Your learning path
AI Governance and Risk Lead
Assess AI risks and help teams decide which controls, reviews and evidence they need.
First session
Start with one task
Choose a fictional AI assistant. Read the NIST AI RMF overview, then record its intended use, affected people and the risks you would investigate.
Open the first skill guide →Use a training lab or a system you own. Testing any other system needs written permission.
What this work involves
- Assess AI systems against risk frameworks such as NIST AI RMF and ISO 42001.
- Track LLM-specific risks (prompt injection, data leakage) as part of every assessment.
- Review architecture and cloud deployment choices for AI systems to spot governance gaps.
- Check AppSec controls where security engineering and governance overlap, and brief stakeholders on regulatory exposure.
Learn in order
Your learning steps
Start with the first skill. Each step has a few resources here and a link to the full guide. Skip material you already know.
01AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICMThis is the day job: running formal risk assessments and mapping controls to frameworks, not just knowing the frameworks exist.
- AI Risk Management Framework NIST, standard, free, about 3 h, introThis is the baseline voluntary framework most AI governance programs are built on, and it links to the RMF 1.0 document, the Playbook, and the Generative AI Profile.
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST-AI-600-1) NIST, standard, free, about 2 h, workingRead the risks and suggested actions specific to generative AI alongside the base NIST AI Risk Management Framework.
- NIST AI RMF Playbook NIST, tool, free, about 3 h, workingTurns the RMF's four functions into concrete, actionable suggestions you can use as a checklist when running an actual assessment.
02LLM security: prompt injection, jailbreaks, output handlingEvery posting expects you to understand LLM-specific risks like prompt injection and hallucination well enough to assess them, not just cyber risk in general.
- OWASP Top 10 for LLM Applications OWASP GenAI Security Project, standard, free, about 3 h, introUse this list of LLM application risks to structure a review, including prompt injection and unsafe output handling.
- Prompt Injection Prevention Cheat Sheet OWASP Cheat Sheet Series, guide, free, about 1 h, workingShort, practical control checklist you can reuse directly in a design review or a client report.
- Web LLM attacks PortSwigger Web Security Academy, lab, free, about 3 h, workingPractise attacks against an LLM-backed application in authorised browser-based labs.
03AI system threat modelling and secure architectureYou need enough system design literacy to read an architecture diagram and spot where a risk actually lives.
- MITRE ATLAS MITRE, guide, free, about 3 h, workingGives you a tactics and techniques matrix for adversarial ML attacks that you can use directly in threat modelling sessions.
- Guidelines for secure AI system development UK National Cyber Security Centre, guide, free, about 2 h, workingWalks through secure design, development, deployment and maintenance decisions for AI systems in plain, practitioner language.
- Gandalf Lakera, lab, free, about 1 h, introLets you try prompt injection against a live guarded LLM so the threats in the frameworks stop being abstract.
04Securing model and agent workloads on cloud platformsMany AI systems are deployed on cloud platforms, so you need to recognise cloud-specific risk patterns even if you never configure them yourself.
- Securing generative AI: An introduction to the Generative AI Security Scoping Matrix AWS Security Blog, guide, free, about 2 h, workingGives you a working model for figuring out which security responsibilities are yours versus the provider's for any generative AI deployment.
- Azure security baseline for Azure OpenAI Microsoft Learn, guide, free, about 2 h, workingLists the specific network, identity and data controls to configure when you run a model workload on Azure.
- Google's Secure AI Framework (SAIF) Google, guide, free, about 1 h, introSets out Google's own conceptual framework for securing AI systems across the ecosystem, useful for comparing against AWS and Azure approaches.
05Application security for LLM-backed softwareSome roles blend governance with reviewing secure coding and deployment practices for AI applications.
- OWASP Top 10 for LLM Applications OWASP GenAI Security Project, standard, free, about 2 h, introThe reference risk list you will map every LLM app review against, so start here.
- Guidelines for secure AI system development UK National Cyber Security Centre, guide, free, about 2 h, workingCovers secure design, build, deployment and maintenance for AI systems the way an AppSec review checklist would.
- HackAPrompt Learn Prompting, lab, free, about 3 h, introHands-on practice crafting prompt injection payloads, the equivalent of learning SQL injection by doing it.
06Advisory and customer-facing delivery skills1 of the 7 postings is consulting-style and asks you to explain risk findings to clients directly.
- Multilayer framework for good cybersecurity practices for AI ENISA, guide, free, about 2 h, workingA structured way to walk a client through AI security practices across the organisation, not just the model layer.
- AI Governance Professional (AIGP) training IAPP, course, USD 1500, about 20 h, advancedA recognised credential for advisors whose clients need a named expert on AI governance and law, not just technical controls.
Put it into practice
Risk register and EU AI Act note for a fictional LLM system
Allow about 8 hours, plus setup. This is a practice project, not a certification or a measure of job readiness.
Invent one fictional LLM-based system (for example an internal HR chatbot that answers policy questions), map it against the NIST AI RMF, and produce a risk register plus a short note on which EU AI Act obligations would apply. This shows you can turn a framework into a working document.
Use fictional data and an authorised sandbox. Check model, cloud and licence costs before starting.
Project steps
- Write a one-paragraph description of your fictional LLM system: what it does, who uses it, what data it touches.
- Read the NIST AI RMF core functions (Govern, Map, Measure, Manage) directly from the NIST document.
