Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.
F5 Networks in Mexico's Región Centro seeks a Security Engineer III in Detection Engineering to develop, test, deploy, and improve detections that support Security Operations. You will transform threat intelligence and telemetry into scalable, actionable content in collaboration with Incident Response and Threat Intelligence teams.
Responsibilities include developing detections using Detection-as-Code, aligning coverage with MITRE ATT&CK, automating workflows, onboarding new log sources, and
Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software — refuse. These are signs of fraud.
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
The Security Engineer III, Detection Engineering is a career-level security engineering professional responsible for developing, testing, deploying, and continuously improving detection capabilities that support Security Operations. As part of the Security Operations Platform Engineering (SOPE) team, this role focuses on transforming threat intelligence, telemetry, and security requirements into reliable, actionable detections that improve visibility and reduce organizational risk. The engineer partners closely with Incident Response, Threat Intelligence, Logging Engineering, and platform engineering teams to build scalable, threat-driven detection capabilities while advancing automation, detection coverage, and operational maturity.
Primary Responsibilities
Develop andmaintaincustom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows.
Analyze and improvedetection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework,identifyinggaps and prioritizing enhancements.
Partner withIncident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate emerging threats, investigations, and telemetry into actionable detection content.
Validate and tunedetections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives.
Automate andoptimisedetectionengineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability.
Supportonboardingofnew log sources and security telemetry by collaborating with engineering and infrastructure teams toestablishdetection coverage across new environments and technologies.
Create andmaintaindetectiondocumentation, runbooks, coverage assessments, and technical standards whileparticipatingin an engineering on-call rotation.
Help define detection strategy for AI and agentic systems (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs), andexplore using AI to accelerate detection engineering workflows.
Required Skills / Qualifications
Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience.
5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, ora relateddiscipline.
Experience developing, tuning, ormaintainingdetections within a SIEM, EDR, log analytics, or security monitoring platform.
Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies.
Strong understanding of attacker techniques, detection methodologies, and frameworks such as MITRE ATT&CK.
Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
Preferred Skills / Qualifications
Experience implementing Detection-as-Code practices, including Git-based workflows, automated testing, and CI/CD pipelines.
Experiencewith adversary emulation, atomic testing, purple-team exercises, or detection validation frameworks.
Experience performing detection coverage analysis and developing ATT&CK-based coverage roadmaps.
Experience onboarding log sources and building detections across cloud, endpoint, network, identity, or SaaS environments.
Experience with platforms such as CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic, or similar security technologies.
Familiarity with AI/LLM threat models (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs) or frameworks such as MITRE ATLAS and the OWASP LLM Top 10 — and interest in applying AI to accelerate detection engineering workflows.
This is a full-time engineering role and is not a shift-based position.Participation in an engineering on-call rotation isrequiredand may occasionally require support outside normal business hours during critical incidents, platform outages, or detection-related operational events. The Security Engineer III may be engaged as a subject matter expert during security incidents but is not responsible for primary incident response or SOC operations. Travel may berequiredup to 5%, including occasional international travel.
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting .