-talent problem before it is anything else. Four thousand credential holders worldwide. The strong ones are employed, well paid, and not reading job boards.

So I am building this market map candidate-first, function by function — published where it is useful to the field, proprietary where it took real work. You will not be handed to an account manager. Every search on this site is one I run personally.

Straight answers

Questions we get every week

AI governance is the internal system that decides how AI gets built and shipped — who approves a model, what testing it has to survive, who is accountable when it misbehaves. AI compliance is the narrower job of proving that system satisfies an external rule: a state statute, a customer contract, an auditor's request.

Governance is the machine. Compliance is the receipt. Companies routinely hire for the second when the problem is the first, which is how you end up with a compliance manager who has no authority to stop a launch.

Director-level scope generally runs $190K–$250K base, with executive scope reaching $250K–$400K and above. Median across the wider function sits near $169K.

One correction worth making early: the technical roles — ML security engineer, LLM security architect, red teamer — price against security engineering, not against compliance. Companies that band them as compliance roles do not get callbacks, and usually cannot work out why.

It depends entirely on why the role was created. Compliance-triggered hires normally sit under Legal, Risk, or the Chief Privacy Officer. Security-triggered hires sit under the CISO.

At AI vendors it is often neither — if the role exists to clear customer security reviews and unblock revenue, it belongs in go-to-market, and treating it as a compliance seat will cost you the candidates who are good at it.

You can. The constraint is reach: a post reaches the market segment that is actively looking. We take a different approach with focused engagement to professionals who are employed, stable, and not reading job posts in any given week. Building relationships with this audience is a different motion.

Another challenge is knowing what to post — whether you want a governance director, a privacy engineer or a red teamer, and whether the people doing this work call it the same thing.

Fair question, and we pressure-tested it before committing. Posting volume has held flat at roughly 71 net-new US roles a week through the first seven months of 2026 — no seasonal collapse, which is the pattern hype markets show first.

There is also a direct precedent. GDPR created the Data Protection Officer, which turned into a durable specialist recruiting niche that still exists eight years later. Regulatory-created roles do not tend to evaporate; they get absorbed into the org chart.

Two colleagues in conversation
Start here

Tell us what broke, and we'll tell you what to hire.

Whether that turns into a search is a second conversation. The first one is free and usually saves a quarter.

Team working together around a table
For hiring teams

You have exposure. Let's work out what that means as a job.

Most of these searches begin with a problem, not a requisition. That is the right place to start, and it is where the useful work happens.

What usually happened first

The four ways this lands on your desk

An enterprise customer sent a vendor security questionnaire nobody could answer. An auditor asked who signs off on model changes and the room went quiet. A board member read something and asked a direct question. Or a state statute arrived with a date attached.

All four produce the same next step: someone is told to "hire an AI governance person," with no clear sense of whether that means a policy leader, an engineer, or someone who can sit in a customer's security review and win it.

Getting that wrong is expensive twice — once in the wasted search, and again in the six months you spent believing the problem was covered.

Professional presenting during a working session
How a search runs

Five steps, and the first one isn't sourcing

The scoping call does the heaviest lifting. Several of these engagements have ended there, with a client who no longer needed the hire they thought they needed.

01

Scope the exposure, not the title

We work backwards from what actually triggered this — the audit finding, the stalled deal, the statute. That determines which of the eight functions you are really hiring, what the role can be held accountable for, and who it has to report to in order to have any authority at all.

02

Define the role against the market

You get a written role definition with a comp band grounded in live posting data, plus an honest read on which adjacent backgrounds convert well and which look right on paper and fail in practice. Privacy counsel moving into AI governance usually works. Generalist compliance managers usually do not.

03

Map the population before contacting anyone

Credential holders, framework authors, OWASP GenAI and Cloud Security Alliance working-group contributors, and practitioners with real deployment scars. Named, mapped, and ranked before a single message goes out — which is the only way to run outreach in a market this small without burning it.

04

Approach as a peer, not a pitch

These candidates get contacted constantly and screen recruiters hard. Outreach references the specific work — a framework they wrote, a talk they gave, a problem their team owns. Everything is confidential by default; most of these people are not telling anyone they took the call.

05

Submit with the reasoning attached

Every submission carries what was verified, what is inferred, and what we could not confirm — stated plainly. You should be able to disagree with our read, and to see exactly where the evidence stops and the judgment starts.