- For each RMF function, list at least 2 concrete risks specific to your system (not generic cyber risks).
- Build a risk register in a spreadsheet: risk description, RMF function, likelihood, impact, existing control, proposed control, owner.
- Read the EU AI Act risk-tiering criteria and decide which tier your fictional system would likely fall into, with reasoning.
- Write a one-page applicability note: which AI Act obligations apply at that tier, what evidence you would need to show compliance.
- Have someone else (or reread cold after a day) check whether the risks in your register are specific enough to this system, not generic.
- Save both documents as a portfolio pair you can walk through in an interview.
What to produce: A risk register spreadsheet and a one-page EU AI Act applicability note for a named fictional LLM system.
Check your work
- every risk in the register names something specific to the fictional system, not a copy-pasted generic AI risk.
- the register covers all four NIST AI RMF functions with at least one risk each.
- the AI Act note states a specific risk tier with a one-sentence justification.
- you can explain out loud, without notes, why you picked that tier.
- the deliverable is two separate readable documents, not rough notes.
Career context
Security pay by experience
General security benchmarks, not an AI-security salary forecast. Skills and responsibility matter; years of experience alone do not determine pay.
United Kingdom GBP · reported annual salary
Example specialism: security engineering. These are the survey’s experience bands, not AI-security pay or job-level guarantees.
- Experience reported
1–3 years
£45,000–£59,7502026 reported salary rangeNot a zero-experience starting salary.
- Experience reported
4–6 years
£62,500–£75,7502026 reported salary range - Experience reported
7–9 years
£81,000–£98,5002026 reported salary range - Experience reported
10–12 years
£100,000–£115,7502026 reported salary range
United States USD · reported annual salary
Example specialism: security engineering. These are the survey’s experience bands, not AI-security pay or job-level guarantees.
- Experience reported
1–3 years
$59,500–$78,0002026 reported salary rangeNot a zero-experience starting salary.
- Experience reported
4–6 years
$79,750–$96,5002026 reported salary range - Experience reported
7–9 years
$106,500–$129,2502026 reported salary range - Experience reported
10–12 years
$130,500–$150,7502026 reported salary range
Reported annual salary. No bonus, equity or sales OTE added; the source does not explicitly confirm base-only pay. UK and US use separate scales and currencies; no conversion. These are snapshots across people, not a guaranteed pay progression.
Sources and methodology
Sources checked 2026-09-26. These benchmarks are separate from this guide’s small AI-security job sample. Published ranges can overlap and differ by specialism, location and employer.
United Kingdom
Cybershark Recruitment’s 2026 United Kingdom survey, Security Engineering row on page 8. Four published experience bands are reproduced directly, with no interpolation or currency conversion. The whole survey reports 3,861 respondents; counts within each role/experience band and the statistical definition of the range are not provided. Treat this as a directional recruiter benchmark, not a representative national estimate or a salary prediction. Salary and performance bonuses are reported separately, but the report does not explicitly define the table as base-only. We therefore label it reported annual salary, not verified base pay. No bonus, equity, benefits or sales OTE have been added. Zero-experience pay and AI-specific premiums are not established by this table.
- Cybershark Recruitment: United Kingdom Cyber Security Salary Survey, page 8 (PDF) (2026)
Published salary ranges for Security Engineering, by years of experience. Directly transcribed from the report’s table; no pooled job-posting ranges or invented seniority labels.
United States
Cybershark Recruitment’s 2026 United States survey, Security Engineering row on page 7. Four published experience bands are reproduced directly, with no interpolation or currency conversion. The whole survey reports 7,028 respondents; counts within each role/experience band and the statistical definition of the range are not provided. Treat this as a directional recruiter benchmark, not a representative national estimate or a salary prediction. Salary and performance bonuses are reported separately, but the report does not explicitly define the table as base-only. We therefore label it reported annual salary, not verified base pay. No bonus, equity, benefits or sales OTE have been added. Zero-experience pay and AI-specific premiums are not established by this table.
- Cybershark Recruitment: United States Cyber Security Salary Survey, page 7 (PDF) (2026)
Published salary ranges for Security Engineering, by years of experience. Directly transcribed from the report’s table; no pooled job-posting ranges or invented seniority labels.
How this sample informed the learning order
This path uses 7 postings from a 48-posting research dataset compiled on 24 September 2026, not a live vacancy feed. The counts below show how many selected postings explicitly mention each skill. They describe this sample only, not demand across the job market. The learning order also reflects prerequisites.
- AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM6 / 7
- LLM security: prompt injection, jailbreaks, output handling7 / 7
- AI system threat modelling and secure architecture3 / 7
- Securing model and agent workloads on cloud platforms3 / 7
- Application security for LLM-backed software2 / 7
- Advisory and customer-facing delivery skills1 / 7
Reference frameworks for this path
- NIST AI RMF 1.0 + Generative AI Profile (AI 600-1)
The core framework this role assesses systems against; use its four functions to structure the risk register.
- ISO/IEC 42001
Gives the management-system view of AI governance that senior GRC roles are expected to reference alongside NIST.
- OWASP Top 10 for LLM Applications 2025
A ready list of LLM-specific risk categories to draw on when filling in the risk register.
- NCSC Guidelines for secure AI system development
Practical lifecycle guidance to cite when recommending controls, not just naming risks.