Manager, Application & AI Security
arrivia · Remote (US) · Full-time
About arrivia
arrivia specializes in making brands better through the power of travel, powering loyalty and membership travel programs. Formed from the merger of ICE, SOR Technology, and WMPH Vacations, the company brings more than 55 years of combined experience and operates on both US coasts and around the world.
What You'll Do
- Own the secure SDLC per NIST SSDF and ISO/IEC 27001, including application security reviews for major releases and PaaS/SaaS posture.
- Own CI/CD golden-pipeline guardrails, pipeline and artifact integrity, and pipeline monitoring.
- Run application security testing across API security, OWASP ASVS, and the OWASP Top 10 and API Security Top 10.
- Own container, Kubernetes, and IaC security scanning, threat modeling, secure-code training, and SBOM generation.
- Hold the central AI-governance mandate: LLM and Copilot usage policy and data-leakage and shadow-AI controls under NIST AI RMF and ISO/IEC 42001.
- Own the AI and model inventory, AI-BOM, and model registry and approval workflow.
- Run prompt-injection and jailbreak testing and LLM red-teaming (OWASP Top 10 for LLM Applications; MITRE ATLAS).
- Secure MCP and AI-agent runtimes with per-tool-call authorization, guardrails, and containment.
What You Bring
- A degree in computer science, cybersecurity, or a related field, or a minimum of 7 years in security; 5+ years in application security and/or DevSecOps, including team leadership.
- Hands-on experience building security into CI/CD as guardrails-as-code (Azure DevOps, GitHub Actions, GitLab, Jenkins).
- Strong application security testing across SAST, DAST, SCA, secrets scanning, and API security (Checkmarx, Veracode, Snyk).
- Knowledge of API security architecture and standards such as OAuth2, OWASP, and CIS; experience securing containers, Kubernetes, and IaC, threat modeling, and generating SBOMs.
- Working knowledge of AI/LLM security: usage governance, prompt-injection and jailbreak testing, LLM red-teaming, and MCP/AI-agent runtime controls; familiarity with NIST AI RMF and ISO 42001.
- CISSP or CCNP-Security required; CSSLP, CCSP, or CISM preferred.
Compensation and Benefits
- $137,000-$206,000.
- Remote within the US, leading the App and AI Security team (currently three, growing to four or five).
How hiring works here
To apply for this role, you must create an account on provn.co and submit all required application artifacts. Resume only applications may be considered, but candidates who complete a full application are reviewed with priority.
Referrals are king for getting an interview. But what if you don't have a referral? Applying with Provn is designed to help you get more interviews. Instead of sending a cold resume into an ATS and waiting, you will complete a challenge built by arrivia and submit a short video walking through your approach. No time limit. No timers. No restrictions on AI usage. Show how you build with AI.
Why that works in your favor
- You show how you actually build and ship with coding agents, instead of hoping a resume communicates your skill clearly.
- Your judgment with AI becomes visible, which no "proficient with AI coding agents" resume bullet can prove.
- One challenge puts you in front of the security team, scored on the work. Priority without a referral!
The hiring manager reviews every completed submission, and strongest candidates go straight to an interview round. No referral needed. Performance over pedigree. Proof over polish.
For this role, the challenge is a significant part of your candidacy. If you have been looking for a foot in the door, a chance to show what you can do, if you have ever felt like all you needed was ten minutes with the hiring manager to prove yourself, this is that opportunity.
Pay: $137,000.00 - $206,000.00 per year
Benefits:
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Work Location: Remote