Roles

Who Should Own AI Security Governance, and What Background Does That Job Take?

AI security governance belongs to one named owner inside security, not to a committee. The job holds a live inventory of every model and agent in use, maps each one to EU AI Act and sector obligations, writes the acceptable-use and vendor-review rules, and turns red-team and incident findings into risk a board can act on. Hire someone with security GRC depth who has shipped a control that changed behavior, not a policy writer who has only read about AI.

The takeMost companies get this wrong by making AI governance a committee with a rotating chair. A committee cannot hold an inventory, cannot be paged at midnight, and cannot say no on a Friday. Put one person in security who reports to the CISO, give them a written veto over production AI deployments, and make them accountable for the register that legal cites. If the role has no authority to stop a launch, the honest thing to do is not hire it. Hire a consultant for the paperwork instead and stop pretending the risk is owned.

Where Olive fits

Open a role and see what the work shows

Under the automated-decision rules, "the model gave them a 74" is not an explanation. Olive produces no composite and no automated decision at all: a person writes every finding, each one carries the excerpt it rests on, and every released report exports with its rubric, scorer and bank versions attached.

Rank your shortlist

What Does an AI Security Governance Officer Do in the First Ninety Days?

A product manager forwards a vendor contract at 4pm on a Friday. The tool ships an agent that reads the ticketing system and drafts customer replies. Legal wants a risk opinion by Monday, security has never seen the model, and nobody can say which other agents already hold that data. The first ninety days of this role are spent making that question answerable.

The first artifact is an inventory: every model, agent, copilot and embedded feature in use, with the data each one touches, the vendor behind it, the business owner, and whether a human reviews its output before anything leaves the building. Shadow usage is the interesting half. The inventory that only lists procured tools is a list of what finance paid for, not a list of what employees run.

The second artifact is the obligation map. Regulation (EU) 2024/1689 sets requirements on high-risk systems around technical documentation, record-keeping and human oversight, and deployer duties sit alongside provider duties 3. A sector regulator, a state law or a customer contract may bind you before the EU text does. This is a place to name the jurisdiction, name the date, and check the mapping with counsel rather than treat a blog summary as advice.

The third is the loop that keeps the first two honest: an acceptable-use policy people can actually follow, a vendor AI review that runs before the contract rather than after, and a path from red-team and incident findings into a risk register the board reads. Findings that stop at a slide deck are the failure mode. The officer's real output is a change in what ships.

The boundary worth drawing at the offer stage: this person governs, and a separate engineer builds the guardrails. If the job description asks for both, read what an AI security engineer actually owns before writing the requisition, because merging them produces a person who reviews their own work.

Recruit AI Security Governance From Safety Investigators, Not Policy Writers

The reliable feeder is security GRC with real technical depth: someone who ran a SOC 2 or ISO 27001 program, sat in vendor security reviews, and has argued a control down to something engineers would adopt. Third-party risk leads and internal auditors from regulated industries are the second stream. Both bring the habit this job runs on, which is asking for evidence rather than assurances.

The unexpected backgrounds are often stronger. Clinical safety officers and aviation safety investigators already think in failure modes, near misses and mandatory reporting, and they do not confuse a policy with a barrier. Privacy program managers who came up through DPIAs can read a regulation and produce a decision. Site reliability engineers who ran incident command bring blameless postmortems and a working sense of how systems fail under load. Machine learning engineers who moved into safety work bring the one thing most GRC candidates lack, which is the ability to argue with the platform team about evals.

The tells separating real from performed take about ten minutes to surface, and the Friday vendor contract is a serviceable prop for all of them. Hand it over. Ask what they would cut from an acceptable-use policy to make room for a tool like this, and a real one names a clause that got ignored somewhere else and explains what replaced it. Ask what they would have told legal on Monday with only what was knowable on Friday, and whether they would reverse that answer now, and a real one has a decision they would take back and can say what evidence would have changed it. Then ask what happens if the product team switches the agent on over the weekend without waiting. Performed governance escalates to a committee. Real governance names the first three questions, the containment step, and the point at which the launch stops.

