← Back to job listings
ST
Senior Manager of Cybersecurity Strategy & Risk
Strava · United States
About The Role
Join Strava's Cybersecurity team as a Senior Manager of Cybersecurity Strategy & Risk. In this role, you will build and advance Strava's security governance, strategy, and risk management programs. You will establish a repeatable process for prioritizing risk signals, own the AI and third-party risk management process, and deliver regular risk reporting to executive stakeholders. You will partner with cross-functional teams and continuously evolve the risk methodology. This position offers a 70/30 split between hands-on execution and people management, reporting directly to the CISO.
- Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them.
- Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths.
- Establish a multi-year, actionable security strategy, roadmap and investment priorities, and deliver regular, executive- and board-ready risk reporting.
- Quantitative risk methodology experience (e.g., FAIR) is a plus
- 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles
- Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end
- Hands-on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them
- Experience handling ambiguity, driving accountability and working across multiple stakeholders
- Third-party or vendor risk management experience is a plus
- Bachelor's degree in Engineering, Cybersecurity or related field
- Experience managing and developing teams
- Experience scaling GRC processes in a high-growth or consumer tech company is a plus
- Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring)
- Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives
- Strong understanding of security controls and how to work with engineering on implementation details
- Security certifications e.g. CISSP, CISM, or other relevant certifications
- Demonstrated track record translating technical security or threat findings into clear risk narratives
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring