Primary record

Senior Manager, Cybersecurity Strategy & Risk

Strava Indexed employerStrava SF
Source-hosted applyChecked 1h ago$270K–$290K/yrFull-Time
Apply at Strava

Strava receives this application through Ashby. Babu Careers does not claim delivery.

Workplace

hybrid

Employment

Full-Time

Published

Jul 21, 2026

Closes

No date supplied

The role

ABOUT STRAVA Strava is the app for active people. With over 200 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey https://www.strava.com/subscription with Strava today. Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward. ABOUT THIS ROLE Strava's Cybersecurity team protects the trust of a global community of athletes who rely on our platform every day. As the team scales its security program, we're rethinking how we assess and act on security risk: moving away from static, point-in-time risk registers and toward a living, data-driven view of where our real exposure lies. This is a role with a 70/30 split between hands-on execution and people management, reporting directly to the CISO. You'll build this function largely from scratch, standing up a repeatable process that turns various risk signals into a single, prioritized view that executive stakeholders can act on. You'll partner closely with cross-functional stakeholders across the business. We follow a flexible hybrid model that translates to more than half of your time on-site in our San Francisco office, three days per week. WHAT YOU'LL DO - Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them - Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths - Own the AI and third-party risk management process — delivering risk insights that matter, not rubber-stamping compliance - Establish a security steering committee with relevant stakehold

Requirements

Department: Department; Team: Engineering