Senior Director, Engineering, Cybersecurity

2 months ago


San Francisco, California, United States Strava Full time

Senior Director of Cybersecurity About This Role

Strava is the leading digital community for active people with more than 125 million athletes, in more than 190 countries. The platform offers a comprehensive view of your active lifestyle, no matter where you live, which sport you love and/or what device you use. Everyone belongs on Strava when they are pursuing an active life.

Strava is seeking a highly experienced Senior Director of Cybersecurity to lead and enhance our cybersecurity strategy and operations. This role is essential in ensuring the protection of our digital assets, networks, and data. The ideal candidate will possess deep technical expertise, strategic vision, and exceptional leadership skills to drive our cybersecurity initiatives and implement a robust defense-in-depth strategy.

As the Senior Director of Cybersecurity, you will play a critical role in protecting our digital assets, networks, and data. Your deep technical expertise, strategic vision, and exceptional leadership skills will drive our cybersecurity initiatives and implement a robust defense-in-depth strategy. This is your chance to make a significant impact in a world-class organization. This is a Hybrid role based in our San Francisco office.

For more information on compensation and benefits, please click here.

You're excited about this opportunity because you will:

  • Develop and implement a comprehensive cybersecurity strategy aligned with the organization's goals and objectives.
  • Offer guidance and vision to the organization, ensuring the adoption of widely accepted approaches and industry norms, including defense-in-depth principles.
  • Stay abreast of emerging cybersecurity threats, trends, and technologies to proactively address potential risks.
  • Identify, assess, and prioritize cybersecurity risks across the organization.
  • Develop and implement policies, procedures, and protocols to mitigate identified risks through a defense-in-depth approach.
  • Ensure compliance with relevant laws, regulations, and industry standards (e.g., GDPR, CCPA, ISO 27001, NIST).
  • Be responsible for the development and execution of incident response programs, ensuring timely and effective resolution of cybersecurity incidents.
  • Lead post-incident analysis to identify root causes and implement corrective actions.
  • Collaborate with colleagues and external partners to ensure effective incident response activities.
  • Oversee the management and maintenance of security tools and technologies, including firewalls, intrusion detection/prevention systems, and SIEM solutions.
  • Monitor and analyze security alerts and events, ensuring appropriate response and reporting.
  • Perform regular security assessments, vulnerability scans, and penetration testing to identify and address security weaknesses, using defense-in-depth methodologies.
  • Ensure application security by integrating security practices into the software development lifecycle, conducting code reviews, and implementing secure coding standards.
  • Lead and mentor a team of software engineering and cybersecurity professionals, encouraging a culture of continuous learning and improvement.
  • Attract, nurture, and develop top cybersecurity talent to cultivate a team that consistently displays exceptional performance.
  • Develop and implement educational programs to enhance employee understanding ofcybersecurity practices and policies.
  • Collaborate with teams from various departments, such as IT and legal, to ensurecybersecurity initiatives are aligned.
  • Communicate cybersecurity risks, strategies, and progress to executive leadership and the board of directors.
  • Serve as a key contact for external partners, auditors, and regulators regarding cybersecurity matters.

We're excited about you because:

  • You have your Bachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • Have a minimum of 15 years of experience in cybersecurity for a highly regulated industry (e.g., finance, healthcare, energy), with at least 5 years in a leadership role.
  • Have a proven track record of developing and implementing successful cybersecurity strategies, including defense-in-depth.
  • Have a strong understanding of cybersecurity frameworks, standards, and effective approaches.
  • Have extensive knowledge of threat intelligence, risk management, and incident response.
  • Have excellent leadership, communication, and interpersonal skills.
  • Have relevant certifications such as CISSP, CISM, CEH, or equivalent
  • Have solid experience in project management and familiarity with implementing cybersecurity programs.

