Senior Manager Detection Response positions focus on delivering results in their domain. This page aggregates open Senior Manager Detection Response roles and what employers typically expect.
ABOUT STRAVA Strava is the app for active people. With over 200 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey https://www.strava.com/subscription with Strava today. Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward. About This Role Strava's Security team protects the platform, the data, and the trust of more than 200 million athletes worldwide. As threats against consumer platforms grow more sophisticated, this team is responsible for detecting, investigating, and responding to them quickly and confidently. We're looking for a Senior Manager, Detection & Response to own and scale this function, reporting to the CISO. You'll set the strategy and drive execution for security monitoring, incident response, recovery, and post-incident improvement covering both our corporate environment and the Strava product. You'll build and manage a small team of engineers, decide how to extend that team's reach through automation and strategic partners, and partner closely with Infrastructure, Product Security, Enterprise Security, IT, and Engineering to make sure detection and response capabilities are built into our systems by design. This is a role for a technically hands-on leader who's naturally curious and comfortable digging in without all the facts, in a high-growth environment. We follow a flexible hybrid model that translates to more than half of your time on-site in our San Francisco office, three days per week. What You'll Do Lead incident response and security operations, acting as the senior escalation point and incident commander during active investigations Build and mature detection engineering across cloud, endpoint, and application layers (Strava product surface), continuously raising detection quality and coverage Own the security logging and telemetry pipeline, ensuring the right data is collected, normalized, and usable for detection Shape the operating model for the function, deciding what we build in-house versus deliver through managed services and strategic vendors, and holding those partners accountable for measurable security outcomes Leverage outside threat intel to proactively improve detection Modernize the SOC with automation and AI to increase coverage and speed up response Manage incident playbooks, on-call and escalation paths, and run tabletop exercises Deliver clear, executive-ready reporting on incident trends, coverage, and program maturity Build, manage and coach a small team of detection and response engineers Apply threat intelligence and a working knowledge of adversary tradecraft to drive proactive detection and threat hunting What You'll Bring to the Team A highly collaborative, low-ego approach to working across security, engineering, and other partner teams Deep technical credibility and operational instincts, with a track record of building or scaling a detection engineering or security operations program Sound understanding of modern adversary tradecraft, with experience turning threat intelligence into practical detection strategies, proactive hunts, and response actions Experience extending a lean team's coverage through managed services or security vendors, including selecting partners and holding them accountable to measurable outcomes Track record leading incident command for security incidents involving multiple stakeholders, from working teams to executive leadership Excellent problem-solving instincts and comfort operating with ambiguity, including the judgment to think beyond established playbooks when a situation calls for it, and a steady, structured presence during active incidents Familiarity applying automation or AI/ML techniqu…