Senior Vulnerability Management Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
This role is on the Strava Security Team, which exists to protect Strava’s people, business, and data through integrated, proactive security practices. The team works across all security domains including product security, vulnerability management, incident response, infrastructure, network, governance, and enterprise security. The position follows a flexible hybrid model with about half the time on-site in San Francisco office (roughly three days per week). Responsibilities include owning the full lifecycle of vulnerability management—visibility, prioritization, and remediation—across a diverse tech stack; having a high-leverage impact on Strava’s risk posture by enabling timely, efficient, and measurable patching and hardening efforts; building automations and processes to eliminate manual toil and support continuous security improvement; collaborating across Engineering, IT, and Security to align technical execution with real-world risk reduction; leading efforts to identify, assess, and remediate vulnerabilities across endpoints, infrastructure, and SaaS systems; building scalable processes and automation for vulnerability ingestion, deduplication, enrichment, and routing; partnering with engineers and business teams to embed patching and configuration management into daily operations; prioritizing engineering-focused solutions over manual processes and continuously seeking ways to reduce friction. Requirements include being highly self-motivated and detail-oriented with strong ownership of outcomes; experience in vulnerability management, patch engineering, or endpoint hardening at scale in enterprise environments; ability to evaluate and act on vulnerability data using context, threat intelligence, and business impact; experience with tools like Tenable, AWS Inspector, CrowdStrike Spotlight or similar; collaboration with IT, SRE, and Engineering to implement automated patching, enforce baselines, or manage exceptions; scripting skills in Python, Bash, or similar to automate and integrate remediation workflows; pragmatic and adaptive troubleshooting skills; clear and proactive communication fostering alignment and accountability across teams in a remote, distributed company.