This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role is on the Strava Security Team, which exists to protect Strava’s people, business, and data through integrated, proactive security practices. We work across all security domains, including, but not limited to, product security, vulnerability management, incident response, infrastructure, network, governance, and enterprise security.
Job Responsibility:
Protect a platform that supports millions of athletes by ensuring Strava’s applications and infrastructure are secure, resilient, and compliant across regions
Work closely with engineering, infrastructure, and security teams to design and implement secure architectures and development practices
Shape how Strava manages application and infrastructure risks in the EU, ensuring speed, accuracy, and consistency in remediation and governance
Build automated workflows that identify vulnerabilities early, enforce secure configurations, and strengthen our CI/CD and cloud security controls
Collaborate across Security, Engineering, Legal, and Compliance to ensure that systems, processes, and data handling meet EU regulatory standards and Strava’s global security expectations
Serve as the primary security point of contact for Strava Group in the EU, bridging global strategy with local implementation and compliance
Drive secure-by-design practices across engineering teams, including threat modeling, architecture reviews, and vulnerability management
Partner with Engineering and Infrastructure teams to embed automated security checks into CI/CD pipelines and infrastructure-as-code deployments
Coordinate regional incident response, vulnerability triage, and remediation validation in partnership with the global security team
Requirements:
Hands-on experience in application and infrastructure security, including code review, threat modeling, and securing cloud-native environments (AWS preferred)
Designed or implemented automated security controls in CI/CD pipelines using tools like Semgrep, Tenable, GHAS, Snyk, or custom scripting
Understand how to secure containerized and distributed environments, including Kubernetes, IAM, and network segmentation
Comfortable managing vulnerability management programs end-to-end — from detection and prioritization through engineering remediation
Familiarity with EU security and privacy frameworks (GDPR, NIS2) and know how to apply them pragmatically to cloud infrastructure and data systems
Collaborative and pragmatic — able to influence engineering teams through partnership, technical credibility, and clear communication
Communicate proactively and effectively across technical and non-technical stakeholders, ensuring alignment between EU operations and global security strategy