Security Engineer - Incident response

Posted 23 Days Ago
Be an Early Applicant
2 Locations
In-Office
132K-198K Annually
Senior level
Cloud • Information Technology • Security • Software
The Role
Support high-severity cyber and product security incident response across cloud, corporate, application, and customer-facing environments. Coordinate incident workstreams, communications, stakeholder engagement, containment, recovery, documentation, and post-incident reviews. Develop AI security incident response capabilities, support threat hunting and investigations, improve detection and response metrics, conduct tabletop exercises, and advance automation and resilience across hybrid multicloud environments.
Summary Generated by Built In

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. 
 

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Security Engineer III – Incident Response

Organization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience
Eligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)

Position Summary

We are seeking a Security Engineer III to join the Office of the CISO as a core member of our Global Incident Response team. In this role, you will lead hands-on triage, containment, and resolution of complex security incidents across corporate infrastructure, multicloud environments, core products (BIG-IP, NGINX, Distributed Cloud, WAAP), and emerging AI-enabled services.

You will serve as an incident responder and workstream lead during active cyber events, partnering across engineering, SRE, cloud operations, legal, and executive leadership from initial triage through post-incident remediation.

Key Responsibilities

Incident Triage & Response Execution

  • Lead end-to-end response for high-severity cyber and product security incidents (detection, containment, eradication, and recovery).

  • Drive incident command workflows, track mitigation workstreams, document forensic findings, and deliver clear technical updates to stakeholders.
  • On-Call Availability: Participate in a scheduled, rotating 24/7 on-call roster to ensure continuous incident response readiness.

AI & Cloud Security Response

  • Develop and execute response procedures for AI-enabled applications, large language model (LLM) workflows, AI gateways, and API data paths.

  • Implement automated triage, observability tooling, and detection rules to rapidly identify and isolate novel threats.

Cross-Functional Crisis Coordination

  • Collaborate with Product Engineering, SRE, Legal, Privacy, Communications, and Support teams during active investigations.

  • Author actionable post-incident reports, executive briefings, and customer notification materials.

Operational Resilience & Continuous Improvement

  • Facilitate post-incident reviews (PIRs/RCAs) to identify systemic risks and drive preventative engineering fixes.

  • Conduct tabletop exercises, purple team simulations, and playbook updates to continuously improve MTTD and MTTR.

Qualifications & Requirements

Citizenship & Compliance (Mandatory)

  • Must be a U.S. Citizen (required to support F5’s FedRAMP authorization, federal compliance mandates, and regulated environments).

Experience & Availability

  • 5+ years of hands-on experience in Incident Response, Security Operations (SOC), Threat Hunting, or Digital Forensics in enterprise cloud/SaaS environments.

  • Willingness and ability to participate in a rotating 24/7 on-call schedule.

Technical Skills

  • Deep familiarity with application security, reverse proxies, load balancers, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.

  • Strong experience analyzing telemetry across AWS/Azure/GCP, SIEM/EDR platforms (e.g., CrowdStrike), identity systems, and network logs.
  • Working knowledge of modern attack techniques (MITRE ATT&CK), API vulnerabilities, and emerging AI/LLM security risks.

Frameworks

  • Solid understanding of incident response frameworks and standards (NIST SP 800-61, ISO 27001, SOC 2, FedRAMP, PCI-DSS).

Success Measures (First 12–18 Months)
  • Successfully lead incident response investigations while meeting target response SLAs.

  • Expand playbook coverage and automated response actions for hybrid cloud and AI/API services.

  • Measurably reduce MTTC/MTTR through automated triage and streamlined escalation paths.

  • Integrate smoothly into the on-call rotation and support FedRAMP readiness initiatives.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $132,000.00 - $198,000.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice. 

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination.  F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].

Skills Required

  • 5+ years of cybersecurity experience
  • Hands-on experience in incident response, security operations, threat hunting, vulnerability response, product security, or investigations
  • Experience supporting complex incident response activities in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments
  • Knowledge of modern attack techniques, incident management, technical communications, cross-functional response coordination, workstream tracking, and stakeholder engagement
  • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security
  • Experience conducting AI and security investigations using cloud, identity, API gateway, application, endpoint, SIEM, WAF/WAAP, DLP, vulnerability, threat intelligence, and network/edge logs
  • Ability to work effectively across distributed teams
  • Familiarity with NIST, ISO, SOC, PCI, and GDPR requirements
  • Ability to support global incident response operations from Poland, including collaboration across LATAM and Americas time zones

F5 Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about F5 and has not been reviewed or approved by F5.

  • Equity Value & Accessibility Equity grants and an employee stock purchase plan are positioned as meaningful parts of total compensation, with RSUs and a discount ESPP commonly included. Pay packages for many technical roles are considered competitive when equity is taken into account.
  • Leave & Time Off Breadth Paid vacation that increases with tenure, sick time, paid holidays, and paid family leave are prominently featured. Additional programs like volunteer time and periodic wellness long weekends are highlighted as part of the time-off ecosystem.
  • Inclusive Benefits Coverage Health plans include travel support for specific care (such as reproductive and gender‑affirming services) and mental health resources, alongside comprehensive medical, dental, and vision coverage. These elements are presented as part of a broad, inclusive approach to healthcare.

F5 Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Seattle, WA
5,847 Employees

What We Do

F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device. F5 (NASDAQ: FFIV) powers applications from development through their entire life cycle, across any multi-cloud environment, so our customers – enterprise businesses, service providers, governments, and consumer brands—can deliver differentiated, high-performing, and secure digital experiences.

Similar Jobs

F5 Logo F5

Security Engineer

Cloud • Information Technology • Security • Software
In-Office
2 Locations
5847 Employees
182K-273K Annually

Grow Therapy Logo Grow Therapy

Security Engineer

Healthtech • Social Impact • Software
Remote or Hybrid
3 Locations
650 Employees
220K-280K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Claims Specialist, Workers Compensation - West Region

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
10 Locations
40000 Employees
61K-113K Annually

PwC Logo PwC

Sales Operations Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
41 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account