SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Strava is seeking a Senior Manager of Enterprise Security Engineering to lead the strategy and execution of the company's corporate security program. Reporting directly to the CISO, you will manage a lean, high-performing engineering team responsible for securing Strava's internal environment across a globally distributed organization of over 200 million athletes.
In this highly technical leadership role, you will own the enterprise security roadmap spanning corporate identity, endpoint security, email, corporate networking, and SaaS security. You'll define the long-term operating model for the function, deciding which capabilities Strava owns internally versus delivers through strategic partners, while balancing security rigor with business velocity.
Key responsibilities include leading and coaching a small team of enterprise security engineers, designing and building security capabilities alongside your team, architecting Strava's identity and access management platform (SSO, MFA, privileged access, Zero Trust), securing the enterprise environment through endpoint hardening and automation, and developing strategies for enterprise AI security and data protection. You'll partner closely with IT, Engineering, Legal, People, and Workplace teams to build secure-by-default experiences, and communicate priorities and risks to senior leadership.
You bring 10+ years of experience designing and operating enterprise security programs in modern cloud-first environments, with 3+ years leading security engineering teams. You have deep expertise in enterprise security capabilities at scale (MFA, SSO, OAuth, MDM, EDR, device compliance) and experience with tools like Okta, Intune, Jamf, ZTNA, Sailpoint, and GitHub. Strong communication and stakeholder management skills are essential, along with experience designing enterprise security architectures that balance security with employee productivity and developer velocity. Experience managing strategic security vendors and MSPs is required.
Bonus qualifications include expertise in DLP, CASB, SSPM, DSPM, or modern data security platforms; integrating AI governance into enterprise productivity platforms; and building self-service security capabilities and automation.
Strava operates a flexible hybrid model requiring more than half your time on-site in the San Francisco office, approximately three days per week.