Senior Manager, Enterprise Security

Socket.dev

San Francisco (CA)

Hybrid

USD 230,000 - 350,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Strava is seeking a Senior Manager of Enterprise Security Engineering to own strategy and execution of the corporate security program. Reporting to the CISO, you will lead a lean, high-performing team securing Strava's internal environment while enabling secure growth.

This is a highly technical leadership role, defining long-term roadmaps and balancing in-house work with strategic partners to keep the business moving forward. The role is hybrid with on-site in San Francisco three days a week.

Qualifications

  • 10+ years designing, building, and operating enterprise security programs in cloud-first environments.
  • 3+ years leading security engineering teams with hands-on engineering involvement.
  • Strong communication and stakeholder management to influence executives through risk-based decisions.

Responsibilities

  • Own and execute the enterprise security roadmap across identity, endpoint, email, corporate network and SaaS security.
  • Lead a small team of enterprise security engineers, fostering a culture of technical excellence, operational rigor and ownership.
  • Stay hands-on by designing, building, and configuring security capabilities alongside your team when needed.
  • Build an operating model that combines internal engineering with strategic partners, determining what should be owned in-house and holding vendors accountable for measurable security outcomes.
  • Architect and evolve Strava's identity and access management platform, including SSO, MFA, privileged access, identity governance, lifecycle automation, and Zero Trust principles across cloud and SaaS environments.

Skills

Leadership
Cloud security
Team leadership
Stakeholder management
IAM architecture
Security architecture

Tools

Okta
Intune
Jamf
ZTNA
Sailpoint
GWS
Slack
GitHub

Job description

About Strava

Strava is the app for active people. With over 200 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey with Strava today.

Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward.

About This Role

Strava's Cybersecurity team protects the trust of over 200 million athletes by securing our platform, our data, and the systems our community depends on every day. Enterprise Security Engineering owns the engineering, architecture, and operation of the systems that secure Strava's workforce and corporate environment across a globally distributed company.

As the Senior Manager of Enterprise Security Engineering, you will own the strategy and execution of Strava's corporate security program. Reporting directly to the CISO, you will lead a lean, high-performing engineering team responsible for securing Strava's internal environment while partnering across the business to enable secure growth.

This is a highly technical leadership role. You'll define the long-term roadmap and operating model for the function, including which capabilities Strava owns internally versus delivers through strategic partners, while balancing strategic leadership with execution and making risk-based decisions that strengthen security without slowing the business down.

We follow a flexible hybrid model that translates to spending more than half of your time on-site in our San Francisco office, three days per week.

What You'll Do

Own and execute the enterprise security roadmap across corporate identity, endpoint, email, corporate network and SaaS security.

Lead a small team of enterprise security engineers, fostering a culture of technical excellence, operational rigor and ownership.

Stay hands‑on by designing, building, and configuring security capabilities alongside your team when needed.

Build an operating model that combines internal engineering with strategic partners, determining what should be owned in‑house and holding vendors accountable for measurable security outcomes.

Architect and evolve Strava's identity and access management platform, including SSO, MFA, privileged access, identity governance, lifecycle automation, and Zero Trust principles across cloud and SaaS environments.

Secure Strava's enterprise environment by driving the architecture, hardening, and automation of endpoints, enterprise networking, email, collaboration platforms, SaaS applications, and third‑party integrations.

Develop and execute strategies for enterprise AI security, data security, vulnerability and exposure management, and continuous hardening of the corporate environment.

Partner closely with IT, Engineering, Legal, People, Workplace to build secure‑by‑default experiences.

Partner with the Detection & Response team during corporate‑related security incidents.

Communicate priorities, risks, and measurable outcomes to the CISO and senior leadership.

What You'll Bring to the Team
  • Leadership
  • 10+ years of experience designing, building, and operating Enterprise Security programs in modern cloud‑first environments.
  • 3+ years leading security engineering teams, with experience coaching engineers while remaining technically engaged.
  • Strong communication and stakeholder management skills, with the ability to influence cross‑functional partners and executives through clear, risk‑based decision making.
  • Deep expertise in operating enterprise security capabilities at scale, including MFA, SSO,OAuth, MDM, EDR, device compliance and fleet management across macOS and Windows.
  • Experience working with tooling such as Okta, Intune, Jamf, ZTNA, Sailpoint, GWS, Slack, Github.
  • Experience designing enterprise security architectures that balance strong security with employee productivity and developer velocity.
  • Experience managing strategic security vendors and managed service providers.
Bonus Points
  • Experience with DLP, CASB, SSPM, DSPM, or modern data security platforms.
  • Experience integrating AI governance and security into enterprise productivity platforms.
  • Experience building self‑service security capabilities and security automation for internal users.
Why Join Us?

Movement brings us together. At Strava, we’re building the world’s largest community of active people, helping them stay motivated and achieve their goals.

Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether you’re shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact.

When you join Strava, you’re not just joining a company—you’re joining a movement. If you’re ready to bring your energy, ideas, and drive, let’s build something incredible together.

Strava builds software that makes the best part of our athletes’ days even better. Just as we’re deeply committed to unlocking their potential, we’re dedicated to providing a world‑class, inclusive workplace where our employees can grow and thrive, too. We’re backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we’re expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together.

Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy‑related condition, marital status, height and/or weight.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

California Consumer Protection Act Applicant Notice

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

Strava • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

United States Digital Space LLC • United States

Hybrid
USD 250,000 - 350,000
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

Socket.dev • San Francisco (CA)

Hybrid
USD 210,000 - 320,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

Strava, Inc. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

TOGETHXR • San Francisco (CA)

Hybrid
USD 160,000 - 220,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

United States Digital Space LLC • United States

Hybrid
USD 260,000 - 360,000
Senior Manager, Cybersecurity Strategy & Risk
Senior Manager, Cybersecurity Strategy & Risk

Strava • United States

Hybrid
USD 180,000 - 280,000
Strava employee benefits
Senior Manager, Detection Response
Senior Manager, Detection Response

Strava, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Senior Manager, Detection Response
Senior Manager, Detection Response

Strava • San Francisco (CA)

Hybrid
USD 180,000 - 240,000