Manager - Application & AI Security
Arrivia
Remote-US · Full-time
Job Context
Arrivia powers the travel behind many of the world's membership and loyalty brands. Its private travel marketplace gives members access to deeply discounted cruises, resorts, and hotels, and its platform runs the booking, servicing, and rewards underneath those programs. The engineering teams build and scale that platform across a distributed, cloud-native architecture.
As Manager of Application & AI Security, you lead a team of four to five and hold Arrivia's central AI-governance mandate. You own the DevSecOps golden pipelines, application security testing, and the runtime security for MCP and AI agents, embedding guardrails as code so delivery speed never outruns risk review. You own the secure software development lifecycle across the application and PaaS layer, and you set the policy for how the company adopts LLMs and Copilot safely, from shadow-AI controls to the model registry and approval workflow. This role reports to the EVP of IT and Security and is Remote-US (open to most states, with a few exceptions listed on the role page).
You fit if you have five or more years in application security or DevSecOps, including leading a team, and you have built security into CI/CD pipelines as guardrails-as-code. You bring working knowledge of AI and LLM security, from usage governance and prompt-injection testing to LLM red-teaming and MCP runtime controls. A CISSP or CCNP-Security is required for this role. The full requirements live on the role page at provn.co.
How hiring works here
Applying with Provn is designed to get more interviews for the best candidates coming in without a referral. The challenge is the first step of the application, and it carries as much weight as anything else you submit. Instead of sending a cold resume into an ATS and waiting, you complete a challenge built by Arrivia: you build the work, then record a short video walking through how you approached it. You'll work through it the way you would on the job, and you'll show the thinking behind the calls you made.
Both the artifact and the video are required to complete your application, and only complete applications are considered for this role. You'll take on a security scenario shaped like the work you'd own here and show how you'd assess the risk, where you'd set the guardrail, and why.
Why that works in your favor:
- You show how you actually reason about application and AI risk and where you draw the line, instead of hoping a resume of frameworks and certs gets it across.
- Your security judgment becomes visible, which no list of tools and standards on a resume can prove.
- One challenge puts you in front of the security leadership team, scored on the work, with no referral required to get there.
The hiring manager reviews every completed submission, and the strongest candidates go straight to an interview round. No referral needed. Performance over pedigree. Proof over polish.
What's in it for you
Compensation for this role is $120,000-$160,000. Salary is competitive and will be discussed during interviews. You also get access to the private travel marketplace with deeply discounted cruises, resorts, and hotels, comprehensive medical, dental, and vision coverage, and a 401k with company match. Beyond the package, you lead the team that makes safe AI adoption the default across the company, with a clear mandate over application security, AI governance, and the pipelines everything ships through.
Apply by completing the challenge at provn.co, where the full role details live. Applications are open through August 28.
Pay: $120,000.00 - $160,000.00 per year
Benefits:
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Work Location: Remote