ForgeApply
Try it free

ForgeApply · Job listing

Principal Security Engineer - Incident Response

Ffive

Seattle, US$182k – $273khybrid

See all 55 open roles at Ffive

Tailor your resume for this Ffive job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Ffive's site. Free trial, no card required.

About this role

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Position Summary We are seeking a Principal Incident Response Lead to serve as the dedicated incident command and response program lead within F5’s Office of the CISO. This role coordinates cross-functional response efforts, maintains incident command structure during active events, and ensures consistent communication, documentation, and resolution tracking across F5’s infrastructure, applications, products, and customer-facing environments.

The ideal candidate thrives in fast-paced environments, brings structure to and learning to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review. This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events. The Principal Incident Response Lead is a senior individual contributor in F5’s Office of the CISO responsible for advancing incident response strategy, execution, and operational maturity across corporate, cloud, product, and customer-facing environments. This role strengthens cyber resilience for F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI-enabled services. The role leads high-severity cyber and product security incident response, end-to-end cyber crisis management, response workstream coordination, executive communications, and post-incident improvement. The successful candidate will influence security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders to drive timely, coordinated response outcomes.

Key Responsibilities Incident Response Program Leadership • Own F5’s incident response, roadmap, governance, standards, playbooks, severity model, metrics, and executive reporting. • Lead end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post-incident learning. • Manage cyber crises end to end by defining workstreams, driving decisions, coordinating cross-company stakeholders, and maintaining executive visibility through resolution.

AI Security and Incident Response • Build incident response capabilities for AI-enabled applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths secured or delivered through F5 technologies. • Partner with AI engineering, product security, security research, and governance teams on AI incident classification, response procedures, customer notification inputs, and recovery frameworks. • Advance AI-assisted security operations, observability, automated triage, and responsible response automation across F5 environments.

Strategic Security Leadership • Influence F5 security strategy across incident response, product security, threat intelligence, application security, detection engineering, and resilience. • Coordinate security, engineering, SRE, product, legal, compliance, privacy, communications, customer support, and business teams during readiness and response activities. • Represent incident response in executive reviews, audits, customer escalations, partner discussions, and board-level conversations.

Operational Excellence • Define KPIs and KRIs for response effectiveness, vulnerability readiness, customer-impact reduction, and product security resilience. • Lead tabletop exercises, cyber simulations, product security drills, and customer-impact response assessments. • Improve MTTD, MTTC, MTTR, observability, fleet visibility, automation, and response orchestration across F5 environments.

Technical Leadership • Provide expert guidance on cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS, bot defense, AI security, threat hunting, vulnerability response, and digital investigations. • Mentor and help guide learning for responders and security engineers through technical leadership, influence, and practical operating guidance.

Qualifications • 10+ years of cybersecurity experience, including deep expertise in incident response, security operations, product security, threat hunting, vulnerability response, or investigations. • Proven ability to lead enterprise-scale incident response programs in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments. • Strong knowledge of modern attack techniques, incident management, executive communications, cross-functional crisis coordination, workstream management, and stakeholder orchestration. • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security. • Experience using the following log sources or familiarity, CrowdStrike, Model invocation logs , identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, security telemetry, CrowdStrike endpoint detections, EDR process/network events, SIEM alerts, WAF/WAAP events, DLP alerts, vulnerability signals, threat intelligence matches, and network/edge logs. • Experience influencing strategy across large organizations without direct authority through partnership; familiarity with NIST, ISO, SOC, PCI, and GDPR requirements preferred. • Ability to support global incident respon

Salary insight

The midpoint of this range ($228k) is about 42% above the median disclosed salary for Seattle roles listed on ForgeApply ($160k across 1,708 jobs).

See full Security Engineer salary data for Seattle

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Ffive role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Seattle · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)