MLW LogoMost Loved Workplace® Certified Job

Senior Manager, Cybersecurity Strategy & Risk

MLW LogoMost Loved Workplace® Certified Job
92% of candidates apply because they are a Most Loved Workplace®
Strava SF
Department
FullTime

About the Role

At Strava, a Most Loved Workplace® certified employer in the Computer Software space, Connect, inspire, and achieve your personal best with the global active community.

About Strava Strava is the app for active people. With over 200 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey with Strava today. Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward. About This Role Strava's Cybersecurity team protects the trust of a global community of athletes who rely on our platform every day. As the team scales its security program, we're rethinking how we assess and act on security risk: moving away from static, point-in-time risk registers and toward a living, data-driven view of where our real exposure lies. This is a role with a 70/30 split between hands-on execution and people management, reporting directly to the CISO. You'll build this function largely from scratch, standing up a repeatable process that turns various risk signals into a single, prioritized view that executive stakeholders can act on. You'll partner closely with cross-functional stakeholders across the business. We follow a flexible hybrid model that translates to more than half of your time on-site in our San Francisco office, three days per week. What You'll Do Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths Own the AI and third-party risk management process — delivering risk insights that matter, not rubber-stamping compliance Establish a security steering committee with relevant stakeholders to ensure alignment on risk tolerance and prioritization Establish a multi-year, actionable security strategy, roadmap and investment priorities Deliver regular, executive- and board-ready risk reporting Partner across Engineering, Trust & Safety, Legal, AI Enablement, and other business functions, representing security in cross-functional planning and risk reviews Identify and implement opportunities to use AI and automation to improve efficiency of risk workflows Continuously evolve the risk methodology as new data sources, attack patterns, and business priorities emerge What You'll Bring to the Team Bachelor's degree in Engineering, Cybersecurity or related field 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles Security certifications e.g. CISSP, CISM, or other relevant certifications Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end Strong understanding of security controls and how to work with engineering on implementation details Demonstrated track record translating technical security or threat findings into clear risk narratives Hands-on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring) Experience handling ambiguity, driving accountability and working across multiple stakeholders Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives Experience managing and developing teams Experience scaling GRC processes in a high-growth or consumer tech company is a plus Third-party or vendor risk management experience is a plus Quantitative risk methodology experience (e.g., FAIR) is a plus Why Join Us? Movement brings us together. At Strava, we’re building the world’s largest community of active people, helping them stay motivated and achieve their goals. Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether you’re shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact. When you join Strava, you’re not just joining a company—you’re joining a movement. If you’re ready to bring your energy, ideas, and drive, let’s build something incredible together. Strava builds software that makes the best part of our athletes’ days even better. Just as we’re deeply committed to unlocking their potential, we’re dedicated to providing a world-class, inclusive workplace where our employees can grow and thrive, too. We’re backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we’re expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together. Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. California Consumer Protection Act Applicant Notice

Want to learn more about what it's like to work at Strava? View our full profile.

MLW Logo

Why This Is a Most Loved Workplace® Certified Job

What It's Like to Work Here

heart Living the Mission Daily
users Community-Driven Collaboration
zap Audacious Vision with Purpose
compass Flexibility and Work-Life Balance
rocket Growth Through Continuous Learning
Certified for: Most Loved Workplace Most Loved Workplaces® 2026, Most Loved Workplace Most Loved Workplaces® 2021

Frequently Asked Questions About Working at Strava

Common questions candidates ask about this role and Strava's workplace

Strava is the leading subscription platform at the center of connected fitness, with more than 100 million community members in over 190 countries. The platform offers a holistic view of your active lifestyle, no matter where you live, which sport you love and/or what device you use. Everyone belongs on Strava when they are pursuing an active life. Join the community, find motivation and discover new experiences with a Strava subscription.

Please review the specific job listing or contact Strava's recruiting team for details on remote or hybrid work options for this role.

Salary information may vary by role and location. Please check the specific job listing or discuss compensation during the interview process.

Strava is an established organization in its industry. The company is a certified Most Loved Workplace®, highlighting a strong, positive culture and committed workforce.

Key benefit categories include: Health & Wellness, Financial & Retirement, Time Off & Flexibility, Professional Development, Community & Perks. You can view more details on their CertCheck profile.

The day-to-day environment is guided by core values such as Living the Mission Daily and Community-Driven Collaboration and Audacious Vision with Purpose.

The company has committed to inclusive practices including: Inspire Movement and Connection and Prioritize Employee Wellness and Growth.

They have earned Most Loved Workplace® certifications including: Most Loved Workplace Most Loved Workplaces® 2026 and Most Loved Workplace Most Loved Workplaces® 2021.

Strava currently has 21 open positions. They are hiring across departments like Department. You can view all current openings at certcheck.mostlovedworkplace.com/companies/strava/jobs.

The interview process typically involves an initial recruiter screen followed by team interviews. Please contact Strava's recruiting team for specific details on this role's process.

Apply for Senior Manager, Cybersecurity Strategy & Risk

Submit your application directly to the Strava team. Let them know why you'd be a great addition to their loved place to work.

Most Loved Workplace® Logo
Powered by Most Loved Workplace®

The global standard for company culture certification and employer of choice visibility.

Learn more about Most Loved Workplace®