Provn
    How it worksBrowse jobsFor companiesBlogLog in

    © 2026 Provn Inc. All rights reserved.

    About•Blog•Terms of Service•Privacy Policy

    Made with love in Seattle

    Arrivia/Manager - Application & AI Security
    Arrivia logo

    Manager - Application & AI Security

    Arrivia
    Type
    full-time
    Work Style
    remote
    Location
    Remote (US)
    Posted
    July 20, 2026
    Description

    To be considered for this role, you must complete the associated challenge

    You will keep arrivia's applications, cloud, and AI usage governed and secure-by-default — so delivery speed never outruns risk review. You hold the central AI-governance mandate and own the DevSecOps golden pipelines, application security testing, and MCP/AI-agent runtime security, embedding guardrails as code and making safe AI adoption the default.

    Reports to: EVP – IT & Security / Chief Information Officer (CIO) Direct Reports: Yes — will lead the App & AI Security team of approximately 4–5 (current team of 3, target 4–5)

    WHAT YOU'LL DO

    • Own the secure software development lifecycle per NIST SSDF (SP 800-218) and ISO/IEC 27001:2022 A.8.25–A.8.31, including application security reviews for major releases and PaaS/SaaS application posture.
    • Own Contact Center tooling security guardrails, including agent flows, member workflows, and overall platform/call center security guardrails for member experience.
    • Own CI/CD golden-pipeline guardrails and pipeline/artifact integrity (SLSA), run pipeline monitoring, and manage application/pipeline PIM role assignments through the platform operated by Identity.
    • Run application security testing — API security, aligned to OWASP ASVS and the OWASP Top 10 / API Security Top 10 (ISO/IEC 27001:2022 A.8.29).
    • Own container/Kubernetes and IaC security scanning, threat modeling (OWASP SAMM), secure-code training, and SBOM generation for internally built applications (NIST SSDF; NTIA minimum elements).
    • Own cloud tenant security guardrails at the application/PaaS layer.
    • Provide the cloud-architecture domain input to the GTM security review owned by GRC.
    • AI: Hold the central AI-governance mandate — LLM/Copilot usage policy, local/public model governance, and data-leakage & shadow-AI controls — implementing NIST AI RMF (Govern/Map/Measure/Manage) and ISO/IEC 42001 technical controls with GRC.
    • AI: Own the AI/model inventory and AI-BOM and the model registry and approval workflow.
    • AI: Conduct prompt-injection / jailbreak testing and LLM red-teaming (OWASP Top 10 for LLM Applications; MITRE ATLAS).
    • AI: Secure MCP and AI-agent runtimes — per-tool-call authorization, guardrails, and containment.

    HOW THIS ROLE FITS THE TEAM

    • Identity owns PIM/PAM and identity governance — this role consumes it for application and pipeline entitlements.
    • Infrastructure owns IaaS/compute posture and AI/ML hosting — this role owns application/PaaS posture and pipeline guardrails.
    • GRC owns the AI management-system program and evidence (ISO/IEC 42001 clauses; NIST AI RMF Govern) — this role implements the technical AI controls and operates the model registry.
    • Procurement reviews third-party/supplier SBOMs — this role generates SBOMs for internally built applications.
    • Data Security owns prompt/response DLP and training-data controls — this role owns runtime guardrails, the model registry, and red-teaming.

    WHAT SUCCESS LOOKS LIKE

    • LLM/Copilot usage policy enforced; 100% of AI tools risk-assessed before use; shadow-AI triaged within SLA.
    • 100% of production pipelines covered by CI/CD guardrails and pipeline monitoring.
    • Application security reviews completed for 100% of major releases, with zero critical app-sec findings shipped.
    • PaaS/SaaS security-posture score at or above target; PIM role assignments reviewed quarterly.
    • SAST, DAST, SCA, and secrets scanning automated across 100% of pipelines with auto-block of critical findings; shadow-AI discovery automated.

    KEY PROJECTS

    • Enterprise AI governance & shadow-AI control (Now) — Usage policy, discovery, and prompt DLP.
    • Secure-by-default CI/CD golden pipeline templates (Now) — DevSecOps guardrails-as-code with auto-block of criticals.
    • Cloud tenant guardrails hardening (Next) — Tenant controls across cloud and SaaS.
    • AI-agent & MCP runtime security gateway (Next) — Per-tool-call authorization and containment.
    Required Qualifications

    Bachelor's degree in Computer Science, Cybersecurity, or a related field, or a minimum of 7 years in security. 5+ years in application security and/or DevSecOps, including team leadership. Hands-on experience building security into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions, GitLab, Jenkins) as guardrails-as-code. Strong experience with application security testing across SAST, DAST, SCA/open-source, secrets scanning, and API security (e.g., Checkmarx, Veracode, Snyk). Comprehensive knowledge of API security architecture and standards such as OAuth2, OWASP, and CIS. Experience securing containers/Kubernetes and Infrastructure-as-Code, threat modeling, and generating SBOMs. Working knowledge of AI/LLM security: usage governance, prompt-injection and jailbreak testing, LLM red-teaming, and MCP/AI-agent runtime controls. Familiarity with AI governance frameworks such as NIST AI RMF and ISO 42001. Ability to translate complex technology issues into language a wide range of audiences can understand. CISSP or CCNP-Security required; CSSLP, CCSP, or CISM preferred.

    Benefits & Perks

    Welcome to arrivia. We specialize in making brands better through the power of travel. With more than 55 years of combined experience, we're a merger of three powerhouse brands — ICE, SOR Technology, and WMPH Vacations. With offices on both coasts of the US and around the world, we embrace diversity and a passion for travel across our global staff.

    We're focused on building a customer-first culture, fueled by the best travel experiences for all our members at every point in their journey. Grow with us as we continue our path to deliver innovative solutions and take charge of change.

    Our Core Values:

    • Stay Curious — Explore new challenges and make space to learn, grow and improve
    • Keep it Real — Earn trust through open, honest and clear communication
    • Own it — Seek ways to make an impact and take action
    • Win Together — Create a culture of connection and inclusion where everyone can be their best

    Your Application

    Your application starts with a short challenge.

    On this page

    Top of Page
    Description
    QualificationsBenefits & Perks
    Challenges
    Arrivia logoAbout Arrivia

    Founded in 1997 and rebranded in 2020 to reflect several acquisitions and phenomenal growth as a travel technology provider for companies wishing to reimagine their loyalty and rewards programs. Arrivia is now the world's largest stand-alone travel loyalty provider.