FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Manager, Cybersecurity Strategy & Risk
StravaSenior Manager managing cybersecurity strategy and risk at Strava. Overseeing a small team while collaborating with cross-functional partners in a hybrid environment.
Posted 7/22/2026full-timeSan Francisco • California • 🇺🇸 United StatesSenior💰 $270,000 - $290,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security governance, risk management, and technical security assurance, with a strong focus on AI and automation to enhance risk workflows. Proven ability to lead teams, communicate effectively with stakeholders, and deliver actionable risk insights.
Highest-signal resume keywords
Security GovernanceRisk ManagementAI and Automation ToolsSecurity CertificationsCross-Functional Collaboration
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Risk ProgramsThreat ModelsVulnerability FindingsIncident Data InterpretationQuantitative Risk Methodology
Soft Skills
Excellent Communication SkillsTeam ManagementAccountabilityHandling Ambiguity
Tools & Technologies
GRC ProcessesRisk Reporting ToolsAutomation Tools
Certifications & Qualifications
CISSPCISM
Industry Keywords
CybersecurityTechnical Security AssuranceThird-Party Risk ManagementConsumer Tech
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them
- Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths
- Own the AI and third-party risk management process — delivering risk insights that matter, not rubber-stamping compliance
- Establish a security steering committee with relevant stakeholders to ensure alignment on risk tolerance and prioritization
- Establish a multi-year, actionable security strategy, roadmap and investment priorities
- Deliver regular, executive- and board-ready risk reporting
- Partner across Engineering, Trust & Safety, Legal, AI Enablement, and other business functions, representing security in cross-functional planning and risk reviews
- Identify and implement opportunities to use AI and automation to improve efficiency of risk workflows
- Continuously evolve the risk methodology as new data sources, attack patterns, and business priorities emerge
Requirements
What you’ll need- Bachelor's degree in Engineering, Cybersecurity or related field
- 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles
- Security certifications e.g. CISSP, CISM, or other relevant certifications
- Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end
- Strong understanding of security controls and how to work with engineering on implementation details
- Demonstrated track record translating technical security or threat findings into clear risk narratives
- Hands-on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them
- Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring)
- Experience handling ambiguity, driving accountability and working across multiple stakeholders
- Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives
- Experience managing and developing teams
- Experience scaling GRC processes in a high-growth or consumer tech company is a plus
- Third-party or vendor risk management experience is a plus
- Quantitative risk methodology experience (e.g., FAIR) is a plus
Benefits
Comp & perks- Offers Equity 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score