What you get

Market intelligence, whether or not you hire

  • A written role definition you can circulate internally — including what this role cannot be held accountable for.
  • Live comp banding from current US posting data, not a national salary survey from last year.
  • A named population map — how many people in the country credibly do this, and how many are reachable for you specifically.
  • Competitive read on who else is hiring the same profile right now and what they are paying for it.
  • A direct answer on feasibility. If the role as written cannot be filled at that band, you will hear it on the first call.

Most know they have exposure. They don't know what to hire for. Translating a compliance problem into a role definition, a comp band and three names worth talking to — that is the job.

Chris Jensen · AI Assurance Talent
Working session around a conference table
Scoping call

Bring the problem. The requisition can wait.

Thirty minutes. You will leave with a role definition and a comp band whether or not we work together.

Two professionals in conversation
For AI GRC talent

You're not on the market. That's exactly why we should talk.

The strongest people in this field are employed, well compensated, and not browsing postings. Everything here is built around that, starting with the fact that no conversation obligates you to anything.

Why you're getting contacted

Your title probably undersells what you do

Job titles in this field travel badly between companies. People doing genuine model risk management are titled compliance managers in one org and risk leads in the next. People running adversarial testing programs are titled security engineers. People who built an entire AI governance function from nothing are titled whatever the org chart had available at the time.

That gap costs money. It costs it at the offer stage, and it costs it earlier when a company screens you out because their keyword search did not know what you were called.

We can tell you what your actual scope is worth right now — not from a salary survey, but from live US posting data and the offers currently moving in this market.

Professionals in a working discussion
$169K
Median across the function. Executive scope runs $250K–$400K+.
How we work with candidates

Four commitments, and we'd rather you hold us to them

01

Your name doesn't move without your say-so

Not to a client, not to a "we're just gauging interest" conversation, not in an anonymised profile detailed enough to identify you. In a market of a few thousand practitioners, discretion is not a courtesy — it is the entire basis for talking to us at all.

02

We'll tell you when a role is wrong for you

Including when it is wrong in ways the hiring company has not admitted to itself — a governance role with no authority to stop a launch, a compliance seat that reports three levels below where the decisions get made, a Field CISO title over a job that is actually solutions engineering.

03

You get the comp read before you need it

What your scope is worth, where the band moves for your specific function, and which parts of your background the market is currently paying a premium for. Useful in your next internal review even if you never take a call with us.

04

Staying put is a legitimate outcome

Plenty of these conversations end with someone deciding they are in the right seat. That is a good result. This market is small enough that we would rather be the people you call in three years than the one who pushed you into a bad move now.

Where we work

If your work sits anywhere in here, we should be in contact

Whether or not anything is open right now, and whether you are an individual contributor or running the function. The map is more useful to both of us when it is built ahead of the need.

Governance

Policy & Program

Policy ownership, program leadership, the approval gate for AI deployment — analyst through Chief AI Officer.

Risk

Model & Enterprise Risk

Model risk management, AI risk assessment, third-party and vendor AI risk, at every level of seniority.

Compliance

Regulatory Readiness

Regulatory readiness against the state patchwork and customer contracts, from analyst to compliance executive.

Audit

Audit & Assurance

Independent testing and attestation. The function this practice is named for, underrepresented everywhere else.

Privacy

Privacy Engineering

AI privacy engineering, data protection for ML systems, privacy-preserving architecture, at every level.

Security

AI & ML Security

ML security engineering, LLM security architecture, AI red teaming, adversarial testing — plus the Field CISO track.

Safety

Trust & Safety

AI trust and safety, misuse monitoring, bias mitigation, alignment. Concentrated at frontier labs.

Data

Data Governance

Training-data provenance, lineage, quality and stewardship for AI systems, at every level.

Why people actually take the call

Advancement is one reason to talk. It is rarely the only one.

Moving up a title is the obvious reason to pick up the phone. It is not the most common one. Here is what usually starts the conversation instead.

01

The comp read

What your scope is actually worth right now, from live posting data rather than a survey. Useful in a review whether or not you ever take a role.

02

Equity and upside

Same title, same band, very different equity story. Post-Series-B versus pre-seed versus public changes what the offer is actually worth.

03

A more technical seat

Moving from a policy-heavy version of this work into one with real technical depth, or the reverse — both are common, and both change what the next five years look like.

04

A more technical industry

Same function, a company or sector where the AI risk is sharper and the work is closer to the actual model, not three layers of process removed from it.

