Principal Security Engineer - Incident Response

F5 Networks, Inc. 

Seattle (WA)

Hybrid

USD 182,000 - 273,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

F5 Networks, Inc. seeks a Principal Incident Response Lead to head incident command and response within the Office of the CISO.

You will coordinate cross-functional response efforts, maintain incident command during active events, and ensure consistent communication, documentation, and resolution tracking across F5’s infrastructure, applications, products, and customer‑facing environments. The role leads cyber and product security incidents, provides executive visibility, and advances incident

Qualifications

  • 10+ years in cybersecurity with incident response and security operations experience.
  • Experience leading enterprise-scale incident response programs in SaaS/cloud environments.
  • Strong communication skills for executive audiences and cross-functional teams.
  • Familiarity with modern attack techniques, incident management, and crisis coordination.
  • Understanding of application delivery security: WAF, API security, DDoS protection, and cloud security.

Responsibilities

  • Own incident response program including governance, playbooks, and metrics.
  • Lead end-to-end response for cyber and product security incidents with cross-team coordination.
  • Drive post-incident reviews and executive reporting to improve maturity and resilience.

Skills

Incident response leadership
Cross-functional coordination
Executive communications
Cloud security
Threat intelligence
AI security
Kubernetes

Tools

CrowdStrike
SIEM
EDR
Kubernetes

Job description

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Position Summary

We are seeking a Principal Incident Response Lead to serve as the dedicated incident command and response program lead within F5’s Office of the CISO. This role coordinates cross-functional response efforts, maintains incident command structure during active events, and ensures consistent communication, documentation, and resolution tracking across F5’s infrastructure, applications, products, and customer‑facing environments. The ideal candidate thrives in fast‑paced environments, brings structure to and learning to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post‑incident review. This role will serve as a central driver for security incident response, ensuring effective management of day‑to‑day incidents as well as large‑scale, high‑impact cybersecurity events. The Principal Incident Response Lead is a senior individual contributor in F5’s Office of the CISO responsible for advancing incident response strategy, execution, and operational maturity across corporate, cloud, product, and customer‑facing environments. This role strengthens cyber resilience for F5 BIG‑IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI‑enabled services. The role leads high‑severity cyber and product security incident response, end‑to‑end cyber crisis management, response workstream coordination, executive communications, and post‑incident improvement. The successful candidate will influence security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders to drive timely, coordinated response outcomes.

Key Responsibilities
  • Incident Response Program Leadership Own F5’s incident response, roadmap, governance, standards, playbooks, severity model, metrics, and executive reporting. Lead end‑to‑end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post‑incident learning. Manage cyber crises end to end by defining workstreams, driving decisions, coordinating cross‑company stakeholders, and maintaining executive visibility through resolution.
  • AI Security and Incident Response Build incident response capabilities for AI‑enabled applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths secured or delivered through F5 technologies. Partner with AI engineering, product security, security research, and governance teams on AI incident classification, response procedures, customer notification inputs, and recovery frameworks. Advance AI‑assisted security operations, observability, automated triage, and responsible response automation across F5 environments.
  • Strategic Security Leadership Influence F5 security strategy across incident response, product security, threat intelligence, application security, detection engineering, and resilience. Coordinate security, engineering, SRE, product, legal, compliance, privacy, communications, customer support, and business teams during readiness and response activities. Represent incident response in executive reviews, audits, customer escalations, partner discussions, and board‑level conversations.
  • Operational Excellence Define KPIs and KRIs for response effectiveness, vulnerability readiness, customer‑impact reduction, and product security resilience. Lead tabletop exercises, cyber simulations, product security drills, and customer‑impact response assessments. Improve MTTD, MTTC, MTTR, observability, fleet visibility, automation, and response orchestration across F5 environments.
  • Technical Leadership Provide expert guidance on cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS, bot defense, AI security, threat hunting, vulnerability response, and digital investigations. Mentor and help guide learning for responders and security engineers through technical leadership, influence, and practical operating guidance.
Qualifications
  • 10+ years of cybersecurity experience, including deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations.
  • Proven ability to lead enterprise‑scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer‑facing technology environments.
  • Strong knowledge of modern attack techniques, incident management, executive communications, cross‑functional crisis coordination, workstream management, and stakeholder orchestration.
  • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security.
  • Experience using the following log sources or familiarity, CrowdStrike, Model invocation logs , identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, security telemetry, CrowdStrike endpoint detections, EDR process/network events, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence matches, and network/edge logs.
  • Experience influencing strategy across large organizations without direct authority through partnership; familiarity with NIST, ISO, SOC, PCI, and GDPR requirements preferred.
  • Ability to support global incident response operations from US, including collaboration across EMEA/LATAM / Americas time zones.
  • FedRAMP eligible
Success Measures