About Strava

Strava is Swedish for "strive," which epitomizes who we are and what we do. We're a passionate and committed team, unified by our mission to connect athletes to what motivates them and help them find their personal best. With billions of activity uploads from all over the world, we have a humbling and adventurous vision: to be the record of the world's athletic activities and the technology that makes every effort count. Strava builds software that makes the best part of our athletes' days even better. Just as we're deeply committed to unlocking their potential, we're dedicated to providing a world-class, inclusive workplace where our employees can grow and thrive, too. We're backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we're expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage diverse teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together. Despite challenges in the world around us, we are continuing to grow camaraderie and positivity within our culture, and we are unified in our commitment to becoming an antiracist company. We are differentiated by our truly people-first approach, our compassionate leadership, and our belief that we can bring joy and inspiration to athletes' lives — now more than ever. All to say, it's a great time to join Strava Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard

to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in

the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

California Consumer Protection Act Applicant Notice



  • San Diego, California, United States Oneida Technical Solutions LLC Full time

    Oneida Technical Solutions, LLC (OTS) has been a trusted partner since its inception in 2014, delivering cutting-edge information technology and cybersecurity solutions across a multitude of sectors, including defense, healthcare, education, and law enforcement. Our expertise in cyber capabilities has established us as reliable collaborators for IT...


  • San Diego, California, United States The MITRE Corporation Full time

    Join MITRE Corporation, a unique not-for-profit organization dedicated to addressing our nation's most pressing challenges while ensuring the well-being of our workforce. At MITRE, we operate R&D centers that deliver impactful solutions across various sectors, including cybersecurity, healthcare, aviation, defense, and enterprise transformation. We pride...


  • San Diego, California, United States Northrop Grumman Full time

    Requisition ID: RCategory: Information TechnologyLocation: San Diego, California, United States of AmericaClearance Type: Top SecretTelecommute: No - Teleworking not available for this positionShift: 1st Shift (United States of America)Travel Required: Yes, 25% of the TimeRelocation Assistance: Relocation assistance may be availablePositions Available: 1At...


  • San Diego, California, United States Northrop Grumman Full time

    Requisition ID: RCategory: Information Technology Location: San Diego, California, United States of America Clearance Type: Top Secret Telecommute: No - Teleworking not available for this position Shift: 1st Shift (United States of America) Travel Required: Yes, 25% of the Time Relocation Assistance: Relocation assistance may be available Positions...


  • San Diego, California, United States Northrop Grumman Full time

    Requisition ID: RCategory: Information Technology Location: San Diego, California, United States of America Clearance Type: Top Secret Telecommute: No - Teleworking not available for this position Shift: 1st Shift (United States of America) Travel Required: Yes, 25% of the Time Relocation Assistance: Relocation assistance may be available Positions...


  • San Diego, California, United States Tactical Engineering Analysis Full time

    OverviewTactical Engineering & Analysis is in search of a skilled Cybersecurity Systems Engineer to contribute to the Navy Enterprise Architecture (EA) and Model Based Systems Engineering (MBSE) initiatives. The ideal candidate will engage throughout the program development lifecycle of platforms, enclaves, and systems, adhering to the Defense in Depth...


  • San Francisco, California, United States Benchling Full time

    In the rapidly evolving field of biotechnology, the integration of advanced technology is crucial for innovation. Benchling is at the forefront of this transformation, empowering leading biotech firms with our R&D Cloud to enhance product development and expedite market readiness. POSITION SUMMARYThe Security division at Benchling plays a pivotal role in our...


  • San Francisco, California, United States Motion Recruitment Full time

    Position: Lead Cybersecurity Risk EngineerLocation: RemoteType: ContractCompensation: $118/hr - $120/hrOverview:Join a dynamic team at Motion Recruitment as a Lead Cybersecurity Risk Engineer. This role is designed for professionals eager to tackle complex cybersecurity challenges in a flexible remote environment.Key Responsibilities:- Evaluate and document...


