F logo

Principal Security Engineer - Incident Response

F5, IncSan Jose, CA

$182,200 - $273,200 / year

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Senior-level
Remote
On-site
Compensation
$182,200-$273,200/year

Job Description

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Principal Security Engineer - Incident Response & Crisis Management

Organization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience

Eligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)

Position Summary

We are seeking a Principal Security Engineer / Incident Response Lead to serve as the Incident Commander and strategic program lead within the Office of the CISO. In this senior role, you will orchestrate enterprise-scale response efforts, drive cyber crisis management, and elevate incident response maturity across F5's corporate infrastructure, hybrid multicloud environments, core product lines (BIG-IP, NGINX, Distributed Cloud, WAAP), and emerging AI-enabled services.

You will act as the primary escalation point during high-impact security events, translating complex forensic investigations into clear executive communications and driving cross-functional alignment across Engineering, SRE, Legal, Communications, and Executive Leadership.

Key Responsibilities

Incident Command & Cyber Crisis Leadership

  • Serve as the Incident Commander for enterprise-wide, high-severity cyber and product security incidents from detection through post-incident review.

  • Define and lead response workstreams, coordinate cross-functional teams, and maintain executive visibility throughout crisis resolution.

  • On-Call Availability: Participate in and lead the rotating 24/7 on-call escalation rotation for major security incidents.

IR Program Strategy & AI Security Readiness

  • Own and evolve F5's global Incident Response roadmap, playbooks, severity matrix, governance standards, and executive metrics.

  • Architect incident response frameworks for AI-enabled applications, LLMs, AI gateways, APIs, and model runtime data paths.

  • Drive AI-assisted security operations, automated triage, and response orchestration to eliminate manual overhead.

Executive Stakeholder & Regulatory Engagement

  • Author high-impact technical summaries, root-cause analyses (RCAs), customer notifications, and board-level briefing materials.

  • Represent the Incident Response program in compliance audits, regulatory reviews, and key customer escalations.

Operational Resilience, Metrics & Mentorship

  • Define and track key resilience metrics (MTTD, MTTC, MTTR, blast-radius reduction) and conduct high-fidelity tabletop simulations.

  • Mentor security engineers and incident responders, establishing technical standards, investigation playbooks, and operational best practices.

Qualifications & Requirements

Citizenship & Compliance (Mandatory)

  • Must be a U.S. Citizen (required to support F5's FedRAMP authorization, federal compliance mandates, and government-regulated environments).

Experience & Availability

  • 10+ years of progressive cybersecurity experience with deep expertise in Incident Command, SOC leadership, Threat Hunting, Product Security, or Digital Forensics in large-scale SaaS/cloud environments.

  • Willingness and availability to participate in a rotating 24/7 on-call escalation schedule.

Technical Mastery

  • Advanced understanding of application delivery architectures, load balancing, reverse proxies, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.

  • Proven expertise investigating complex telemetry across AWS/Azure/GCP, SIEMs, EDR platforms (e.g., CrowdStrike), identity providers, and network/edge devices.

  • Working knowledge of modern adversary tradecraft (MITRE ATT&CK), API attack vectors, and emerging AI/LLM threat landscapes.

Leadership & Frameworks

  • Demonstrated ability to command high-stress situations and influence senior engineering and executive stakeholders without direct authority.

  • Comprehensive familiarity with industry frameworks: FedRAMP, NIST SP 800-61 / 800-53, ISO 27001, SOC 2, and PCI-DSS.

Success Measures (First 12-18 Months)

  • Mature and standardize global incident command playbooks across hybrid cloud and AI workloads.

  • Lead high-severity crisis investigations to swift containment while maintaining stakeholder trust and SLA adherence.

  • Drive measurable improvements in MTTD/MTTR across enterprise and product environments.

  • Ensure IR processes fully satisfy FedRAMP continuous monitoring and compliance requirements.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $182,200.00 - $273,200.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5's benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Principal Security Engineer - Incident Response Jobs at F5, Inc

What is the work location for this position at F5, Inc?
This job at F5, Inc is located in San Jose, CA, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at F5, Inc?
Candidates can expect a pay range of $182,200 and $273,200 per year.
What employment applies to this position at F5, Inc?
F5, Inc lists this role as a Full-time position.
What experience level is required for this role at F5, Inc?
F5, Inc is looking for a candidate with "Senior-level" experience level.
What is the process to apply for this position at F5, Inc?
You can apply for this role at F5, Inc either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.