Senior Engineer, Application and Security Infrastructure
2 weeks ago
Strava is the app for active people. With over 150 million athletes in more than 185 countries, it's more than tracking workouts—it's where connection, motivation, and personal bests thrive. No matter your activity, gear, or goals, Strava's got you covered. Find your crew, crush your milestones, and keep moving forward. Start your journey with Strava today.
This role is on the Strava Security Team, which exists to protect Strava's people, business, and data through integrated, proactive security practices.
We work across all security domains, including, but not limited to, product security, vulnerability management, incident response, infrastructure, network, governance, and enterprise security.
We follow a flexible hybrid model that translates to more than half your time on-site in our London office— three days per week.
What You'll Do:- Are passionate about protecting a platform that supports millions of athletes by ensuring Strava's applications and infrastructure are secure, resilient, and compliant across regions.
- Enjoy working closely with engineering, infrastructure, and security teams to design and implement secure architectures and development practices.
- Will have a high-leverage impact by shaping how Strava manages application and infrastructure risks in the EU, ensuring speed, accuracy, and consistency in remediation and governance.
- Are excited to build automated workflows that identify vulnerabilities early, enforce secure configurations, and strengthen our CI/CD and cloud security controls.
- Will collaborate across Security, Engineering, Legal, and Compliance to ensure that systems, processes, and data handling meet EU regulatory standards and Strava's global security expectations.
- Being highly self-motivated and detail-oriented, with a strong sense of ownership for Strava's regional application and infrastructure security posture.
- Serving as the primary security point of contact for Strava Group in the EU, bridging global strategy with local implementation and compliance.
- Driving secure-by-design practices across engineering teams, including threat modeling, architecture reviews, and vulnerability management.
- Partnering with Engineering and Infrastructure teams to embed automated security checks into CI/CD pipelines and infrastructure-as-code deployments.
- Coordinating regional incident response, vulnerability triage, and remediation validation in partnership with the global security team.
- Bring hands-on experience in application and infrastructure security, including code review, threat modeling, and securing cloud-native environments (AWS preferred).
- Have designed or implemented automated security controls in CI/CD pipelines using tools like Semgrep, Tenable, GHAS, Snyk, or custom scripting.
- Understand how to secure containerized and distributed environments, including Kubernetes, IAM, and network segmentation.
- Are comfortable managing vulnerability management programs end-to-end — from detection and prioritization through engineering remediation.
- Have familiarity with EU security and privacy frameworks (GDPR, NIS2) and know how to apply them pragmatically to cloud infrastructure and data systems.
- Are collaborative and pragmatic — able to influence engineering teams through partnership, technical credibility, and clear communication.
- Communicate proactively and effectively across technical and non-technical stakeholders, ensuring alignment between EU operations and global security strategy.
At Strava, we know our employees are the most important ingredient to our success, and our compensation and total rewards programs reflect that. We take a market-based approach to pay, and pay may vary depending on the department and your location. Salary ranges are categorized into one of three zones based on a cost of labor index for that geographic area. We will determine the candidate's starting pay based on job-related skills, experience, qualifications, work location, and market conditions. We may modify these ranges in the future. For more information, please contact your talent partner.
Compensation: For roles that are based at our offices in London: £93,500 - £110,000. This range reflects base compensation only and does not include equity or benefits. Your recruiter can share more details about the full compensation package during the hiring process.
For more information on benefits, please click here.
Why Join Us?Movement brings us together. At Strava, we're building the world's largest community of active people, helping them stay motivated and achieve their goals.
Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether you're shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact.
When you join Strava, you're not just joining a company—you're joining a movement. If you're ready to bring your energy, ideas, and drive, let's build something incredible together.
Strava builds software that makes the best part of our athletes' days even better. Just as we're deeply committed to unlocking their potential, we're dedicated to providing a world-class, inclusive workplace where our employees can grow and thrive, too. We're backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and we're expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together.
Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
California Consumer Protection Act Applicant Notice
-
London, Greater London, United Kingdom Strava Full time £93,500 - £110,000 per yearAbout This RoleStrava is the app for active people. With over 150 million athletes in more than 185 countries, it's more than tracking workouts—it's where connection, motivation, and personal bests thrive. No matter your activity, gear, or goals, Strava's got you covered. Find your crew, crush your milestones, and keep moving forward. Start your journey...
