Cybersecurity Strategy & Risk Leader — Hybrid Role

Strava, Inc.

San Francisco (CA)

Hybrid

USD 180,000 - 240,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Strava, Inc. is seeking a senior security leader to own governance, risk management and a growing security program reporting to the CISO.

You will build a scalable function from the ground up, turn diverse risk signals into a single prioritized view, and partner across engineering, legal, and product teams. You will lead a small team, apply quantitative risk methods, and drive continuous improvement in risk processes, automation, and third‑party risk management, while preparing board‑level risk

Qualifications

  • Bachelor's degree in Engineering, Cybersecurity or related field.
  • 8–12 years of security, cyber risk, or related roles.
  • Security certifications such as CISSP, CISM, or equivalent.
  • Experience standing up and managing security risk programs and cross-functional execution.
  • Strong understanding of security controls and collaboration with engineering on implementations.
  • Ability to translate technical findings into clear risk narratives.
  • Hands-on technical fluency with threat models, vulnerability data, or incident data.
  • Experience using AI or automation to improve risk workflows.
  • Experience managing teams and driving accountability across stakeholders.
  • Knowledge of scaling GRC processes in high-growth consumer tech is a plus.

Responsibilities

  • Own and advance Strava's security governance, strategy and risk programs with a small team.
  • Create a repeatable process turning risk signals into a prioritized risk view with thresholds.
  • Own AI and third-party risk management, delivering meaningful risk insights.
  • Establish a security steering committee with stakeholders for risk tolerance and prioritization.
  • Develop a multi-year security strategy, roadmap and investment priorities.
  • Deliver executive- and board-ready risk reporting.
  • Collaborate across Engineering, Trust & Safety, Legal and other functions.
  • Identify and implement AI/automation opportunities to improve risk workflows.
  • Evolve risk methodology as new data sources and attack patterns emerge.

Skills

Security governance
Risk management
Leadership
Cross‑functional collaboration
Executive risk reporting
Threat modeling
AI/automation in security
Technical fluency
GRC & controls
Vendor risk management

Education

Bachelor's degree in Engineering/Cybersecurity/related field
CISSP/CISM certifications

Tools

Threat modeling tools
AI/automation in risk workflows

Job description

Strava, Inc. is seeking a senior security leader to own governance, risk management and a growing security program reporting to the CISO.

You will build a scalable function from the ground up, turn diverse risk signals into a single prioritized view, and partner across engineering, legal, and product teams. You will lead a small team, apply quantitative risk methods, and drive continuous improvement in risk processes, automation, and third‑party risk management, while preparing board‑level risk

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Cybersecurity Strategy & Risk Leader
Hybrid Cybersecurity Strategy & Risk Leader

Socket.dev • San Francisco (CA)

Hybrid
USD 210,000 - 320,000
Enterprise Security Leader — Architecture & Strategy
Enterprise Security Leader — Architecture & Strategy

Strava • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Head of Enterprise Security Engineering - Hybrid SF
Head of Enterprise Security Engineering - Hybrid SF

Socket.dev • San Francisco (CA)

Hybrid
USD 230,000 - 350,000
Enterprise Security Engineering Lead
Enterprise Security Engineering Lead

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Security Program Manager - Hybrid & Strategic
Senior Security Program Manager - Hybrid & Strategic

Strava • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

Socket.dev • San Francisco (CA)

Hybrid
USD 210,000 - 320,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

Strava, Inc. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Senior Manager, Detection & Response — Security Operations Leader
Senior Manager, Detection & Response — Security Operations Leader

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

Socket.dev • San Francisco (CA)

Hybrid
USD 230,000 - 350,000
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

Strava • San Francisco (CA)

Hybrid
USD 180,000 - 240,000