Manager of Application & AI Security
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Are you ready to pioneer the frontier of AI security while championing modern Dev Sec Ops ? At arrivia, we are transforming the travel industry, and we need a visionary leader to ensure our innovation never outpaces our security.
As the Manager of Application & AI Security
, you will hold the central AI-governance mandate and own our Dev Sec Ops "golden pipelines". Your mission is to keep arrivia's applications, cloud ecosystems, and cutting-edge AI deployments governed and secure-by-default. You will bridge the gap between rapid delivery and robust risk review, building security guardrails directly into code and defining what safe AI adoption looks like at scale.
- Hold the Central AI Mandate: Establish and enforce LLM/Copilot usage policies, local and public model governance, and shadow-AI controls.
- Architect AI Guardrails: Implement technical controls aligned with the NIST AI RMF and ISO/IEC 42001 alongside our GRC team.
- Lead AI Red-Teaming: Conduct proactive prompt-injection, jailbreak testing, and LLM red-teaming utilizing the OWASP Top 10 for LLM Applications and MITRE ATLAS frameworks.
- Secure Agentic Runtimes: Own the model registry, AI-BOM, and runtime security for Model Context Protocol (MCP) and AI agents, implementing per-tool-call authorization and strict containment.
- Own the Secure SDLC: Champion application security reviews for major releases, PaaS/SaaS application posture, and lifecycle frameworks per NIST SSDF and ISO/IEC 27001:2022.
- Enforce Pipeline Integrity: Standardize CI/CD golden-pipeline guardrails and artifact integrity (SLSA), leading automated scanning across SAST, DAST, SCA, and secrets management.
- Secure the Architecture: Define container, Kubernetes, Infrastructure-as-Code (IaC) security standards, threat modeling (OWASP SAMM), and contact center tooling guardrails to protect the member experience.
- AI Under Governance: 100% of AI tools are risk-assessed before deployment, shadow-AI is discovered and triaged automatically within SLA, and compliance policies are strictly enforced.
- Flawless Delivery: 100% of production pipelines are covered by automated CI/CD guardrails, with zero critical application security findings shipping to production.
- Proactive Defense: Comprehensive security posture scores for PaaS/SaaS meet or exceed targets, with automated blocking of critical vulnerabilities built right into the developer workflow.
- An Experienced Leader: You possess a Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or 7+ years of dedicated security experience), including 5+ years specializing in App Sec and Dev Sec Ops with a proven track record of team leadership.
- A Guardrails-as-Code Practitioner: You have hands-on experience building automated security controls directly into CI/CD platforms like Azure Dev Ops, Git Hub Actions, Git Lab, or Jenkins.
- An AI Security Enthusiast: You possess a strong working knowledge of LLM application security risks, prompt-injection defense, model registries, and the emerging paradigms of AI-agent runtime controls.
- An Industry Expert: You are deeply familiar with industry standards including OWASP (ASVS, Top 10, API Top 10), NIST SSDF, NIST AI RMF, and ISO 42001/27001.
- A Clear Communicator: You excel at translating complex, highly technical vulnerabilities into actionable, business-friendly insights for diverse audiences.
- Credentialed: You hold a CISSP or CCNP-Security certification. (CSSLP, CCSP, or CISM designations are highly preferred).
- Schedule & Environment: This position operates in an office setting with a current schedule requirement of 4 days per week in-office.
- Autonomy & Direction: You will operate under general direction, establishing your own methods and procedures to attain high-level organizational goals.
- Team Leadership: You will manage and mentor a growing Application & AI Security team, scaling it from 3 to 5 direct reports.
Welcome to arrivia
. We specialize in making brands better through the power of travel. With more than 55…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).