At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Security Engineer III – Incident ResponseOrganization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience
Eligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)
We are seeking a Security Engineer III to join the Office of the CISO as a core member of our Global Incident Response team. In this role, you will lead hands-on triage, containment, and resolution of complex security incidents across corporate infrastructure, multicloud environments, core products (BIG-IP, NGINX, Distributed Cloud, WAAP), and emerging AI-enabled services.
You will serve as an incident responder and workstream lead during active cyber events, partnering across engineering, SRE, cloud operations, legal, and executive leadership from initial triage through post-incident remediation.
Key ResponsibilitiesIncident Triage & Response Execution
Lead end-to-end response for high-severity cyber and product security incidents (detection, containment, eradication, and recovery).
- Drive incident command workflows, track mitigation workstreams, document forensic findings, and deliver clear technical updates to stakeholders.
- On-Call Availability: Participate in a scheduled, rotating 24/7 on-call roster to ensure continuous incident response readiness.
AI & Cloud Security Response
Develop and execute response procedures for AI-enabled applications, large language model (LLM) workflows, AI gateways, and API data paths.
Implement automated triage, observability tooling, and detection rules to rapidly identify and isolate novel threats.
Cross-Functional Crisis Coordination
Collaborate with Product Engineering, SRE, Legal, Privacy, Communications, and Support teams during active investigations.
Author actionable post-incident reports, executive briefings, and customer notification materials.
Operational Resilience & Continuous Improvement
Facilitate post-incident reviews (PIRs/RCAs) to identify systemic risks and drive preventative engineering fixes.
Conduct tabletop exercises, purple team simulations, and playbook updates to continuously improve MTTD and MTTR.
Citizenship & Compliance (Mandatory)
Must be a U.S. Citizen (required to support F5’s FedRAMP authorization, federal compliance mandates, and regulated environments).
Experience & Availability
5+ years of hands-on experience in Incident Response, Security Operations (SOC), Threat Hunting, or Digital Forensics in enterprise cloud/SaaS environments.
- Willingness and ability to participate in a rotating 24/7 on-call schedule.
Technical Skills
Deep familiarity with application security, reverse proxies, load balancers, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.
- Strong experience analyzing telemetry across AWS/Azure/GCP, SIEM/EDR platforms (e.g., CrowdStrike), identity systems, and network logs.
- Working knowledge of modern attack techniques (MITRE ATT&CK), API vulnerabilities, and emerging AI/LLM security risks.
Frameworks
Solid understanding of incident response frameworks and standards (NIST SP 800-61, ISO 27001, SOC 2, FedRAMP, PCI-DSS).
Successfully lead incident response investigations while meeting target response SLAs.
Expand playbook coverage and automated response actions for hybrid cloud and AI/API services.
Measurably reduce MTTC/MTTR through automated triage and streamlined escalation paths.
Integrate smoothly into the on-call rotation and support FedRAMP readiness initiatives.
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $132,000.00 - $198,000.00F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].
Skills Required
- 5+ years of cybersecurity experience
- Hands-on experience in incident response, security operations, threat hunting, vulnerability response, product security, or investigations
- Experience supporting complex incident response activities in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments
- Knowledge of modern attack techniques, incident management, technical communications, cross-functional response coordination, workstream tracking, and stakeholder engagement
- Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security
- Experience conducting AI and security investigations using cloud, identity, API gateway, application, endpoint, SIEM, WAF/WAAP, DLP, vulnerability, threat intelligence, and network/edge logs
- Ability to work effectively across distributed teams
- Familiarity with NIST, ISO, SOC, PCI, and GDPR requirements
- Ability to support global incident response operations from Poland, including collaboration across LATAM and Americas time zones
F5 Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about F5 and has not been reviewed or approved by F5.
-
Equity Value & Accessibility — Equity grants and an employee stock purchase plan are positioned as meaningful parts of total compensation, with RSUs and a discount ESPP commonly included. Pay packages for many technical roles are considered competitive when equity is taken into account.
-
Leave & Time Off Breadth — Paid vacation that increases with tenure, sick time, paid holidays, and paid family leave are prominently featured. Additional programs like volunteer time and periodic wellness long weekends are highlighted as part of the time-off ecosystem.
-
Inclusive Benefits Coverage — Health plans include travel support for specific care (such as reproductive and gender‑affirming services) and mental health resources, alongside comprehensive medical, dental, and vision coverage. These elements are presented as part of a broad, inclusive approach to healthcare.
F5 Insights
What We Do
F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device. F5 (NASDAQ: FFIV) powers applications from development through their entire life cycle, across any multi-cloud environment, so our customers – enterprise businesses, service providers, governments, and consumer brands—can deliver differentiated, high-performing, and secure digital experiences.








