Job Description
📋 Description Own and advance Strava's security governance, strategy and risk programs. Build a repeatable process turning risk signals into a prioritized risk view. Lead AI and third-party risk management; deliver meaningful insights. Establish a security steering committee for risk alignment and prioritization. Define a multi-year security strategy, roadmap and investments. Deliver exec- and board-ready risk reporting. 🎯 Requirements Bachelor's degree in Engineering, Cybersecurity or related field. 8-12 years in security, cyber risk, or related technical risk roles. Security certifications such as CISSP, CISM, or similar. Proven success standing up and managing security risk programs end to end. Strong understanding of security controls and working with engineers on implementation. Proven ability translating technical findings into clear risk narratives. 🎁 Benefits Hybrid work model with about 3 days on-site in San Francisco. Equity compensation offered. Global, inclusive culture with growth opportunities. Leadership development and cross-functional collaboration.