At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
About the Role
F5 Distributed Cloud is seeking a Security Engineer III to advance our monitoring, detection, and incident response capabilities across the F5 SDC platform. Our platform provides a global, scalable, and secure way to deploy applications. In this role, you will design and enhance monitoring and audit solutions, improve detection quality, and strengthen our ability to respond to and investigate security incidents in a large-scale distributed environment.
Key Responsibilities
Design, implement, and continuously enhance observability solutions by leveraging AI-powered monitoring, telemetry analytics, logging, tracing, and metrics collection to improve platform reliability, security visibility, incident detection, response effectiveness, availability, and forensic readiness.
Partner with Software Architects, Platform Engineering, Security Engineering, SRE/Operations teams, Compliance stakeholders, and business leaders to define system boundaries, critical assets, security controls, and monitoring requirements across cloud-native and hybrid environments.
Integrate and optimize logging, monitoring, and security telemetry pipelines with enterprise platforms such as SIEM, SOAR, EDR/XDR, APM, cloud-native security tools, and AI-assisted analytics solutions, ensuring comprehensive data quality, coverage, and usability.
Run Security Operations Center (SOC), Incident Response, Threat Detection, Vulnerability Management, and Engineering teams to establish and maintain effective escalation paths, communication workflows, and automated response mechanisms.
Partner with development and infrastructure teams to identify, prioritize, remediate, and validate vulnerabilities, ensuring timely patch management, security hardening, and compliance with organizational security standards
Maintain SIEM deployment , upgrade as needed.
Implement Infrastructure as Code (IaC), Policy as Code, and Security as Code principles to automate deployment, governance, security controls, and compliance validation across cloud environments.
Participate in 24/7 on-call rotations and weekend support activities, as required, to ensure timely response to operational incidents, security events, and critical platform issues.
Qualifications
Be Kind
Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
4–6 years of experience in security operations, monitoring, detection engineering, or incident response.
Strong hands-on experience with logging, monitoring, and SIEM/dash boarding tools such as AWS GuardDuty, Sumo Logic, Grafana, CrowdStrike, DataDog, Splunk, Thycotic, or similar.
Working knowledge of at least one major cloud platform (e.g., AWS, Microsoft Azure, Google Cloud Platform), including native security and observability services.
Solid understanding of log handling and telemetry pipelines: collection, normalization, integration with downstream systems, and alert configuration/tuning.
Proficiency with at least one programming or scripting language (e.g., Python, Java, Shell).
Experience with CICD and vulnerability scanning with Shift left mindset.
Working knowledge of container orchestration and cloud platforms such as Kubernetes and/or OpenStack.
Relevant certifications (e.g., Security+, GSEC, CISSP) are preferred.
Familiarity with FedRAMP is a plus
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $152,200.00 - $228,400.00F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].
Skills Required
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience
- 4-6 years of experience in security operations, monitoring, detection engineering, or incident response
- Hands-on experience with logging, monitoring, and SIEM or dashboarding tools such as AWS GuardDuty, Sumo Logic, Grafana, CrowdStrike, Datadog, Splunk, or Thycotic
- Working knowledge of at least one major cloud platform, including native security and observability services
- Understanding of log handling and telemetry pipelines, including collection, normalization, downstream integration, and alert tuning
- Proficiency with at least one programming or scripting language, such as Python, Java, or Shell
- Experience with CI/CD and vulnerability scanning using a shift-left approach
- Working knowledge of Kubernetes and/or OpenStack
- Relevant certifications such as Security+, GSEC, or CISSP
- Familiarity with FedRAMP
F5 Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about F5 and has not been reviewed or approved by F5.
-
Equity Value & Accessibility — Equity grants and an employee stock purchase plan are positioned as meaningful parts of total compensation, with RSUs and a discount ESPP commonly included. Pay packages for many technical roles are considered competitive when equity is taken into account.
-
Leave & Time Off Breadth — Paid vacation that increases with tenure, sick time, paid holidays, and paid family leave are prominently featured. Additional programs like volunteer time and periodic wellness long weekends are highlighted as part of the time-off ecosystem.
-
Inclusive Benefits Coverage — Health plans include travel support for specific care (such as reproductive and gender‑affirming services) and mental health resources, alongside comprehensive medical, dental, and vision coverage. These elements are presented as part of a broad, inclusive approach to healthcare.
F5 Insights
What We Do
F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device. F5 (NASDAQ: FFIV) powers applications from development through their entire life cycle, across any multi-cloud environment, so our customers – enterprise businesses, service providers, governments, and consumer brands—can deliver differentiated, high-performing, and secure digital experiences.








