Jobedly Post a Job

Senior Manager, Cybersecurity Strategy & Risk

strava · Remote
RemoteFull-timeDepartmentTechnology$128,000–$173,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Senior Manager Cybersecurity Strategy Risk role

Senior Manager Cybersecurity Strategy Risk positions focus on delivering results in their domain. This page aggregates open Senior Manager Cybersecurity Strategy Risk roles and what employers typically expect.

ABOUT STRAVA Strava is the app for active people. With over 200 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey https://www.strava.com/subscription with Strava today. Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward. ABOUT THIS ROLE Strava's Cybersecurity team protects the trust of a global community of athletes who rely on our platform every day. As the team scales its security program, we're rethinking how we assess and act on security risk: moving away from static, point-in-time risk registers and toward a living, data-driven view of where our real exposure lies. This is a role with a 70/30 split between hands-on execution and people management, reporting directly to the CISO. You'll build this function largely from scratch, standing up a repeatable process that turns various risk signals into a single, prioritized view that executive stakeholders can act on. You'll partner closely with cross-functional stakeholders across the business. We follow a flexible hybrid model that translates to more than half of your time on-site in our San Francisco office, three days per week. WHAT YOU'LL DO - Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them - Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths - Own the AI and third-party risk management process — delivering risk insights that matter, not rubber-stamping compliance - Establish a security steering committee with relevant stakeholders to ensure alignment on risk tolerance and prioritization - Establish a multi-year, actionable security strategy, roadmap and investment priorities - Deliver regular, executive- and board-ready risk reporting - Partner across Engineering, Trust & Safety, Legal, AI Enablement, and other business functions, representing security in cross-functional planning and risk reviews - Identify and implement opportunities to use AI and automation to improve efficiency of risk workflows - Continuously evolve the risk methodology as new data sources, attack patterns, and business priorities emerge WHAT YOU'LL BRING TO THE TEAM - Bachelor's degree in Engineering, Cybersecurity or related field - 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles - Security certifications e.g. CISSP, CISM, or other relevant certifications - Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end - Strong understanding of security controls and how to work with engineering on implementation details - Demonstrated track record translating technical security or threat findings into clear risk narratives - Hands-on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them - Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring) - Experience handling ambiguity, driving accountability and working across multiple stakeholders - Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives - Experience managing and developing teams - Experience scaling GRC processes in a high-growth or consumer tech company is a plus - Third-party or vendor ris…

Salary estimate

$128,000 – $173,000/yr
Provided by the employer.

Skills for this role

CommunicationLeadershipSecurityAutomation

Resume tips for Senior Manager Cybersecurity Strategy Risk applicants

Interview preparation

Prepare concrete STAR-format stories that show Senior Manager Cybersecurity Strategy Risk outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Senior Manager Cybersecurity Strategy Risk problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About strava

Strava is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles