Senior Manager, Cybersecurity Strategy & Risk
Job description
About the role
Strava is on the lookout for a Senior Manager to join its Cybersecurity Strategy and Risk team. This vital position is essential for fortifying our security infrastructure to safeguard our global athlete community. You will take the lead in crafting a proactive risk assessment strategy, overseeing a dedicated team, and reporting directly to the Chief Information Security Officer.
Key facts
What you'll do
- Spearhead the enhancement of Strava's security governance and risk management programs, guiding a small team in their implementation.
- Establish a structured methodology to integrate various risk indicators into a prioritized risk overview, complete with defined acceptance thresholds and escalation protocols.
- Oversee the processes for assessing AI and third-party risks, ensuring the delivery of actionable insights that go beyond mere compliance.
- Initiate the formation of a security steering committee comprising key stakeholders to align on risk tolerance and prioritization strategies.
- Develop a comprehensive, long-term security strategy that includes a clear roadmap and investment priorities.
- Generate regular risk assessment reports tailored for executive and board-level reviews.
- Collaborate with various departments, including Engineering, Trust & Safety, Legal, and AI Enablement, to represent security in planning and risk evaluations.
- Investigate and implement AI and automation solutions to streamline risk management workflows and improve efficiency.
- Continuously adapt the risk assessment methodology in response to emerging data sources, evolving attack vectors, and shifting business priorities.
Requirements
- A Bachelor's degree in Engineering, Cybersecurity, or a related field is required.
- A minimum of 8 to 12 years of experience in security, cyber risk, or technical security assurance roles is essential.
- Relevant security certifications, such as CISSP or CISM, are preferred.
- Demonstrated success in establishing and managing security risk programs and executing cross-functional initiatives is necessary.
- Strong understanding of security controls and experience collaborating with engineering teams for implementation is required.
- Ability to distill complex technical security findings into clear and comprehensible risk narratives is crucial.
- Technical expertise in analyzing threat models, vulnerability reports, or incident data is expected.
- Experience with AI or automation tools to enhance security or risk management processes is advantageous.
- Proven ability to navigate ambiguity, promote accountability, and engage with diverse stakeholders is essential.
- Excellent communication skills, both written and verbal, with a track record of presenting risk reports to various audiences is required.
- Experience in managing and developing teams is necessary.
- Familiarity with scaling Governance, Risk, and Compliance (GRC) processes in a fast-paced tech environment is a plus.
- Knowledge of third-party or vendor risk management is beneficial.
- Experience with quantitative risk methodologies, such as FAIR, is an added advantage.
Nice to have
- Experience in the sports or fitness technology sector is a plus.
- Knowledge of regulatory compliance frameworks relevant to cybersecurity is beneficial.
- Familiarity with cloud security principles and practices is advantageous.
Skills & tools
- Proficiency in risk management frameworks and methodologies.
- Familiarity with security tools and technologies, including SIEM, vulnerability management, and incident response platforms.
- Strong analytical skills for assessing risk and security posture.
- Experience with project management tools and methodologies.
Practical notes
Strava is committed to being an equal opportunity employer. We make all hiring decisions without discrimination based on race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical or mental disabilities, medical conditions, gender identity, or any other protected status. We provide reasonable accommodations for individuals with disabilities throughout the application and interview process, as well as in performing essential job functions. Please feel free to reach out for accommodation requests.
Why Join Us?
At Strava, we are about building a community of active individuals, empowering them to stay motivated and achieve their goals. Our team is dedicated to making movement enjoyable and accessible for everyone. By joining Strava, you become part of a movement that prioritizes innovation and collaboration. We are supported by prominent investors and are expanding to meet the needs of our growing athlete community. Our inclusive culture reflects our commitment to hiring individuals from diverse backgrounds and experiences, as we believe that a varied team is a stronger team.