F5 Logo

F5

Security Engineer - Incident response

Posted 25 Days Ago
Be an Early Applicant
In-Office
Seattle, WA, USA
132K-198K Annually
Senior level
In-Office
Seattle, WA, USA
132K-198K Annually
Senior level
Support high-severity cyber and product security incident response across cloud, corporate, application, and customer-facing environments. Coordinate incident workstreams, communications, stakeholder engagement, containment, recovery, documentation, and post-incident reviews. Develop AI security incident response capabilities, support threat hunting and investigations, improve detection and response metrics, conduct tabletop exercises, and advance automation and resilience across hybrid multicloud environments.
The summary above was generated by AI

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. 
 

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Security Engineer III – Incident Response

Organization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience
Eligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)

Position Summary

We are seeking a Security Engineer III to join the Office of the CISO as a core member of our Global Incident Response team. In this role, you will lead hands-on triage, containment, and resolution of complex security incidents across corporate infrastructure, multicloud environments, core products (BIG-IP, NGINX, Distributed Cloud, WAAP), and emerging AI-enabled services.

You will serve as an incident responder and workstream lead during active cyber events, partnering across engineering, SRE, cloud operations, legal, and executive leadership from initial triage through post-incident remediation.

Key Responsibilities

Incident Triage & Response Execution

  • Lead end-to-end response for high-severity cyber and product security incidents (detection, containment, eradication, and recovery).

  • Drive incident command workflows, track mitigation workstreams, document forensic findings, and deliver clear technical updates to stakeholders.
  • On-Call Availability: Participate in a scheduled, rotating 24/7 on-call roster to ensure continuous incident response readiness.

AI & Cloud Security Response

  • Develop and execute response procedures for AI-enabled applications, large language model (LLM) workflows, AI gateways, and API data paths.

  • Implement automated triage, observability tooling, and detection rules to rapidly identify and isolate novel threats.

Cross-Functional Crisis Coordination

  • Collaborate with Product Engineering, SRE, Legal, Privacy, Communications, and Support teams during active investigations.

  • Author actionable post-incident reports, executive briefings, and customer notification materials.

Operational Resilience & Continuous Improvement

  • Facilitate post-incident reviews (PIRs/RCAs) to identify systemic risks and drive preventative engineering fixes.

  • Conduct tabletop exercises, purple team simulations, and playbook updates to continuously improve MTTD and MTTR.

Qualifications & Requirements

Citizenship & Compliance (Mandatory)

  • Must be a U.S. Citizen (required to support F5’s FedRAMP authorization, federal compliance mandates, and regulated environments).

Experience & Availability

  • 5+ years of hands-on experience in Incident Response, Security Operations (SOC), Threat Hunting, or Digital Forensics in enterprise cloud/SaaS environments.

  • Willingness and ability to participate in a rotating 24/7 on-call schedule.

Technical Skills

  • Deep familiarity with application security, reverse proxies, load balancers, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.

  • Strong experience analyzing telemetry across AWS/Azure/GCP, SIEM/EDR platforms (e.g., CrowdStrike), identity systems, and network logs.
  • Working knowledge of modern attack techniques (MITRE ATT&CK), API vulnerabilities, and emerging AI/LLM security risks.

Frameworks

  • Solid understanding of incident response frameworks and standards (NIST SP 800-61, ISO 27001, SOC 2, FedRAMP, PCI-DSS).

Success Measures (First 12–18 Months)
  • Successfully lead incident response investigations while meeting target response SLAs.

  • Expand playbook coverage and automated response actions for hybrid cloud and AI/API services.

  • Measurably reduce MTTC/MTTR through automated triage and streamlined escalation paths.

  • Integrate smoothly into the on-call rotation and support FedRAMP readiness initiatives.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $132,000.00 - $198,000.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice. 

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination.  F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].

HQ

F5 Seattle, Washington, USA Office

801 5th Ave, Seattle, WA, United States, 98104

Similar Jobs

10 Days Ago
In-Office
Seattle, WA, USA
182K-273K Annually
Expert/Leader
182K-273K Annually
Expert/Leader
Cloud • Information Technology • Security • Software
Leads F5’s enterprise incident response and cyber crisis management program, coordinating high-severity cyber and product security incidents from detection through recovery and post-incident review. Owns response governance, playbooks, metrics, executive reporting, tabletop exercises, and operational improvements. Provides technical leadership across cloud, identity, endpoint, application, API, Kubernetes, AI, and product security environments while coordinating engineering, legal, privacy, communications, customer support, and business stakeholders.
Top Skills: Ai SecurityAPIsBot DefenseCloud SecurityCrowdstrikeDdos ProtectionDlpEdrFedrampGdprHybrid MulticloudIsoKubernetesLoad BalancingNistPciReverse ProxySIEMSocThreat IntelligenceWaapWaf
One Month Ago
Remote or Hybrid
Seattle, WA, USA
220K-280K Annually
Senior level
220K-280K Annually
Senior level
Healthtech • Social Impact • Software
Lead and execute Grow Therapy's multi-year Security Engineering roadmap. Build secure-by-default infrastructure (auth, authZ, logging, egress), drive data security and systematic data tagging, develop org-wide security scorecards, enable automated least-privilege and vulnerability management, and influence AI-native security and security culture across product, platform, and compliance teams.
4 Hours Ago
In-Office or Remote
Seattle, WA, USA
200K-260K Annually
Expert/Leader
200K-260K Annually
Expert/Leader
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Lead regional growth strategy for USDC by building partnerships with exchanges and OTC desks, delivering regionally compliant product initiatives, and creating AI-driven, automated growth platforms. Own experimentation frameworks, dashboards, and metrics to scale liquidity, adoption, and measurable share shift versus competing stablecoins through cross-functional execution and data-driven prioritization.
Top Skills: Agent-Driven SystemsAIAnalyticsAutomation PlatformsBlockchainDashboardsExperimentation FrameworksStablecoins

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account