Security Engineer - Incident response

Posted Yesterday
Be an Early Applicant
Seattle, WA, USA
In-Office
132K-198K Annually
Senior level
Cloud • Information Technology • Security • Software
The Role
Support high-severity cyber and product security incident response across cloud, corporate, application, and customer-facing environments. Coordinate incident workstreams, communications, stakeholder engagement, containment, recovery, documentation, and post-incident reviews. Develop AI security incident response capabilities, support threat hunting and investigations, improve detection and response metrics, conduct tabletop exercises, and advance automation and resilience across hybrid multicloud environments.
Summary Generated by Built In

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. 
 

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Security Engineer III _ Incident Response

F5 Office of the CISO | Application Delivery, Security, and AI Resilience

Position Summary

We are seeking a Security Engineer III based in Poland to serve as a dedicated incident response member within F5’s Office of the CISO. This role supports coordinated response efforts across global teams, helps maintain incident command structure during active events, and ensures consistent communication, documentation, and resolution tracking across F5’s infrastructure, applications, products, and customer-facing environments.

The ideal candidate brings hands-on incident response experience, sound judgment under pressure, strong written and verbal communication, and the ability to support complex incidents from detection through post-incident review. This role contributes to F5’s incident response execution and operational maturity across corporate, cloud, product, and customer-facing environments, including F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI-enabled services.

The role supports high-severity cyber and product security incident response, cyber crisis coordination, workstream tracking, stakeholder communications, and post-incident improvement. The successful candidate will partner across F5 security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders to help drive timely, coordinated response outcomes across regions and time zones.

Key Responsibilities

Incident Response Program Support

  • Support F5’s incident response strategy, governance, standards, playbooks, severity model, metrics, and executive reporting through disciplined execution and clear documentation.
  • Participate in end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post-incident learning.
  • Coordinate assigned incident workstreams, track decisions and actions, engage cross-company and regional stakeholders, and maintain response visibility through resolution.

AI Security and Incident Response

  • Build incident response capabilities for AI-enabled applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths secured or delivered through F5 technologies.
  • Collaborate with AI engineering, product security, security research, and governance teams on AI incident classification, response procedures, customer notification inputs, and recovery frameworks.
  • Contribute to AI-assisted security operations, observability, automated triage, and responsible response automation across F5 environments.

Security Collaboration and Stakeholder Engagement

  • Contribute to security initiatives across incident response, product security, threat intelligence, application security, detection engineering, and resilience.
  • Coordinate security, engineering, SRE, product, legal, compliance, privacy, communications, customer support, and business teams during readiness and response activities.
  • Prepare clear incident updates, technical summaries, and operational inputs for leadership reviews, audits, customer escalations, partner discussions, and executive communications.

Operational Excellence

  • Track KPIs and KRIs for response effectiveness, vulnerability readiness, customer-impact reduction, and product security resilience.
  • Support tabletop exercises, cyber simulations, product security drills, and customer-impact response assessments.
  • Help improve MTTD, MTTC, MTTR, observability, fleet visibility, automation, and response orchestration across F5 environments.

Technical Execution

  • Provide practical technical support across cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS, bot defense, AI security, threat hunting, vulnerability response, and digital investigations.
  • Share knowledge with responders and security engineers through documentation, peer support, and practical operating guidance.

Qualifications

  • 5+ years of cybersecurity experience, including hands-on experience in incident response, security operations, threat hunting, vulnerability response, product security, or investigations.
  • Demonstrated ability to support complex incident response activities in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments.
  • Strong knowledge of modern attack techniques, incident management, technical communications, cross-functional response coordination, workstream tracking, and stakeholder engagement.
  • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security.
  • Experience conducting AI and security investigations using eReady, AWS, CrowdStrike, model invocation, identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, EDR, SIEM, WAF/WAAP, DLP, vulnerability, threat intelligence, and network/edge logs.
  • Ability to work effectively across distributed teams; familiarity with NIST, ISO, SOC, PCI, and GDPR requirements preferred.
  • Ability to support global incident response operations from Poland, including collaboration across LATAM / Americas time zones.

Success Measures

Success in the first 12–18 months will be measured by contributing to improved response capabilities and execution, faster detection, containment, and recovery; stronger product and AI incident readiness; reduced manual effort through automation; and effective coordination across global stakeholders.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $132,000.00 - $198,000.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice. 

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination.  F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].

Skills Required

  • 5+ years of cybersecurity experience
  • Hands-on experience in incident response, security operations, threat hunting, vulnerability response, product security, or investigations
  • Experience supporting complex incident response activities in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments
  • Knowledge of modern attack techniques, incident management, technical communications, cross-functional response coordination, workstream tracking, and stakeholder engagement
  • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security
  • Experience conducting AI and security investigations using cloud, identity, API gateway, application, endpoint, SIEM, WAF/WAAP, DLP, vulnerability, threat intelligence, and network/edge logs
  • Ability to work effectively across distributed teams
  • Familiarity with NIST, ISO, SOC, PCI, and GDPR requirements
  • Ability to support global incident response operations from Poland, including collaboration across LATAM and Americas time zones

F5 Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about F5 and has not been reviewed or approved by F5.

  • Equity Value & Accessibility Equity grants and an employee stock purchase plan are positioned as meaningful parts of total compensation, with RSUs and a discount ESPP commonly included. Pay packages for many technical roles are considered competitive when equity is taken into account.
  • Leave & Time Off Breadth Paid vacation that increases with tenure, sick time, paid holidays, and paid family leave are prominently featured. Additional programs like volunteer time and periodic wellness long weekends are highlighted as part of the time-off ecosystem.
  • Inclusive Benefits Coverage Health plans include travel support for specific care (such as reproductive and gender‑affirming services) and mental health resources, alongside comprehensive medical, dental, and vision coverage. These elements are presented as part of a broad, inclusive approach to healthcare.

F5 Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Seattle, WA
5,847 Employees

What We Do

F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device. F5 (NASDAQ: FFIV) powers applications from development through their entire life cycle, across any multi-cloud environment, so our customers – enterprise businesses, service providers, governments, and consumer brands—can deliver differentiated, high-performing, and secure digital experiences.

Similar Jobs

F5 Logo F5

Security Engineer

Cloud • Information Technology • Security • Software
In-Office
Seattle, WA, USA
5847 Employees
182K-273K Annually

ServiceNow Logo ServiceNow

Security Engineer

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Kirkland, WA, USA
29000 Employees
201K-352K Annually

Grow Therapy Logo Grow Therapy

Security Engineer

Healthtech • Social Impact • Software
Remote or Hybrid
3 Locations
460 Employees
220K-280K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account