Manager of Application & AI Security
Arrivia · Scottsdale Quarter, Scottsdale, AZ, United States
About The Role
Are you ready to pioneer the frontier of AI security while championing modern DevSecOps? At arrivia, we are transforming the travel industry, and we need a visionary leader to ensure our innovation never outpaces our security.
As the
Manager of Application & AI Security
, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines." Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale.
What You’ll Do
Forge the Future of AI Security & Governance
Hold the Central AI Mandate
Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
Architect AI Guardrails
Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
Lead AI Red-Teaming
Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
Secure Agentic Runtimes
Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
Elevate Application Security & DevSecOps
Own the Secure SDLC
Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
Enforce Pipeline Integrity
Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
Secure the Architecture
Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
What Success Looks Like
AI Under Governance
100% of AI tools are risk-assessed before deployment, shadow-AI is discovered and triaged automatically within SLA, and compliance policies are strictly enforced.
Flawless Delivery
100% of production pipelines are covered by automated CI/CD guardrails, with zero critical application security findings shipping to production.
Proactive Defense
Comprehensive security posture scores for PaaS/SaaS meet or exceed targets, with automated blocking of critical vulnerabilities built right into the developer workflow.
Who You Are
An Experienced Leader
You possess a Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience), including 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership.
A Guardrails-as-Code Practitioner
You have hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins.
An AI Security Enthusiast
You possess a strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
An Industry Expert
You are deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
A Clear Communicator
You excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
Credentialed
You hold a CISSP or CCNP-Security certification. (CSSLP, CCSP, or CISM designations are highly preferred).
Working Conditions & Leadership Style
Schedule & Environment
This position operates in an office setting with a current schedule requirement of 4 days per week in-office.
Autonomy & Direction
You will operate under general direction, establishing your own methods and procedures to attain high-level organizational goals.
Team Leadership
You will manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.
Who We Are
Welcome to
arrivia
. We specialize in making brands better through the power of travel. With more than 55 years of combined experience, we are a merger of three powerhouse brands—ICE, SOR Technology, and WMPH Vacations. With offices on both coasts of the US and around the world, we embrace diversity and a passion for travel across our global staff.
We are focused on building a customer-first culture, fueled by the best travel experiences for all our members at every point in their journey. Grow with us, as we continue our path to deliver innovative solutions and take charge of change. The adventure is only beginning.
Our Core Values
Stay Curious
- Explore new challenges and make space to learn, grow and improve.
Keep it Real
- Earn trust through open, honest and clear communication.
Own it
- Seek ways to make an impact and take action.
Win Together
- Create a culture of connection and inclusion where everyone can be their best.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring