At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Principal Security Engineer – Incident Response & Crisis ManagementEligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)
- Serve as the Incident Commander for enterprise-wide, high-severity cyber and product security incidents from detection through post-incident review.
- Define and lead response workstreams, coordinate cross-functional teams, and maintain executive visibility throughout crisis resolution.
- On-Call Availability: Participate in and lead the rotating 24/7 on-call escalation rotation for major security incidents.
- Own and evolve F5’s global Incident Response roadmap, playbooks, severity matrix, governance standards, and executive metrics.
- Architect incident response frameworks for AI-enabled applications, LLMs, AI gateways, APIs, and model runtime data paths.
- Drive AI-assisted security operations, automated triage, and response orchestration to eliminate manual overhead.
- Author high-impact technical summaries, root-cause analyses (RCAs), customer notifications, and board-level briefing materials.
- Represent the Incident Response program in compliance audits, regulatory reviews, and key customer escalations.
- Define and track key resilience metrics (MTTD, MTTC, MTTR, blast-radius reduction) and conduct high-fidelity tabletop simulations.
- Mentor security engineers and incident responders, establishing technical standards, investigation playbooks, and operational best practices.
- Must be a U.S. Citizen (required to support F5’s FedRAMP authorization, federal compliance mandates, and government-regulated environments).
- 10+ years of progressive cybersecurity experience with deep expertise in Incident Command, SOC leadership, Threat Hunting, Product Security, or Digital Forensics in large-scale SaaS/cloud environments.
- Willingness and availability to participate in a rotating 24/7 on-call escalation schedule.
- Advanced understanding of application delivery architectures, load balancing, reverse proxies, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.
- Proven expertise investigating complex telemetry across AWS/Azure/GCP, SIEMs, EDR platforms (e.g., CrowdStrike), identity providers, and network/edge devices.
- Working knowledge of modern adversary tradecraft (MITRE ATT&CK), API attack vectors, and emerging AI/LLM threat landscapes.
- Demonstrated ability to command high-stress situations and influence senior engineering and executive stakeholders without direct authority.
- Comprehensive familiarity with industry frameworks: FedRAMP, NIST SP 800-61 / 800-53, ISO 27001, SOC 2, and PCI-DSS.
- Mature and standardize global incident command playbooks across hybrid cloud and AI workloads.
- Lead high-severity crisis investigations to swift containment while maintaining stakeholder trust and SLA adherence.
- Drive measurable improvements in MTTD/MTTR across enterprise and product environments.
- Ensure IR processes fully satisfy FedRAMP continuous monitoring and compliance requirements.
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $182,200.00 - $273,200.00F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].
Skills Required
- 10+ years of cybersecurity experience, including deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations
- Experience leading enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments
- Strong knowledge of modern attack techniques, incident management, executive communications, cross-functional crisis coordination, workstream management, and stakeholder orchestration
- Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security
- Experience with CrowdStrike, model invocation logs, identity and access logs, API gateway and application logs, agent and tool execution logs, data access and retrieval logs, cloud and infrastructure logs, security telemetry, EDR events, SIEM alerts, WAF or WAAP events, DLP alerts, vulnerability signals, threat intelligence matches, and network or edge logs
- Experience influencing strategy across large organizations without direct authority through partnership
- Familiarity with NIST, ISO, SOC, PCI, and GDPR requirements
- Ability to support global incident response operations from the United States across EMEA, LATAM, and Americas time zones
- FedRAMP eligibility
F5 Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about F5 and has not been reviewed or approved by F5.
-
Equity Value & Accessibility — Equity grants and an employee stock purchase plan are positioned as meaningful parts of total compensation, with RSUs and a discount ESPP commonly included. Pay packages for many technical roles are considered competitive when equity is taken into account.
-
Leave & Time Off Breadth — Paid vacation that increases with tenure, sick time, paid holidays, and paid family leave are prominently featured. Additional programs like volunteer time and periodic wellness long weekends are highlighted as part of the time-off ecosystem.
-
Inclusive Benefits Coverage — Health plans include travel support for specific care (such as reproductive and gender‑affirming services) and mental health resources, alongside comprehensive medical, dental, and vision coverage. These elements are presented as part of a broad, inclusive approach to healthcare.
F5 Insights
What We Do
F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device. F5 (NASDAQ: FFIV) powers applications from development through their entire life cycle, across any multi-cloud environment, so our customers – enterprise businesses, service providers, governments, and consumer brands—can deliver differentiated, high-performing, and secure digital experiences.








