Manager of Application & AI Security

arriviaScottsdale, AZ
Onsite

About The Position

As the Manager of Application & AI Security, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines." Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience)
  • 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership.
  • Hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins.
  • Strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
  • Deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
  • Excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
  • Hold a CISSP or CCNP-Security certification.

Nice To Haves

  • CSSLP, CCSP, or CISM designations are highly preferred.

Responsibilities

  • Hold the Central AI Mandate: Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
  • Architect AI Guardrails: Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
  • Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
  • Secure Agentic Runtimes: Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
  • Own the Secure SDLC: Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
  • Enforce Pipeline Integrity: Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
  • Secure the Architecture: Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
  • Manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service