Are you ready to pioneer the frontier of AI security while championing modern DevSecOps? At arrivia, we are transforming the travel industry, and we need a visionary leader to ensure our innovation never outpaces our security.
As the Manager of Application & AI Security, you will hold the central AI-governance mandate and own our DevSecOps "golden pipelines." Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale.
What You’ll Do
Forge the Future of AI Security & Governance
- Hold the Central AI Mandate: Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
- Architect AI Guardrails: Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
- Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
- Secure Agentic Runtimes: Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
Elevate Application Security & DevSecOps
- Own the Secure SDLC: Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
- Enforce Pipeline Integrity: Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
- Secure the Architecture: Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
What Success Looks Like
- AI Under Governance: 100% of AI tools are risk-assessed before deployment, shadow-AI is discovered and triaged automatically within SLA, and compliance policies are strictly enforced.
- Flawless Delivery: 100% of production pipelines are covered by automated CI/CD guardrails, with zero critical application security findings shipping to production.
- Proactive Defense: Comprehensive security posture scores for PaaS/SaaS meet or exceed targets, with automated blocking of critical vulnerabilities built right into the developer workflow.
Who You Are
- An Experienced Leader: You possess a Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience), including 5+ years specializing in AppSec and DevSecOps with a proven track record of team leadership.
- A Guardrails-as-Code Practitioner: You have hands-on experience building automated security controls directly into CI/CD platforms like Azure DevOps, GitHub Actions, GitLab, or Jenkins.
- An AI Security Enthusiast: You possess a strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
- An Industry Expert: You are deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
- A Clear Communicator: You excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
- Credentialed: You hold a CISSP or CCNP-Security certification. (CSSLP, CCSP, or CISM designations are highly preferred).
Working Conditions & Leadership Style
- Schedule & Environment: This position operates in an office setting with a current schedule requirement of 4 days per week in-office.
- Autonomy & Direction: You will operate under general direction, establishing your own methods and procedures to attain high-level organizational goals.
- Team Leadership: You will manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.
Who We Are
Welcome to arrivia. We specialize in making brands better through the power of travel. With more than 55 years of combined experience, we are a merger of three powerhouse brands—ICE, SOR Technology, and WMPH Vacations. With offices on both coasts of the US and around the world, we embrace diversity and a passion for travel across our global staff.
We are focused on building a customer-first culture, fueled by the best travel experiences for all our members at every point in their journey. Grow with us, as we continue our path to deliver innovative solutions and take charge of change. The adventure is only beginning.
Our Core Values
- Stay Curious - Explore new challenges and make space to learn, grow and improve.
- Keep it Real - Earn trust through open, honest and clear communication.
- Own it - Seek ways to make an impact and take action.
- Win Together - Create a culture of connection and inclusion where everyone can be their best.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.