05

Culture and authority

A governance seat with no authority to stop a launch looks identical to a strong one on paper. What the role can actually do matters more than the title on it.

06

A lateral that isn't lateral

Same level, same title, a genuinely different job — moving from compliance-triggered work into the vendor/GTM side, or from IC depth into building a function from zero.

07

Staying visible, not moving

Plenty of good conversations end with someone staying put, better informed. In a market this small, being known before you need something is worth more than a fast placement.

08

You're just not sure yet

You don't need a thesis on why you might move. A confidential conversation, off the record, is enough of a reason on its own.

Professionals seated in a meeting
No obligation

Start with the comp read. Decide about the rest later.

Confidential by default. Nothing moves without your explicit go-ahead.

Analysis and documents on a working desk
Coverage map

Eight domains. Every level inside each one. Click a card for the ladder.

A hiring layer on top of the frameworks that already exist — NIST, ISO/IEC 42001, the IAPP. They define the work; this maps it to roles, levels and bands. It is a working document, not a standard, and the calls behind it are stated further down.

The taxonomy

Eight domains, not eight jobs

Every domain below runs from individual contributor to C-level. The title on a requisition is the least stable part of this market — the domain and the level are what actually determine fit. Click a card to see the ladder.

01

Governance

Policy, program ownership and the approval gate for how AI gets built and shipped.

$95K – $400K+
See the ladder
02

Risk

Model risk management and enterprise AI risk assessment. Deep overlap with banking model risk.

$100K – $320K+
See the ladder
03

Compliance

Regulatory readiness against the state patchwork and customer contractual obligations.

$90K – $300K+
See the ladder
04

Audit & Assurance

Independent testing and attestation that controls actually work. The function this practice is named for.

$100K – $310K+
See the ladder
05

Privacy

Technical safeguards for user data inside ML systems. Blends engineering, privacy law and model design.

$110K – $290K+
See the ladder
06

Security

ML security, LLM security architecture and AI red teaming. Prices against security bands, not compliance.

$120K – $340K+
See the ladder
07

Safety & Trust

Trust and safety, bias mitigation, alignment. Concentrated at frontier labs; bias mitigation crosses into the enterprise.

$95K – $300K+
See the ladder
08

Data Governance

Provenance, lineage and stewardship of training data. Upstream of every other domain here.

$90K – $270K+
See the ladder
Governance — the ladder
ICAI Governance Analyst
ManagerAI Governance Manager
Head / DirectorDirector of AI Governance, Responsible AI Lead
VPVP of AI Governance
C-levelChief AI Officer, Chief AI Governance Officer
Risk — the ladder
ICAI Risk Analyst
ManagerAI Risk Manager
Head / DirectorDirector of AI Risk, Head of Model Risk
VPVP of AI Risk Management
C-levelChief Risk Officer (AI mandate)
Compliance — the ladder
ICAI Compliance Analyst
ManagerAI Compliance Manager
Head / DirectorAI Compliance Lead, Director of AI Compliance
VPVP of Compliance (AI mandate)
C-levelChief Compliance Officer
Audit & Assurance — the ladder
ICAI Auditor, IT Audit Analyst (AI scope)
ManagerAI Audit Manager
Head / DirectorHead of AI Audit, Director of Assurance
VPVP of Internal Audit (AI mandate)
C-levelChief Audit Executive
Privacy — the ladder
ICAI Privacy Engineer
ManagerAI Privacy Manager
Head / DirectorDirector of AI Privacy Engineering
VPVP of Privacy Engineering
C-levelChief Privacy Officer
Security — the ladder
ICML Security Engineer, AI Red Teamer
ManagerAI Security Engineering Manager
Head / DirectorLLM Security Architect, Director of AI Security
VPVP of AI Security, Field CISO
C-levelCISO (AI mandate)
Safety & Trust — the ladder
ICAI Trust & Safety Analyst, AI Safety Researcher
ManagerAI Bias Mitigation Specialist, Safety Engineering Manager
Head / DirectorHead of AI Safety, Responsible AI Lead
VPVP of Trust & Safety
C-levelChief Trust & Safety Officer — rare, mostly frontier labs
Data Governance — the ladder
ICData Governance Analyst (AI)
ManagerData Governance Manager (AI)
Head / DirectorDirector of Data Governance
VPVP of Data Governance
C-levelChief Data Officer (AI mandate)
One domain, worth a closer look

Safety & Trust behaves differently from the other seven

A smaller and differently-shaped population: AI Safety Researcher, AI Safety Engineer, Head of AI Safety, AI Alignment Researcher, Responsible AI Lead, AI Trust & Safety Analyst, AI Bias Mitigation Specialist.