-
Senior Application Security Engineer
7 days ago
London, Greater London, United Kingdom Fortinet Full time £60,000 - £120,000 per yearDescriptionSenior Application Security EngineerFortinet is looking for a Sr. Application Security Engineer to join the Corporate Information Security team. This is a highly technical role, with responsibilities conducting security reviews on various Fortinet applications, providing security education to our engineers and handling externally reported...
-
Senior GCP Infrastructure Engineer
2 weeks ago
London, Greater London, United Kingdom Stott and May Full time £60,000 - £120,000 per yearJob DescriptionSenior GCP Infrastructure EngineerStart: ASAPLocation: 2 days per week in any of: London, Bristol, Leeds, ManchesterPay: INSIDE IR35, paying up to £515 per dayWe're seeking an experienced Senior GCP Infra & DevOps Engineer to join a high-impact Public Cloud Platform team within a leading financial services organisation.Key...
-
Application Security Engineer
7 days ago
London, Greater London, United Kingdom Ignite Digital Full time £60,000 - £120,000 per yearApplication Security Engineer / AppSec Engineer / Cloud Security Engineer Hybrid London (2 days in-office) | Competitive Salary + Bonus + BenefitsAre you passionate about securing cutting-edge digital platforms in a fast-moving fintech environment? We're seeking an experienced Application Security Engineer to play a vital role in safeguarding our cloud...
-
Senior IT Infrastructure Engineer
23 hours ago
London, Greater London, United Kingdom Rutherford Briant Recruitment Full time £45,000 - £60,000 per yearHave you led complex Azure or infrastructure projects? Do you enjoy taking technical ownership while guiding others?Our client is seeking a Senior IT Infrastructure Engineer who can drive Azure deployments, lead infrastructure transformation, and support a high-performing operations team. This is an international professional services organisation recognised...
-
Infrastructure Security Monitoring Engineer
2 weeks ago
London, Greater London, United Kingdom Meta Full time £80,000 - £120,000 per yearMeta's Infrastructure Security Monitoring (ISM) team is seeking an experienced engineer to help secure the infrastructure that connects over a billion users. You will be responsible for building, implementing and operationally supporting detections throughout our infrastructure. We are looking for candidates who are passionate about security and innovation,...
-
Senior Infrastructure Engineer
2 weeks ago
London, Greater London, United Kingdom 68a5487c-0533-42c0-99e2-517f6f4a08fc Full time £40,000 - £80,000 per yearRole: Senior Infrastructure EngineerSalary: £53, gross) per annum inclusive of London Weighting, with a fixed sum allowance of £2,003.Location: Head Office- LondonDuration: PermanentThe Labour Party is looking to recruit a Senior Infrastructure Engineer. The post-holder will be responsible for the management and support of the Party's IT systems, with a...
-
Senior Application Security Engineer
3 days ago
London, Greater London, United Kingdom LSEG Full time £80,000 - £120,000 per yearABOUT US:LSEG (London Stock Exchange Group) is more than a diversified global financial markets infrastructure and data business. We are dedicated, open-access partners with a dedication to excellence in delivering the services our customers expect from us. With extensive experience, deep knowledge and worldwide presence across financial markets, we enable...
-
Infrastructure Security Monitoring Engineer
2 weeks ago
London, Greater London, United Kingdom Meta Full time £60,000 - £120,000 per yearMeta's Infrastructure Security Monitoring (ISM) team is seeking an experienced engineer to help secure the infrastructure that connects over a billion users. You will be responsible for building, implementing and operationally supporting detections throughout our infrastructure. We are looking for candidates who are passionate about security and innovation,...
-
Senior IT Infrastructure Engineer
7 days ago
London, Greater London, United Kingdom Murphy Full time £40,000 - £80,000 per yearMurphy is recruiting for a Senior IT Infrastructure Engineer to work within the IT team in either Stone Cross or LeedsOperating in the United Kingdom, Ireland, Canada and the USA, Murphy provides better engineered solutions to infrastructure sectors including transportation, water, power and natural resources. So that our teams out on projects can run...