Hybrid Cybersecurity Strategy & Risk Leader

Socket.dev

San Francisco (CA)

Hybrid

USD 210,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Strava is seeking a senior Security leader to own and scale risk management, governance, and security strategy, reporting to the CISO. You will build processes turning risk signals into a prioritized view for executives, partnering across engineering, legal, and AI teams to align on risk tolerance and prioritization.

You’ll lead a small team, manage complex risk programs, and drive cross-functional execution with a focus on AI-enabled risk insights and automation.

Qualifications

  • Bachelor's degree in Engineering, Cybersecurity or related field
  • 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles
  • Security certifications e.g. CISSP, CISM, or other relevant certifications
  • Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end
  • Strong understanding of security controls and how to work with engineering on implementation details
  • Demonstrated track record translating technical security or threat findings into clear risk narratives
  • Hands-on technical fluency: you’ve personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them
  • Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring)
  • Experience handling ambiguity, driving accountability and working across multiple stakeholders
  • Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives
  • Experience managing and developing teams
  • Experience scaling GRC processes in a high-growth or consumer tech company is a plus
  • Third-party or vendor risk management experience is a plus
  • Quantitative risk methodology experience (e.g., FAIR) is a plus

Responsibilities

  • Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them
  • Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths
  • Own the AI and third-party risk management process — delivering risk insights that matter, not rubber-stamping compliance
  • Establish a security steering committee with relevant stakeholders to ensure alignment on risk tolerance and prioritization
  • Establish a multi-year, actionable security strategy, roadmap and investment priorities
  • Deliver regular, executive- and board-ready risk reporting
  • Partner across Engineering, Trust & Safety, Legal, AI Enablement, and other business functions, representing security in cross-functional planning and risk reviews
  • Identify and implement opportunities to use AI and automation to improve efficiency of risk workflows
  • Continuously evolve the risk methodology as new data sources, attack patterns, and business priorities emerge

Skills

Security leadership
Risk management
Threat modeling
Automation tools
Cross-functional
Governance
GRC
Communication

Education

Bachelor's degree in Engineering
Cybersecurity

Tools

CISSP
CISM

Job description

Strava is seeking a senior Security leader to own and scale risk management, governance, and security strategy, reporting to the CISO. You will build processes turning risk signals into a prioritized view for executives, partnering across engineering, legal, and AI teams to align on risk tolerance and prioritization.

You’ll lead a small team, manage complex risk programs, and drive cross-functional execution with a focus on AI-enabled risk insights and automation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Strategy & Risk Leader — Hybrid Role
Cybersecurity Strategy & Risk Leader — Hybrid Role

Strava, Inc. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Cybersecurity Strategy & Risk Leader
Cybersecurity Strategy & Risk Leader

Strava • United States

Hybrid
USD 180,000 - 280,000
Strava employee benefits
Senior Cybersecurity Strategy & Risk Lead (Hybrid SF)
Senior Cybersecurity Strategy & Risk Lead (Hybrid SF)

TOGETHXR • San Francisco (CA)

Hybrid
USD 160,000 - 220,000
Senior Cybersecurity Strategy & Risk Leader (Hybrid SF)
Senior Cybersecurity Strategy & Risk Leader (Hybrid SF)

United States Digital Space LLC • United States

Hybrid
USD 260,000 - 360,000
Enterprise Security Leader — Architecture & Strategy
Enterprise Security Leader — Architecture & Strategy

Strava • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Senior Manager, Enterprise Security Engineering
Senior Manager, Enterprise Security Engineering

United States Digital Space LLC • United States

Hybrid
USD 250,000 - 350,000
Head of Enterprise Security Engineering - Hybrid SF
Head of Enterprise Security Engineering - Hybrid SF

Socket.dev • San Francisco (CA)

Hybrid
USD 230,000 - 350,000
Enterprise Security Engineering Lead
Enterprise Security Engineering Lead

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

TOGETHXR • San Francisco (CA)

Hybrid
USD 160,000 - 220,000
Senior Manager, Detection & Response — Security Operations Leader
Senior Manager, Detection & Response — Security Operations Leader

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Hybrid work model