Worth naming honestly — this domain concentrates almost entirely at frontier labs rather than across the general market. It is real, it is mappable, and it does not behave like the other seven. Candidates here are frequently motivated by research agenda over compensation, which changes the entire approach.

Bias mitigation is the exception that crosses over. It is the function most directly exposed to active EEOC enforcement on AI-driven hiring under Title VII, which makes it an enterprise hire as much as a lab one.

Professional working at a laptop
Boundaries

Where we focus

A specialist practice is defined as much by where it concentrates as by what it covers. These sit outside our focus, and we will happily refer them.

  • General cybersecurity. SOC leadership, network security, general CISO searches with no AI system in scope.
  • General privacy and data protection. GDPR and CCPA program work that does not touch model development or deployment.
  • Core ML engineering. Research scientists, ML platform and MLOps roles without a security, privacy or governance mandate.
  • AI transformation leadership. Chief AI Officer, Head of AI, VP AI Transformation. Adjacent, larger, and a different market — deliberately kept out of this taxonomy.
Contested calls

Five positions here worth arguing with

A taxonomy nobody disagrees with is not saying anything. These are the calls this map makes that a working practitioner might genuinely push back on, with the reasoning attached — so you can take issue with one without discarding the rest.

Security
A Field CISO is not a CISO. The title carries a C; the mandate does not. No internal security operations, no incident-response ownership, no line to the board. The role sits in or beside go-to-market and is measured the way go-to-market is measured — pipeline, deal velocity, win rate. Read as an executive security hire, it produces a shortlist of people who would be miserable in the job within a quarter.
Governance
A governance seat without authority to stop a launch is a documentation seat. That can still be useful work. It is not the work most companies believe they are buying when an audit finding lands. What decides this is where the role sits on the org chart, not what it is called — which is why the reporting line is worth pinning down ahead of the title or the band.
Sourcing
Red teaming converts from offensive security, rarely from audit. Both disciplines exist to find what is broken, and on paper the output looks similar enough that companies treat the backgrounds as interchangeable. Only one carries the instinct to break the thing first. That instinct does not arrive with a controls-testing history, and hiring as though it does is the most common way one of these searches stalls.
Risk
Banking model risk is the strongest feeder into AI risk. Validation, effective challenge, independent review, documentation standards — all of it has existed there as a formal discipline for roughly two decades. The models changed; the method did not. These candidates are routinely screened out for lacking "AI experience" while being the closest thing this market has to a trained population.
Supply
The credential is a floor, not a ceiling. Roughly four thousand people hold the field's anchor credential (AIGP), the number cited at the top of this page. It is a real qualification and a genuinely useful signal — but it is not the only one. A meaningful share of the strongest practitioners built governance functions from nothing before there was anything to sit for, or moved in from banking model risk, security research, or privacy law without certifying. Screening on the certificate alone removes some of the strongest talent who could easily take and pass the AIGP exam.
Low angle view of office towers
Disagree with the map?

Tell us where it's wrong. That's how it gets better.

If you work in this field and the boundaries here don't match what you see, we want to hear it.

Low angle view of corporate buildings
About

One market, worked deeply enough to know who's real in it.

AI Assurance Talent is a specialist search practice for AI governance, risk, compliance, security and privacy talent in the United States. Not a generalist firm with an AI vertical bolted on.

Chris Jensen
Chris Jensen
Founder · AI Assurance Talent
The founder

I've been hiring into AI companies for eleven years

For the past eleven years I have helped build go-to-market teams at AI startups, US-based and international — including one working on an early precursor to agentic AI in experience management, well before the category had a name or a conference.

The through-line of that work was the hidden market: finding and evaluating people who are performing at the top of their field and are not looking. That is a specific discipline. It is not posting a job and waiting, and it does not get easier with a bigger database.

That aim is not abstract. Some of that startup work put me in the middle of enterprise security reviews — the long-form questionnaires, the architecture calls, the follow-up evidence requests — coordinating between our own engineers and the security and risk teams at Cigna, Amazon, Meta and Omnicom. The pilots went well. More than one of those relationships was moving toward an enterprise license and did not get there. The problem was never that we could not respond to the reviews. It was that we lacked the expertise to recognize that what those enterprises were asking for had to be built, not explained — or the standing to make that case internally while the deal was still live.

