Skip to content
← Back to job listings

Senior Manager of Cybersecurity Strategy & Risk

Strava · United States

External listingfull-time7 days ago

About The Role

Join Strava's Cybersecurity team as a Senior Manager of Cybersecurity Strategy & Risk. In this role, you will build and advance Strava's security governance, strategy, and risk management programs. You will establish a repeatable process for prioritizing risk signals, own the AI and third-party risk management process, and deliver regular risk reporting to executive stakeholders. You will partner with cross-functional teams and continuously evolve the risk methodology. This position offers a 70/30 split between hands-on execution and people management, reporting directly to the CISO.

  • Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them.
  • Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths.
  • Establish a multi-year, actionable security strategy, roadmap and investment priorities, and deliver regular, executive- and board-ready risk reporting.
  • Quantitative risk methodology experience (e.g., FAIR) is a plus
  • 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles
  • Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end
  • Hands-on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them
  • Experience handling ambiguity, driving accountability and working across multiple stakeholders
  • Third-party or vendor risk management experience is a plus
  • Bachelor's degree in Engineering, Cybersecurity or related field
  • Experience managing and developing teams
  • Experience scaling GRC processes in a high-growth or consumer tech company is a plus
  • Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring)
  • Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives
  • Strong understanding of security controls and how to work with engineering on implementation details
  • Security certifications e.g. CISSP, CISM, or other relevant certifications
  • Demonstrated track record translating technical security or threat findings into clear risk narratives

This is an external listing. JobSpring does not represent or verify the employer. Report this listing