Strava runs a platform where over 180 million athletes across 185+ countries log, analyze, and share physical activities - more than 12 billion to date. The attack surface is substantial: a social network layered onto a fitness tracker means you're defending a system that ingests GPS telemetry, biometric data, personal profiles, and location-based activity streams at global scale. The threat model spans data exfiltration of sensitive athlete location patterns, API abuse across integrations pulling from over 50 activity types, and the trust and safety challenges inherent in a platform that functions as both a fitness tool and a social network.
Security work here touches mobile and web application security for a product serving nearly one million hosted clubs and a business-facing layer (Strava for Business) that connects brands with the athletic community. That means protecting OAuth flows, securing map and segment data, hardening API endpoints, and thinking carefully about how aggregated location data could be weaponized - Strava's heat maps have drawn public scrutiny before for revealing sensitive infrastructure patterns. The platform's scale demands engineers who can reason about privacy-by-design in a system where sharing is the default behavior.
Strava's mission centers on motivating active lives by connecting athletes to what inspires them. For a security team, the practical translation is: enable that openness without becoming the next cautionary tale about oversharing. If you want to work on real-world privacy problems where the data is inherently geographic, temporal, and personal, this is a concrete place to do it.