Success in the first 12–18 months will be measured by improved response maturity, faster detection, containment, and recovery; stronger product and AI incident readiness; reduced manual effort through automation; improved customer‑impact analysis; and clear executive visibility through meaningful metrics and reporting.

Role Details

Principal Individual Contributor; F5 Office of the CISO; focused on incident response, end‑to‑end cyber crisis management, workstream leadership, AI security response, application/API security, hybrid multicloud resilience, customer trust, and executive engagement.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all‑inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $182,200.00 - $273,200.00 F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change. You may also be offered incentive compensation, bonus, restricted stock units, and benefits.

More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits.

F5 reserves the right to change or terminate any benefit plan without notice.

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination.

F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.

Hybrid

Employees within 30 commutable miles of an F5 office are required to work from the office a minimum of 30 business days per quarter.

Remote

Primarily work from designated home location but can come into an F5 office to work or travel to an offsite location as needed.

Together, we’re building a better digital world. Founded in 1996, F5 is a global leader in application delivery and security. Our premier platform helps customers secure and deliver every app, API, and piece of infrastructure across all environments. Backed by over three decades of expertise and 553 patents, our solutions protect against threats while ensuring fast, reliable digital experiences. With over 6,400 employees, we serve more than 23,000 customers in over 170 countries. To continue this work, we need people like you—the best minds in the industry. We’re committed to a unique, human‑first culture that encourages authenticity, prioritizes diversity and inclusion, and fosters the growth and success of our employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Incident response
Security Engineer - Incident response

F5 Networks, Inc.  • United States

Hybrid
USD 132,000 - 198,000
Security Engineer - Incident response
Security Engineer - Incident response

F5 Networks, Inc.  • Seattle (WA), Northern (KY)

Hybrid
USD 132,000 - 198,000
Principal Security Engineer - Incident Response
Principal Security Engineer - Incident Response

F5 Networks, Inc • Seattle (WA)

On-site
USD 182,000 - 273,000
Security Engineer - Incident response
Security Engineer - Incident response

F5 Networks, Inc • Seattle (WA)

On-site
USD 132,000 - 198,000
Senior Software Engineer – Agentic AI Tools
Senior Software Engineer – Agentic AI Tools

F5 Networks, Inc.  • San Jose (CA)

Hybrid
USD 166,000 - 250,000
Security Technical Program Manager
Security Technical Program Manager

F5 Networks, Inc.  • Seattle (WA), Northern (KY)

Hybrid
USD 129,000 - 193,000
Security Technical Program Manager
Security Technical Program Manager

F5 Networks, Inc.  • United States

Hybrid
USD 129,000 - 193,000
Sr. Security Engineer - Incident Response
Sr. Security Engineer - Incident Response

F5 Networks, Inc • Warsaw (IN)

On-site
USD 68,000 - 103,000
ISS Security Specialist
ISS Security Specialist

F5 Networks, Inc.  • United States

Hybrid
USD 95,000 - 143,000
Senior Solutions Engineer - SLED - So. California
Senior Solutions Engineer - SLED - So. California

F5 Networks, Inc.  • California (MO)

Hybrid
USD 163,000 - 245,000