Field
Cyber, Risk & Internal Audit
Seven archetypes across 1,060 postings. AI appears in 92% of them โ but AI-specific risk practice in only 9%. That gap is the opportunity.
1,060 roles ยท 362 JDs parsed
Product & Application Security Engineer
The #1 title in the family. An engineering job, not a policy one.
TESTS
Design under constraint Failure and incident narrative Reading a job description
OPEN — full archetype →
Cloud & Infrastructure Security Engineer
Cloud security in 41%, containers in 28%.
TESTS
Design under constraint Failure and incident narrative
OPEN — themes + data →
Detection & Response / Security Operations
SIEM, incident response, and the shift to detection-as-code.
TESTS
Failure and incident narrative Measuring what resists measurement
OPEN — themes + data →
Offensive Security / Red Team
Pentest and bug bounty in 19% of postings.
TESTS
Failure and incident narrative Discovery before solution
OPEN — themes + data →
Security GRC & Risk
GRC and compliance named in 78%. Increasingly an engineering role.
TESTS
The control Measuring what resists measurement Discovery before solution
OPEN — full archetype →
Internal Audit & IT Audit
Audit in 27%. Where AI assurance is landing first.
TESTS
The control Measuring what resists measurement Reading a job description
OPEN — themes + data →
AI Security & Assurance
The emergent one. AI-specific risk practice in only 9% of postings.
TESTS
Measuring what resists measurement The control Failure and incident narrative
OPEN — full archetype →