At a Glance
- Tasks: Protect Strava's platform by ensuring secure applications and infrastructure for millions of athletes.
- Company: Join Strava, the app that motivates active people worldwide.
- Benefits: Competitive salary, inclusive workplace, and opportunities for growth.
- Why this job: Make a real impact on security while collaborating with passionate teams.
- Qualifications: Experience in application security, cloud environments, and vulnerability management.
- Other info: Flexible hybrid model with a dynamic team culture.
The predicted salary is between 93500 - 110000 £ per year.
About Strava
Strava is the app for active people. With over 180 million athletes in more than 185 countries, it’s more than tracking workouts—it’s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Strava’s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey with Strava today. Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward.
About This Role
This role is on the Strava Security Team, which exists to protect Strava’s people, business, and data through integrated, proactive security practices. We work across all security domains, including, but not limited to, product security, vulnerability management, incident response, infrastructure, network, governance, and enterprise security. We follow a flexible hybrid model that translates to more than half your time on-site in our London office—three days per week.
What You’ll Do:
- Are passionate about protecting a platform that supports millions of athletes by ensuring Strava’s applications and infrastructure are secure, resilient, and compliant across regions.
- Enjoy working closely with engineering, infrastructure, and security teams to design and implement secure architectures and development practices.
- Will have a high-leverage impact by shaping how Strava manages application and infrastructure risks in the EU, ensuring speed, accuracy, and consistency in remediation and governance.
- Are excited to build automated workflows that identify vulnerabilities early, enforce secure configurations, and strengthen our CI/CD and cloud security controls.
- Will collaborate across Security, Engineering, Legal, and Compliance to ensure that systems, processes, and data handling meet EU regulatory standards and Strava’s global security expectations.
You Will Be Successful Here By:
- Being highly self-motivated and detail-oriented, with a strong sense of ownership for Strava’s regional application and infrastructure security posture.
- Serving as the primary security point of contact for Strava Group in the EU, bridging global strategy with local implementation and compliance.
- Driving secure-by-design practices across engineering teams, including threat modeling, architecture reviews, and vulnerability management.
- Partnering with Engineering and Infrastructure teams to embed automated security checks into CI/CD pipelines and infrastructure-as-code deployments.
- Coordinating regional incident response, vulnerability triage, and remediation validation in partnership with the global security team.
What You’ll Bring to the Team:
- Bring hands-on experience in application and infrastructure security, including code review, threat modeling, and securing cloud-native environments (AWS preferred).
- Have designed or implemented automated security controls in CI/CD pipelines using tools like Semgrep, Tenable, GHAS, Snyk, or custom scripting.
- Understand how to secure containerized and distributed environments, including Kubernetes, IAM, and network segmentation.
- Are comfortable managing vulnerability management programs end-to-end—from detection and prioritization through engineering remediation.
- Have familiarity with EU security and privacy frameworks (GDPR, NIS2) and know how to apply them pragmatically to cloud infrastructure and data systems.
- Are collaborative and pragmatic—able to influence engineering teams through partnership, technical credibility, and clear communication.
- Communicate proactively and effectively across technical and non-technical stakeholders, ensuring alignment between EU operations and global security strategy.
Why Join Us?
Movement brings us together. At Strava, we’re building the world’s largest community of active people, helping them stay motivated and achieve their goals. Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether you’re shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact. When you join Strava, you’re not just joining a company—you’re joining a movement. If you’re ready to bring your energy, ideas, and drive, let’s build something incredible together. Strava builds software that makes the best part of our athletes’ days even better. Just as we’re deeply committed to unlocking their potential, we’re dedicated to providing a world-class, inclusive workplace where our employees can grow and thrive, too.
We’re backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we’re expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together. Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
Compensation Range: £93.5K - £110K
Senior Engineer, Application and Security Infrastructure employer: Strava
Contact Detail:
Strava Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Engineer, Application and Security Infrastructure
✨Tip Number 1
Network like a pro! Reach out to current or former Strava employees on LinkedIn. Ask them about their experiences and any tips they might have for landing a role at Strava. Personal connections can make a huge difference!
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills. Since this role involves application and infrastructure security, be ready to discuss your hands-on experience with tools like Semgrep or Snyk. Show us you know your stuff!
✨Tip Number 3
Don’t just talk about your past roles; highlight how you can contribute to Strava’s mission. Share specific examples of how you've driven secure practices in previous jobs and how that aligns with our goals at Strava.
✨Tip Number 4
Finally, apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of the Strava community. Let’s get you on board!
We think you need these skills to ace Senior Engineer, Application and Security Infrastructure
Some tips for your application 🫡
Show Your Passion: When you're writing your application, let your enthusiasm for security and protecting users shine through. We want to see how much you care about keeping Strava's platform safe for millions of athletes!
Tailor Your Experience: Make sure to highlight your hands-on experience in application and infrastructure security. We love seeing specific examples of how you've tackled challenges like code reviews or vulnerability management in your previous roles.
Be Clear and Concise: Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and make it easy for us to understand your skills and experiences related to the role.
Apply Through Our Website: Don't forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for this exciting opportunity with Strava.
How to prepare for a job interview at Strava
✨Know Your Stuff
Make sure you brush up on your application and infrastructure security knowledge. Familiarise yourself with the tools mentioned in the job description, like Semgrep and Snyk, and be ready to discuss how you've used them in past projects.
✨Show Your Passion for Security
Strava is all about protecting its community of athletes. Be prepared to share examples of how you've ensured security in previous roles, especially in cloud-native environments. Highlight your enthusiasm for building secure architectures and your commitment to proactive security practices.
✨Collaborate Like a Pro
This role requires working closely with various teams. Think of examples where you've successfully collaborated with engineering or compliance teams. Emphasise your communication skills and how you can bridge the gap between technical and non-technical stakeholders.
✨Understand the Regulations
Since this position involves EU regulatory standards, make sure you have a solid grasp of GDPR and NIS2. Be ready to discuss how you've applied these frameworks in your work, and show that you can navigate the complexities of compliance while maintaining security.