  • San Francisco, California, United States Cresta Full time

    Join Our Team as a Cybersecurity Software EngineerAre you passionate about shaping the future of technology through security? At Cresta, we are dedicated to enhancing the productivity of knowledge workers by leveraging advanced AI solutions. Our mission is to empower the workforce, ensuring they are more effective and efficient without replacing them. With...


  • San Francisco, California, United States Wells Fargo Full time

    Overview:Wells Fargo is in search of a Senior Cybersecurity Incident Response Engineer with a robust background in incident management, network forensics, and proactive threat detection. The ideal candidate will possess a comprehensive understanding of endpoint and network security measures, alongside a foundation in offensive security to facilitate an...


  • San Diego, California, United States Booz Allen Hamilton Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Engineer to join our team at Booz Allen Hamilton. As a Cybersecurity Engineer, you will play a critical role in designing and implementing secure cybersecurity solutions for our clients.Key ResponsibilitiesDesign and implement secure cybersecurity solutions for clientsConduct risk assessments and...


  • San Francisco, California, United States GoodRx Full time

    GoodRx stands as a leading platform in the healthcare sector, dedicated to providing accessible health information and discounts to millions of individuals each month. Since its inception, GoodRx has facilitated savings of over $60 billion for consumers, offering prescription discounts accepted at more than 70,000 pharmacies nationwide, alongside telehealth...


  • San Jose, California, United States Archer Full time

    Archer is a pioneering aerospace organization headquartered in San Jose, California, dedicated to developing an all-electric vertical takeoff and landing aircraft aimed at enhancing sustainable air mobility. Our mission is to design, manufacture, and operate an innovative aircraft capable of transporting four passengers while minimizing noise pollution.We...


  • San Diego, California, United States MedCrypt Full time

    Position Overview:The Junior Cybersecurity Engineer will play a crucial role in enhancing the safety and security of medical devices through effective cybersecurity measures. This position involves collaborating with medical device manufacturers to address a variety of technology, process, and regulatory challenges, ensuring robust protection against...


  • San Jose, California, United States Bayforce Full time

    Important Notice: No third parties or vendors. Direct applicants only.Are you a seasoned Cybersecurity Engineer with a strong commitment to advancing threat detection and security oversight? Bayforce is seeking a Lead Cybersecurity Engineer to become part of our dynamic team on a contract-to-hire basis. This position is primarily remote, offering flexibility...


  • San Diego, California, United States Mitchell1 Full time

    Join a renowned SaaS organization that stands as a pillar in the automotive repair sector, boasting over a century of stability and expertise.At Mitchell 1, a division of Snap-on Inc., we have been at the forefront of delivering innovative information solutions that streamline daily operations for automotive professionals. Our products have continually...


  • San Francisco, California, United States Circle Full time

    Circle is a pioneering financial technology organization positioned at the forefront of the evolving digital currency landscape, where value can seamlessly traverse borders, almost instantaneously and at a lower cost compared to traditional settlement frameworks. This revolutionary new layer of the internet unlocks extraordinary opportunities for...


  • San Diego, California, United States SOLUTE Careers Full time

    SOLUTE Careers is in search of a Cybersecurity Systems Engineer to engage in cybersecurity engineering and configuration management tasks aimed at upholding secure IT platform baselines along with the lab environment and IT infrastructure.The ideal candidate will possess expertise in submitting and maintaining security packages for information systems, with...


  • San Francisco, California, United States CMT Engineering Laboratories Full time

    CMT Engineering Laboratories is seeking a Senior Geotechnical Engineer to take on a pivotal role within our Geotechnical division.Position Overview:Conduct comprehensive geotechnical assessments and analyses to evaluate subsurface and site conditions.Design and implement effective geotechnical exploration initiatives.Carry out field and laboratory...


  • San Francisco, California, United States Abnormal Security Full time

    Position OverviewAbnormal Security is in search of a Senior Software Engineer to spearhead significant projects within our core Research and Development sectors. Our team is responsible for creating reusable components such as Account Management, Notifications, and Feature Flags, which empower other teams to swiftly develop their applications.At Abnormal,...