Manager of Application & AI Security

arrivia. Go far in the travel industry.Scottsdale, AZ
Onsite

About The Position

Are you ready to pioneer the frontier of AI security while championing modern DevSecOps? At arrivia, we are transforming the travel industry, and we need a visionary leader to ensure our innovation never outpaces our security. As the Manager of Application & AI Security, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines." Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience)
  • 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership.
  • Hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins.
  • Strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
  • Deep familiarity with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
  • Excellent communication skills, able to translate complex technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
  • CISSP or CCNP-Security certification.

Nice To Haves

  • CSSLP, CCSP, or CISM designations are highly preferred.

Responsibilities

  • Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
  • Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
  • Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
  • Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
  • Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
  • Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
  • Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
  • Manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.

Benefits

  • 4 days per week in-office schedule
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service