One more filter: ask what they think is overrated. A candidate who cannot criticize any part of the current AI risk orthodoxy has not formed a position, only absorbed one. That matters here more than in most roles, because the job is largely holding a line against people who outrank the person holding it.

How Did the Candidate Learn AI Security Governance by Doing It?

The practice behind the skill is unglamorous and easy to check. Strong candidates have sat with the models rather than around them. They have run a jailbreak set against their own company's assistant, watched an agent take an action nobody authorized, and written up what happened with timestamps. Governance written by someone who has never made a model misbehave reads like a summary of other people's documents.

Ask how they use an assistant in their own work, and listen for the checking. The strong answer is specific about division of labor: the model drafts the control mapping or the first pass of a vendor questionnaire, and the person verifies every citation against the primary text because the model will produce a plausible article number that does not exist. Candidates who describe AI as a research shortcut without describing a verification step are telling you what their risk register will look like.

Look for evidence they have built an eval rather than requested one. That can be small: a set of twenty prompts that a support agent must refuse, run before and after a model version change, with results kept. It shows they understand that a control on a probabilistic system is measured, not asserted. The same instinct shows up in how they talk about adversarial testing of agentic systems, which they should treat as an input they consume rather than a service they buy once a year.

The last practice tell is writing. This job produces memos that executives read under time pressure. Ask for a one-page risk opinion on the Friday contract, written during the process rather than in advance. What you learn is whether they can hold a position, state what would change it, and say plainly what they do not know.

Where Do AI Security Governance Candidates Come From, and What Closes One?

They cluster in a small number of visible places. The IAPP community around the AIGP credential is the densest pool, and certification holders reported a US median of $182,000 in one 2026 salary report 1. Contributors to the OWASP Top 10 for LLM Applications, participants in Cloud Security Alliance AI safety working groups, and people who show up at DEF CON's AI Village or a regional BSides are self-selecting for the technical half of the job.

The adjacent roles worth sourcing from are third-party risk lead, privacy program manager, security architect and lead internal auditor. Feeder employers are banks, insurers, health systems, the big consulting risk practices, and trust and safety or trust-and-compliance teams inside cloud and SaaS vendors. Consultants leaving the big four are a real stream, though the ones to hire are the ones who left because they wanted to own an outcome rather than deliver a report.

What closes them is authority, in writing. This candidate has usually been burned by a role where governance meant producing artifacts nobody read. They want the reporting line named, the veto documented, a budget for tooling and testing that is not borrowed from another team, and direct access to the engineers running the platform. Ask what they need to be effective and they will tell you exactly which of these they lost last time.

What kills the offer is equally predictable: a reporting line into communications or a compliance function with no security engineering access, a title without a decision right, an interview panel where nobody can say who currently owns AI risk, and any signal that the company wants a name on the org chart to show an auditor. Pay close, but do not expect money to fix a structural answer. If the mandate is genuinely broader than security, hire an AI governance lead and let this role stay technical.

What Should You Pay an AI Security Governance Officer, and Where Does the Work Sit?

As of mid-2026 there is no long-running public wage series for this exact title, so anchor on the closest published bands. VerifyWise's 2026 AI governance salary report puts US manager and mid-career AI governance base pay at roughly $140,000 to $218,000, with a US median of $182,000 among AIGP certification holders 1. Senior roles owning security and regulatory exposure together price above that band, and equity varies more than base.

The demand side explains the pressure. The same report cites LinkedIn data putting AI governance demand up 150 percent year over year, with AI compliance officer postings up roughly 45 percent as EU obligations approached 1. The World Economic Forum's 2025 outlook placed Security Management Specialists among its fastest-growing jobs at about 53 percent growth to 2030 2, and McKinsey found 13 percent of organizations had hired AI compliance specialists in the previous twelve months 4. A first hire made now is competing against a field that is still forming its bands.

On location, most of this work is remote-friendly because its outputs are documents, reviews and decisions. The pull toward a desk is specific rather than general: regulated environments with restricted data enclaves, defense or classified work, incident weeks when the person needs to be in the room, and the first quarter of the job, when the inventory gets built by walking to people rather than emailing them. A common shape is hybrid with two anchored days, plus travel for regulator and customer audits.