On the strength of that, I was invited to start a search practice inside an established network of offices. AI Assurance Talent is the next step down that same line — the same method, aimed at the function that is now hardest to hire for anywhere in the economy.

I run every search on this site personally. There is no research team behind me and no account manager in front of me, which is a real constraint on volume and a real advantage on depth.

The thesis

Why niche on a function instead of an industry

Most specialist search firms niche by the kind of company they sell to — fintech, healthtech, agentic AI. That works until the label goes out of fashion or the segment consolidates, and then you rebrand.

Niching on a function inverts the scarce asset. In a company-segment niche the hard part is client access. In a functional niche the hard part is candidate access — and candidate access compounds. Every search makes the map better. Every conversation with a practitioner improves the next role definition.

It also travels. AI governance talent gets hired by AI-native startups, Fortune 500 enterprises, banks, hospital systems and government agencies. The function is constant; only the buyer changes. That is a far more durable position than owning one slice of one industry.

And the timing is unusual. There is no dedicated AI governance recruiting boutique operating in the US today. Entering here is not a share-winning exercise against entrenched incumbents — it is a visibility exercise, which is a materially different problem.

Standing in the field

Earning credibility the way this field expects

The professional bodies in this space describe themselves as policy-neutral homes for practitioners, not talent marketplaces. A recruiter who shows up contributing — comp data, role-definition guidance, research — is welcomed. One who shows up selling is tolerated at best.

So the publishing strategy and the community strategy are the same strategy. What is genuinely useful to the field gets published. What took real work to build stays proprietary.

  • IAPP — membership, chapter participation, and the anchor credential for this profession.
  • OWASP GenAI Security Project — contributing, not recruiting. Overt sourcing burns that room.
  • Cloud Security Alliance — where the vendors hiring Field CISOs actually congregate.
  • P.S.R. + AI Governance Global — Seattle, October 2026.

A directory tells you a person exists. It doesn't produce them, and it doesn't get them on a call.

On why the job board isn't the competition
Colleagues working together
Let's talk

Hiring, looking, or just want to argue about the taxonomy.

All three are worth a conversation.

Professional in a working conversation
Contact

Start with the problem. We'll get to the role.

Every message here reaches us directly. Candidate conversations are confidential by default and nothing moves without your explicit go-ahead.

Direct

No form, no routing queue, no "someone will be in touch."

What happens next

Two paths, depending on why you're here

If you're hiring: a thirty-minute call to work backwards from whatever triggered this. You leave with a written role definition and a live comp band. If the role as written can't be filled at that band, you'll hear it on that call rather than in month three.

If you're in the market — or think you might be in a year: a confidential conversation about what your scope is actually worth right now. No submission, no client name, no obligation. Plenty of these end with someone deciding to stay put, which is a perfectly good outcome.

Documents and analysis at a desk
Legal

Privacy Policy

Last updated August 26, 2026. What we collect, why, and what we do with it.

Who this covers

This policy applies to AI Assurance Talent (aiassurancetalent.com) and describes how we handle information about job candidates, hiring contacts, and site visitors. We are a specialist executive search practice — we are not a data broker, and we do not sell personal information for advertising purposes.

What we collect

From candidates: name, contact details, resume and work history, LinkedIn profile information, compensation history and expectations, and notes from calls or interviews you have with us. From hiring contacts: name, company, role, contact details, and information about open positions and hiring needs. From site visitors generally: basic usage information such as pages viewed and how you arrived at the site, collected through standard analytics tools.

Most candidate information is provided directly by you — through a resume, a call, a LinkedIn profile you've made public, or a form on this site. We do not purchase candidate data from third-party data brokers.

How we use it

To evaluate whether your background fits a specific search, to present you to a hiring company when you've agreed to that, to keep a record of past conversations so we don't waste your time repeating them, and to run our own business — invoicing, scheduling, and basic reporting on how our searches are going.

Who we share it with

We share candidate information in three situations, and only in these:

Hiring authorities. When you're a fit for a specific role and you've agreed to be presented, we share your resume and relevant background with the hiring company running that search.

Other recruiters. On occasion we work a search alongside another recruiter or on a split-fee basis. In those cases, relevant candidate information is shared with that recruiter as part of running the search — never as a blanket list, always tied to a specific opportunity.

Public, anonymized content. We sometimes describe a candidate's background in general terms — on this site or in social posts — to illustrate the kind of talent we work with. When we do this, we remove or generalize anything that would identify you: no name, no current employer, no detail specific enough to be traced back to one person without your explicit permission.

We do not sell candidate or client data to marketing lists, data brokers, or advertisers, and we do not share your information with a hiring company without your knowledge.

Confidentiality by default

Your name does not move to a client, to a "we're just gauging interest" conversation, or into an anonymized profile detailed enough to identify you, without your say-so first. This is a stated commitment on this site's Talent page, and it governs how we actually handle your information, not just how we describe it.

How long we keep it

We retain candidate information for as long as it's useful to you and to us — typically as long as you remain reachable and relevant to searches in this field. You can ask us to update or delete your information at any time; see Your choices below.

Cookies and site analytics

This site may use basic analytics to understand how visitors use it — which pages get read, roughly how people arrive here. We do not use this data to build advertising profiles or sell it to third parties.

Your choices

You can ask us what information we hold about you, ask us to correct it, ask us to delete it, or ask us to stop contacting you, at any time. Email chris@assurancetalent.com and we'll handle it directly — no ticket queue, no runaround. Depending on your state of residence, you may have specific legal rights under state privacy law (for example, California's CCPA); we'll honor the underlying request regardless of where you live.

Changes to this policy

If this policy changes in a way that matters, we'll update the date at the top of this page. Continuing to use the site after a change means you've accepted the update.

Contact

Questions about this policy or your data: chris@assurancetalent.com.

Professional in a working conversation
Legal

Terms of Use

Last updated August 26, 2026. The basic rules for using this site.

Acceptance of these terms

By using aiassurancetalent.com, you agree to these terms. If you don't agree, the straightforward option is not to use the site — nothing here is meant to trap you.

What this site is

AI Assurance Talent is a specialist executive search practice for AI governance, risk, compliance, security, privacy, and adjacent talent. This site describes our practice, our view of the market, and how to reach us. It is not a job board, not a staffing marketplace, and not an automated matching platform — every search here is run personally.

The taxonomy, comp data, and market commentary aren't guarantees

The domain taxonomy, seniority ladders, compensation ranges, market statistics, and opinions on this site (including the "Five positions here worth arguing with" section on the Coverage page) reflect our own research and judgment at a point in time. They are informational, not a guarantee of what any specific role pays, what any candidate is worth, or how any hiring decision will turn out. Markets move faster than a website can be updated. This content is not financial, legal, tax, or career advice, and shouldn't be treated as a substitute for your own professional judgment or for advice from a licensed professional where one is warranted.

No guarantee of placement or hire

Talking with us — including a scoping call, a comp read, or being presented for a role — does not guarantee a placement, an offer, or a hire. Search outcomes depend on many factors outside our control.

Confidentiality works both ways

We take candidate confidentiality seriously, as described in our Privacy Policy. In turn, we ask that anything shared with you in confidence about a specific search, company, or candidate stay confidential and not be redistributed or used outside the purpose it was shared for.

Acceptable use

Don't scrape, copy, or republish this site's content at scale, attempt to access systems or data you're not authorized to access, misrepresent yourself when contacting us, or use this site in any way that violates applicable law. Ordinary use — reading the site, reaching out, sharing a link — is obviously fine.

Intellectual property

The content, design, taxonomy, and written material on this site belong to AI Assurance Talent unless otherwise noted. You're welcome to link to it or quote it with attribution; you're not licensed to reproduce it wholesale or present it as your own.

Third-party links

This site links to third-party tools such as Cal.com and LinkedIn. We don't control those sites and aren't responsible for their content or practices — check their own terms and privacy policies separately.

No warranty

This site is provided as-is. We work to keep it accurate and current, but we don't warrant that it's error-free, uninterrupted, or perfectly up to date at every moment.

Limitation of liability

To the extent permitted by law, AI Assurance Talent isn't liable for indirect, incidental, or consequential damages arising from your use of this site or reliance on its content.

Changes to these terms

We may update these terms as the practice evolves. Material changes will update the date at the top of this page.

Governing law

These terms are governed by the laws of the State of Utah, without regard to conflict-of-law principles.

Contact

Questions about these terms: chris@assurancetalent.com.