Principal Security Engineer - Incident Response

F5
Seattle
Workplace: HybridFull timeUSD 182,200 - 273,200 annuallyFunction: CybersecurityExperience: 10+ yearsSkills: ["Exceptional communication","Cross-functional coordination","Crisis leadership","Stakeholder orchestration","Learning from ambiguity"]

Lead F5’s incident response program within the Office of the CISO, serving as dedicated incident command during active events. Coordinate end-to-end cyber and product security crisis management across infrastructure, applications, and customer-facing environments—driving workstreams, executive communications, documentation, and post-incident improvements. Advance incident response for AI-enabled services and hybrid multicloud environments, improve operational metrics (MTTD/MTTC/MTTR), and provide deep technical leadership across security, cloud, identity, APIs, WAF/WAAP, DDoS, and bot defense.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
F5
F5
3 days ago

Principal Security Engineer - Incident Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Lead F5’s incident response program within the Office of the CISO, serving as dedicated incident command during active events. Coordinate end-to-end cyber and product security crisis management across infrastructure, applications, and customer-facing environments—driving workstreams, executive communications, documentation, and post-incident improvements. Advance incident response for AI-enabled services and hybrid multicloud environments, improve operational metrics (MTTD/MTTC/MTTR), and provide deep technical leadership across security, cloud, identity, APIs, WAF/WAAP, DDoS, and bot defense.
Location: Seattle
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own and evolve F5’s incident response program: governance, standards, playbooks, severity model, metrics, and executive reporting.
  • •Lead end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post-incident learning.
  • •Manage cyber crises end to end by defining workstreams, driving decisions, coordinating cross-company stakeholders, and maintaining executive visibility through resolution.
  • •Build and improve AI security and incident response capabilities for AI-enabled applications, models, agents, inference traffic, gateways, APIs, and secured runtime data paths.
  • •Define KPIs/KRIs and improve incident operations (MTTD/MTTC/MTTR, observability, fleet visibility, automation, and response orchestration), including tabletop exercises and simulations.

Pay and Benefits

Salary: USD 182,200 - 273,200 annually
Equity and Bonus:Equity

Key Requirements

  • •10+ years of cybersecurity experience with deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations.
  • •Proven ability to lead enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments.
  • •Strong knowledge of modern attack techniques and incident management with executive communications and cross-functional crisis coordination.
  • •Understanding of application delivery and security architectures (load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security).
  • •Experience with log sources/telemetry such as CrowdStrike detections, EDR events, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence, and network/edge logs.
Experience:10+ yearsSaaSCloudHybrid multicloudCustomer-facing technology
Skills:Exceptional communicationCross-functional coordinationCrisis leadershipStakeholder orchestrationLearning from ambiguity
Tech Stack:CrowdStrikeSIEMEDRWAFWAAPDLPAPI gatewayAPI securityKubernetes ingressDDoSBot defenseLoad balancingReverse proxyThreat intelligence

Company Brief

F5
Provides application delivery networking, load balancing, and security solutions for on-premises and cloud environments, helping organizations optimize, secure, and scale applications and APIs across multi-cloud infrastructures.
Industry: Networking Equipment
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Seattle, United States
Founded: 1996
Glassdoor
Glassdoor: 3.8
WebsiteLinkedIn