Manager of Application & AI Security
arrivia · Scottsdale, AZ · 1 mo ago
Information TechnologyFull-time
About the role
At arrivia, we are transforming the travel industry and need a visionary leader to ensure our innovation never outpaces our security. As the Manager of Application & AI Security, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines."
Responsibilities
- Forge the Future of AI Security & Governance
- Hold the Central AI Mandate: Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
- Architect AI Guardrails: Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
- Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
- Secure Agentic Runtimes: Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
- Elevate Application Security & DevSecOps
- Own the Secure SDLC: Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
- Enforce Pipeline Integrity: Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
- Secure the Architecture: Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
Qualifications
- An Experienced Leader: You possess a Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience), including 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership.
- A Guardrails-as-Code Practitioner: You have hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins.
- An AI Security Enthusiast: You possess a strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
- An Industry Expert: You are deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
- A Clear Communicator: You excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
- Credentialed: You hold a CISSP or CCNP-Security certification. (CSSLP, CCSP, or CISM designations are highly preferred).
Benefits
- Schedule & Environment: This position operates in an office setting with a current schedule requirement of 4 days per week in-office.
- Autonomy & Direction: You will operate under general direction, establishing your own methods and procedures to attain high-level organizational goals.
- Team Leadership: You will manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.
Pay
The salary range for this role is $120,000 - $150,000 annually, commensurate with experience.
Schedule
This position operates in an office setting with a current schedule requirement of 4 days per week in-office.