F5
Principal Security Engineer - Incident Response
Seattle · Principal
Sponsorship not specified$182k-$273kDetected 18 days ago
KubernetesNginxSite Reliability EngineeringCybersecuritySIEMSOC OperationsDetection EngineeringIncident ResponseComplianceHRISCustomer SupportFirewallLoad BalancingResearchLeadershipCommunicationCollaboration
Stay score
odds of building a lasting career here
64Sponsors, lottery-bound
Cap-exempt (no lottery)0
Sponsors this role100
Entry-level history0
PERM / green-card track0
Lottery odds (Level IV)94
Fits your clock70
Sponsors, but it's cap-subject — you still face the weighted lottery (~61% per draw at Level IV). Good if you win; have a cap-exempt backup on your list.
Lottery odds assume a STEM candidate.
Personalize to your clock →Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events.
- This role strengthens cyber resilience for F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI-enabled services.
Responsibilities
- Own F5's incident response, roadmap, governance, standards, playbooks, severity model, metrics, and executive reporting.
- Manage cyber crises end to end by defining workstreams, driving decisions, coordinating cross-company stakeholders, and maintaining executive visibility through resolution.
- Build incident response capabilities for AI-enabled applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths secured or delivered through F5 technologies.
- Partner with AI engineering, product security, security research, and governance teams on AI incident classification, response procedures, customer notification inputs, and recovery frameworks.
- Coordinate security, engineering, SRE, product, legal, compliance, privacy, communications, customer support, and business teams during readiness and response activities.
- Represent incident response in executive reviews, audits, customer escalations, partner discussions, and board-level conversations.
- Lead tabletop exercises, cyber simulations, product security drills, and customer-impact response assessments.
Requirements
- Proven ability to lead enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments.
- Experience using the following log sources or familiarity, CrowdStrike, Model invocation logs, identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, security telemetry, CrowdStrike endpoint detections, EDR process/network events, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence matches, and network/edge logs.
- Ability to support global incident response operations from US, including collaboration across EMEA/LATAM / Americas time zones.
- FedRAMP eligible
- Success Measures
- Success in the first 12-18 months will be measured by improved response maturity, faster detection, containment, and recovery
- stronger product and AI incident readiness
- reduced manual effort through automation
- improved customer-impact analysis
Nice to have
- Advance AI-assisted security operations, observability, automated triage, and responsible response automation across F5 environments.
- Influence F5 security strategy across incident response, product security, threat intelligence, application security, detection engineering, and resilience.
- Define KPIs and KRIs for response effectiveness, vulnerability readiness, customer-impact reduction, and product security resilience.
- Improve MTTD, MTTC, MTTR, observability, fleet visibility, automation, and response orchestration across F5 environments.
- Provide expert guidance on cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS, bot defense, AI security, threat hunting, vulnerability response, and digital investigations.
- 10+ years of cybersecurity experience, including deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations.
- Strong knowledge of modern attack techniques, incident management, executive communications, cross-functional crisis coordination, workstream management, and stakeholder orchestration.
- Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security.
Compensation
- $182,200.00 - $273,200.00
- F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business.
- The pay range referenced is as of the time of the job posting and is subject to change.
- You may also be offered incentive compensation, bonus, restricted stock units, and benefits.
Benefits
- https://www.f5.com/company/careers/benefits.
- F5 reserves the right to change or terminate any benefit plan without notice.
- This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination.
- Lead end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post-incident learning.
- Mentor and help guide learning for responders and security engineers through technical leadership, influence, and practical operating guidance.
Company info
- At F5, we strive to bring a better digital world to life.
- We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
- That means we obsess over how to make the lives of our customers, and their customers, better.
- We are seeking a Principal Incident Response Lead to serve as the dedicated incident command and response program lead within F5's Office of the CISO.
Equal opportunity
- It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws.
- F5 offers a variety of reasonable accommodations for candidates.
- Requesting an accommodation is completely voluntary.
- F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job.
This listing is sourced directly from F5's careers page and normalized into a canonical job model.