Back to jobs
New

Senior Infrastructure Security Engineer

Denver, CO

About This Role

Strava is the app for active people. With over 150 million athletes in more than 185 countries, Strava is where connection, motivation, and personal bests thrive. No matter your activity, gear, or goals, we help you find your crew, crush your milestones, and keep moving forward. Start your journey with Strava today.

Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward.

At Strava, we protect the infrastructure that powers millions of athletes' journeys. As a Senior Infrastructure Security Engineer on the Foundation Team, you'll be the guardian of our platform—building security into every layer of our infrastructure while enabling teams to move fast and innovate fearlessly. You'll balance security excellence with developer velocity, ensuring our platform remains both impenetrable and performant.

The Foundation Team is the backbone of Strava's engineering organization, providing the secure infrastructure, tools, and frameworks that power every feature our athletes love. In this role, you'll embed security into the foundation of our platform—from hardening our Kubernetes clusters and cloud infrastructure to building automated security guardrails that make the secure path the easy path for developers.

By architecting security solutions that scale, you'll protect the data of 150+ million athletes while enabling product teams to ship features with confidence. You'll be both a builder and a defender—creating tools that empower engineers, responding to emerging threats, and partnering with teams across Strava to weave security into our engineering DNA.

We follow a flexible hybrid model that translates to more than half your time on-site in our Denver office — three days per week.

What You'll Do:

  • Design and implement security controls across Strava's cloud infrastructure, including network segmentation, IAM policies, and data protection mechanisms
  • Lead security initiatives for the Foundation Team, conducting threat modeling, security reviews, and risk assessments for infrastructure changes
  • Build and maintain security automation tools that enable engineering teams to deploy securely by default
  • Partner with engineering teams to integrate security best practices into CI/CD pipelines and infrastructure-as-code workflows
  • Respond to security incidents, perform root cause analysis, and implement preventive measures to strengthen our security posture
  • Develop and maintain security monitoring, alerting, and response systems using SIEM and cloud-native security tools
  • Drive compliance initiatives, ensuring infrastructure meets SOC2, GDPR, and other regulatory requirements
  • Collaborate with the security team to implement zero-trust architecture and strengthen our defense-in-depth strategy
  • Participate in on-call rotations and mentor other engineers on security best practices

What You'll Bring to the Team:

  • 5+ years of infrastructure engineering experience with at least 3 years focused on security engineering or DevSecOps
  • Deep expertise in AWS security services (IAM, GuardDuty, Security Hub, WAF, Shield) and cloud security best practices
  • Strong background in Kubernetes security, including RBAC, network policies, admission controllers, and container security
  • Proven experience implementing infrastructure-as-code security patterns using Terraform, with expertise in policy-as-code tools
  • Track record of building security automation and tooling that scales across large engineering organizations
  • Excellence in cross-team collaboration, with the ability to influence security practices without direct authority
  • Strong incident response experience and ability to remain calm under pressure during security events

Some of our Technical Expectations:

We're not looking for 100% coverage; if you match any of these qualifications, we'd love to hear from you:

  • Experience with security scanning tools (Trivy, Snyk, SonarQube) and vulnerability management workflows
  • Experience in secrets management solutions (HashiCorp Vault, AWS Secrets Manager) and PKI infrastructure
  • Experience with SIEM platforms (Splunk, Datadog Security, Elastic Security) and security orchestration
  • Strong knowledge of network security including VPC design, service mesh (Istio), and zero-trust networking
  • Familiarity with compliance frameworks and experience with security audits (SOC2, ISO 27001, PCI-DSS)

Compensation Overview:

At Strava, we know our employees are the most important ingredient to our success, and our compensation and total rewards programs reflect that. We take a market-based approach to pay, and pay may vary depending on the department and your location. Salary ranges are categorized into one of three zones based on a cost of labor index for that geographic area. We will determine the candidate’s starting pay based on job-related skills, experience, qualifications, work location, and market conditions. We may modify these ranges in the future. For more information, please contact your talent partner.

Compensation: $150,000 - $167,000. This range reflects base compensation only and does not include equity or benefits. Your recruiter can share more details about the full compensation package during the hiring process.

For more information on benefits, please click here.

Why Join Us?

Movement brings us together. At Strava, we’re building the world’s largest community of active people, helping them stay motivated and achieve their goals.

Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether you’re shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact.

When you join Strava, you’re not just joining a company—you’re joining a movement. If you’re ready to bring your energy, ideas, and drive, let’s build something incredible together.

Strava builds software that makes the best part of our athletes’ days even better. Just as we’re deeply committed to unlocking their potential, we’re dedicated to providing a world-class, inclusive workplace where our employees can grow and thrive, too. We’re backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we’re expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together.

Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

California Consumer Protection Act Applicant Notice

Create a Job Alert

Interested in building your career at Strava? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Strava’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.