One budget decision remains. A consultant is the right call when the need is a one-time gap assessment against a named framework and a deadline. An employee is the right call the moment the answer has to be maintained, because the inventory decays in weeks and no retainer keeps it current. Friday's contract arrives again in six weeks under a different vendor's name, and somebody has to be there for it. If the trigger for this hire was a customer questionnaire rather than an operating risk, buy the assessment and revisit the headcount in two quarters.

Read the evidence

Common questions

How do I become an AI security governance officer?

Start from a real security or risk job rather than from a certificate. Run a control program end to end, sit in vendor security reviews, and take ownership of one AI system at your current employer: build its inventory entry, map its obligations, run a refusal test set against it, and write the one-page risk opinion. The AIGP credential helps a resume pass a filter, but hiring managers ask what you stopped, what you changed, and what evidence you kept. Have three specific answers ready.

Should AI risk sit with security, legal or a committee?

Security should own the day-to-day inventory, testing and control decisions, because that is where the telemetry and the incident path already live. Legal owns the obligation itself and signs off on regulatory interpretation. A committee is useful for escalation and for cross-functional visibility, and useless as an owner, because it cannot be paged, cannot maintain a register, and cannot say no under deadline. Name one accountable person and write down what they can stop.

Do we need an AI compliance hire or would a consultant do?

A consultant fits a bounded question: a gap assessment against a named framework, a due-diligence review, or a first policy draft. An employee is needed as soon as the answer must stay current, since the model and agent inventory changes faster than any retainer refreshes it. A practical test: if the deliverable is a report, buy it. If the deliverable is a decision made repeatedly under time pressure, hire it.

What does an AI security governance officer job description need to include?

Name the reporting line, the decision right and the scope. State that the role maintains the inventory of models and agents, maps systems to regulatory and contractual obligations, owns acceptable-use and vendor AI review, and converts red-team and incident findings into board-reportable risk. State explicitly whether the role can block a production deployment. Candidates read that clause first, and a description that omits it reads as a role without teeth.

How do you screen for judgment rather than vocabulary in this role?

Give a real decision with incomplete information and watch the reasoning. A useful prompt: a business unit is running an unapproved agent on customer support data, revenue depends on it, and the regulator's position is unsettled. Strong candidates name what they would check first, what would justify containment versus a shutdown, and what evidence would change their mind. An answer that stops at escalating, or that supplies a framework name where a next step belongs, is the one to worry about.

What certifications actually matter for AI governance security roles?

CISSP or CISM plus audit experience still carries the security half of the job, and the IAPP AIGP has become the recognizable AI-specific credential, with certification holders reporting a US median of $182,000 in a 2026 salary report 1. Treat all of them as filters rather than as evidence. A candidate who has run one adversarial test against a production assistant and written up the result tells you more than any three credentials.

References

  1. 1. AI Governance Salary Report 2026 VerifyWise, 2026. verifywise.ai US manager and mid-career AI governance base pay of roughly $140,000 to $218,000, a US median of $182,000 among AIGP holders, AI governance demand up 150 percent year over year and AI compliance officer postings up about 45 percent.
  2. 2. Future of Jobs Report 2025: the fastest-growing and declining jobs World Economic Forum, 2025. weforum.org Security Management Specialists among the fastest-growing jobs at about 53 percent growth to 2030.
  3. 3. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence EUR-Lex, Official Journal of the European Union, 2024. eur-lex.europa.eu High-risk AI systems carry requirements covering technical documentation, record-keeping and human oversight, with deployer duties alongside provider duties.
  4. 4. The state of AI: How organizations are rewiring to capture value McKinsey and Company, 2025. mckinsey.com 13 percent of organizations reported hiring AI compliance specialists in the previous twelve months.

4 sources, numbered by first appearance. How Olive sources claims

General guidance for hiring teams. What works at one company and one volume may not transfer to yours.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.