Enter a job title or keyword

Principal Security Engineer Incident Response

F5 Networks


Job Location:

Seattle, WA - USA

Monthly Salary: $ 182200 - 273200
Posted: 21 August 2026 (2 days ago)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Job Summary

At F5 we strive to bring a better digital world to life. Our teams empower organizations across the globe to create secure and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity from protecting consumers from fraud to enabling companies to focus on innovation.

Everything we do centers around people. That means we obsess over how to make the lives of our customers and their customers better. And it means we prioritize a diverse F5 community where each individual can thrive.

Position Summary

We are seeking a Principal Incident Response Lead to serve as the dedicated incident command and response program lead within F5s Office of the CISO. This role coordinates cross-functional response efforts maintains incident command structure during active events and ensures consistent communication documentation and resolution tracking across F5s infrastructure applications products and customer-facing environments.

The ideal candidate thrives in fast-paced environments brings structure to and learning to ambiguity has exceptional communication skills and can effectively drive complex incidents from detection through post-incident review. This role will serve as a central driver for security incident response ensuring effective management of day-to-day incidents as well as large-scale high-impact cybersecurity events. The Principal Incident Response Lead is a senior individual contributor in F5s Office of the CISO responsible for advancing incident response strategy execution and operational maturity across corporate cloud product and customer-facing environments. This role strengthens cyber resilience for F5 BIG-IP NGINX Distributed Cloud WAAP API security DDoS bot defense hybrid multicloud and emerging AI-enabled services.

The role leads high-severity cyber and product security incident response end-to-end cyber crisis management response workstream coordination executive communications and post-incident improvement. The successful candidate will influence security product engineering SRE cloud operations legal privacy communications customer support and business stakeholders to drive timely coordinated response outcomes.

Key Responsibilities

Incident Response Program Leadership

  • Own F5s incident response roadmap governance standards playbooks severity model metrics and executive reporting.
  • Lead end-to-end response for cyber and product security incidents including preparation detection containment recovery customer impact assessment and post-incident learning.
  • Manage cyber crises end to end by defining workstreams driving decisions coordinating cross-company stakeholders and maintaining executive visibility through resolution.

AI Security and Incident Response

  • Build incident response capabilities for AI-enabled applications models agents inference traffic AI gateways APIs and runtime data paths secured or delivered through F5 technologies.
  • Partner with AI engineering product security security research and governance teams on AI incident classification response procedures customer notification inputs and recovery frameworks.
  • Advance AI-assisted security operations observability automated triage and responsible response automation across F5 environments.

Strategic Security Leadership

  • Influence F5 security strategy across incident response product security threat intelligence application security detection engineering and resilience.
  • Coordinate security engineering SRE product legal compliance privacy communications customer support and business teams during readiness and response activities.
  • Represent incident response in executive reviews audits customer escalations partner discussions and board-level conversations.

Operational Excellence

  • Define KPIs and KRIs for response effectiveness vulnerability readiness customer-impact reduction and product security resilience.
  • Lead tabletop exercises cyber simulations product security drills and customer-impact response assessments.
  • Improve MTTD MTTC MTTR observability fleet visibility automation and response orchestration across F5 environments.

Technical Leadership

  • Provide expert guidance on cloud identity endpoint application API Kubernetes WAAP DDoS bot defense AI security threat hunting vulnerability response and digital investigations.
  • Mentor and help guide learning for responders and security engineers through technical leadership influence and practical operating guidance.

Qualifications

  • 10 years of cybersecurity experience including deep expertise in incident response security operations product security threat hunting vulnerability response or investigations.
  • Proven ability to lead enterprise-scale incident response programs in SaaS cloud hybrid multicloud and customer-facing technology environments.
  • Strong knowledge of modern attack techniques incident management executive communications cross-functional crisis coordination workstream management and stakeholder orchestration.
  • Understanding of application delivery and security architectures including load balancing reverse proxy WAF API security DDoS protection bot defense Kubernetes ingress and public cloud security.
  • Experience using the following log sources or familiarity CrowdStrike Model invocation logs identity and access API gateway and application agent/tool execution data access and retrieval cloud and infrastructure security telemetry CrowdStrike endpoint detections EDR process/network events SIEM alerts WAF/WAAP events DLP alerts vulnerability signals threat intelligence matches and network/edge logs.
  • Experience influencing strategy across large organizations without direct authority through partnership; familiarity with NIST ISO SOC PCI and GDPR requirements preferred.
  • Ability to support global incident response operations from US including collaboration across EMEA/LATAM / Americas time zones.
  • FedRAMP eligible

Success Measures

Success in the first 1218 months will be measured by improved response maturity faster detection containment and recovery; stronger product and AI incident readiness; reduced manual effort through automation; improved customer-impact analysis; and clear executive visibility through meaningful metrics and reporting.

Role Details: Principal Individual Contributor; F5 Office of the CISO; focused on incident response end-to-end cyber crisis management workstream leadership AI security response application/API security hybrid multicloud resilience customer trust and executive engagement.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However the description may not be all-inclusive and responsibilities and requirements are subject to change.

The annual base pay for this position is: $182200.00 - $273200.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge skills experience geographic locations and market conditions as well as to reflect F5s differing products industries and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation bonus restricted stock units and benefits. More details about F5s benefits can be found at the following link: F5 reserves the right to change or terminate any benefit plan without notice.

Please note that F5 only contacts candidates through F5 email address (ending with @) or auto email notification from Workday (ending with or @).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race religion color national origin sex sexual orientation gender identity or expression age sensory physical or mental disability marital status veteran or military status genetic information or any other classification protected by applicable local state or federal laws. This policy applies to all aspects of employment including but not limited to hiring job assignment compensation promotion benefits training discipline and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting .


Required Experience:

Staff IC


About Company

Company Logo

F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device.

View Profile View Profile