arrivia

arrivia

1 open position available

1 location
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 1 most recent job
arrivia

Manager of Application & AI Security

arriviaScottsdale, ArizonaFull-time
View Job
Compensation$85K - 120K a year

Lead AI governance and DevSecOps pipelines to secure application and AI deployments. | Bachelor's degree or 7+ years security experience with 5+ years in AppSec and DevSecOps, CISSP or CCNP-Security certification, knowledge of OWASP, NIST, ISO. | Are you ready to pioneer the frontier of AI security while championing modern DevSecOps? At arrivia, we are transforming the travel industry, and we need a visionary leader to ensure our innovation never outpaces our security. As the Manager of Application & AI Security, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines." Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale. What You’ll Do Forge the Future of AI Security & Governance * Hold the Central AI Mandate: Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls. * Architect AI Guardrails: Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team. * Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks. * Secure Agentic Runtimes: Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment. Elevate Application Security & DevSecOps * Own the Secure SDLC: Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022. * Enforce Pipeline Integrity: Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management. * Secure the Architecture: Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience. What Success Looks Like * AI Under Governance: 100% of AI tools are risk-assessed before deployment, shadow-AI is discovered and triaged automatically within SLA, and compliance policies are strictly enforced. * Flawless Delivery: 100% of production pipelines are covered by automated CI/CD guardrails, with zero critical application security findings shipping to production. * Proactive Defense: Comprehensive security posture scores for PaaS/SaaS meet or exceed targets, with automated blocking of critical vulnerabilities built right into the developer workflow. Who You Are * An Experienced Leader: You possess a Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience), including 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership. * A Guardrails-as-Code Practitioner: You have hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins. * An AI Security Enthusiast: You possess a strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls. * An Industry Expert: You are deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001. * A Clear Communicator: You excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences. * Credentialed: You hold a CISSP or CCNP-Security certification. (CSSLP, CCSP, or CISM designations are highly preferred). Working Conditions & Leadership Style * Schedule & Environment: This position operates in an office setting with a current schedule requirement of 4 days per week in-office. * Autonomy & Direction: You will operate under general direction, establishing your own methods and procedures to attain high-level organizational goals. * Team Leadership: You will manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports. Who We Are Welcome to arrivia. We specialize in making brands better through the power of travel. With more than 55 years of combined experience, we are a merger of three powerhouse brands—ICE, SOR Technology, and WMPH Vacations. With offices on both coasts of the US and around the world, we embrace diversity and a passion for travel across our global staff. We are focused on building a customer-first culture, fueled by the best travel experiences for all our members at every point in their journey. Grow with us, as we continue our path to deliver innovative solutions and take charge of change. The adventure is only beginning. Our Core Values * Stay Curious - Explore new challenges and make space to learn, grow and improve. * Keep it Real - Earn trust through open, honest and clear communication. * Own it - Seek ways to make an impact and take action. * Win Together - Create a culture of connection and inclusion where everyone can be their best.

Governance Risk Compliance
Information Security Management
Security Frameworks (NIST ISO SOC2)
Direct Apply
Posted 22 days ago

Ready to join arrivia?

Create tailored applications specifically for arrivia with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt