Principal Security Engineer - Incident Response
Listed on 2026-08-22
-
IT/Tech
Cybersecurity
Principal Incident Response Lead
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
We are seeking a Principal Incident Response Lead to serve as the dedicated incident command and response program lead within F5's Office of the CISO. This role coordinates cross-functional response efforts, maintains incident command structure during active events, and ensures consistent communication, documentation, and resolution tracking across F5's infrastructure, applications, products, and customer-facing environments.
The ideal candidate thrives in fast-paced environments, brings structure to and learning to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review. This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events. The Principal Incident Response Lead is a senior individual contributor in F5's Office of the CISO responsible for advancing incident response strategy, execution, and operational maturity across corporate, cloud, product, and customer-facing environments.
This role strengthens cyber resilience for F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI-enabled services.
The role leads high-severity cyber and product security incident response, end-to-end cyber crisis management, response workstream coordination, executive communications, and post-incident improvement. The successful candidate will influence security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders to drive timely, coordinated response outcomes.
Key Responsibilities- Incident Response Program Leadership
- AI Security and Incident Response
- Strategic Security Leadership
- Operational Excellence
- Technical Leadership
Qualifications
- 10+ years of cybersecurity experience, including deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations.
- Proven ability to lead enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments.
- Strong knowledge of modern attack techniques, incident management, executive communications, cross-functional crisis coordination, workstream management, and stakeholder orchestration.
- Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security.
- Experience using the following log sources or familiarity, Crowd Strike, Model invocation logs, identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, security telemetry, Crowd Strike endpoint detections, EDR process/network events, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence matches, and network/edge logs.
- Experience influencing strategy across large organizations without direct authority through partnership; familiarity with NIST, ISO, SOC, PCI, and GDPR requirements preferred.
- Ability to support global incident response operations from US, including collaboration across EMEA/LATAM / Americas time zones.
- FedRAMP eligible
Success Measures
Success in the first 12–18 months will be measured by improved response maturity, faster detection, containment, and recovery; stronger product and AI incident readiness; reduced manual effort through automation; improved customer-impact analysis; and clear executive visibility through meaningful metrics and reporting.
The annual base pay for this position is: $ - $
F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5's benefits can be found at the following link: . F5 reserves the right to change or terminate any benefit plan without notice.
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).