ForgeApply · Job listing
Security Engineer - Incident response
Ffive
See all 55 open roles at Ffive →
Tailor your resume for this Ffive job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Ffive's site. Free trial, no card required.
About this role
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Security Engineer III _ Incident Response F5 Office of the CISO | Application Delivery, Security, and AI Resilience
Position Summary We are seeking a Security Engineer III based in Poland to serve as a dedicated incident response member within F5’s Office of the CISO. This role supports coordinated response efforts across global teams, helps maintain incident command structure during active events, and ensures consistent communication, documentation, and resolution tracking across F5’s infrastructure, applications, products, and customer-facing environments.
The ideal candidate brings hands-on incident response experience, sound judgment under pressure, strong written and verbal communication, and the ability to support complex incidents from detection through post-incident review. This role contributes to F5’s incident response execution and operational maturity across corporate, cloud, product, and customer-facing environments, including F5 BIG-IP, NGINX, Distributed Cloud, WAAP, API security, DDoS, bot defense, hybrid multicloud, and emerging AI-enabled services. The role supports high-severity cyber and product security incident response, cyber crisis coordination, workstream tracking, stakeholder communications, and post-incident improvement. The successful candidate will partner across F5 security, product engineering, SRE, cloud operations, legal, privacy, communications, customer support, and business stakeholders to help drive timely, coordinated response outcomes across regions and time zones.
Key Responsibilities Incident Response Program Support • Support F5’s incident response strategy, governance, standards, playbooks, severity model, metrics, and executive reporting through disciplined execution and clear documentation. • Participate in end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, customer impact assessment, and post-incident learning. • Coordinate assigned incident workstreams, track decisions and actions, engage cross-company and regional stakeholders, and maintain response visibility through resolution.
AI Security and Incident Response • Build incident response capabilities for AI-enabled applications, models, agents, inference traffic, AI gateways, APIs, and runtime data paths secured or delivered through F5 technologies. • Collaborate with AI engineering, product security, security research, and governance teams on AI incident classification, response procedures, customer notification inputs, and recovery frameworks. • Contribute to AI-assisted security operations, observability, automated triage, and responsible response automation across F5 environments.
Security Collaboration and Stakeholder Engagement • Contribute to security initiatives across incident response, product security, threat intelligence, application security, detection engineering, and resilience. • Coordinate security, engineering, SRE, product, legal, compliance, privacy, communications, customer support, and business teams during readiness and response activities. • Prepare clear incident updates, technical summaries, and operational inputs for leadership reviews, audits, customer escalations, partner discussions, and executive communications.
Operational Excellence • Track KPIs and KRIs for response effectiveness, vulnerability readiness, customer-impact reduction, and product security resilience. • Support tabletop exercises, cyber simulations, product security drills, and customer-impact response assessments. • Help improve MTTD, MTTC, MTTR, observability, fleet visibility, automation, and response orchestration across F5 environments.
Technical Execution • Provide practical technical support across cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS, bot defense, AI security, threat hunting, vulnerability response, and digital investigations. • Share knowledge with responders and security engineers through documentation, peer support, and practical operating guidance.
Qualifications • 5+ years of cybersecurity experience, including hands-on experience in incident response, security operations, threat hunting, vulnerability response, product security, or investigations. • Demonstrated ability to support complex incident response activities in SaaS, cloud, hybrid, multicloud, and customer-facing technology environments. • Strong knowledge of modern attack techniques, incident management, technical communications, cross-functional response coordination, workstream tracking, and stakeholder engagement. • Understanding of application delivery and security architectures, including load balancing, reverse proxy, WAF, API security, DDoS protection, bot defense, Kubernetes ingress, and public cloud security. • Experience conducting AI and security investigations using eReady, AWS, CrowdStrike, model invocation, identity and access, API gateway and application, agent/tool execution, data access and retrieval, cloud and infrastructure, EDR, SIEM, WAF/WAAP, DLP, vulnerability, threat intelligence, and network/edge logs. • Ability to work effectively across distributed teams; familiarity with NIST, ISO, SOC, PCI, and GDPR requirements preferred. • Ability to support global incident response operations from Poland, including collaboration across LATAM / Americas time zones.
Success Measures Success in the first 12–18 months will be measured by contributing to improved
Salary insight
The midpoint of this range ($165k) is right around the median disclosed salary for Seattle roles listed on ForgeApply ($160k across 1,708 jobs).
See full Security Engineer salary data for Seattle →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Ffive role before you apply.
Tailor my resume for this jobSimilar jobs
- Security Engineer, Incident Response — Peloton · New York, New York
- Senior Security Engineer, Incident Response — Airbnb · United States
- Senior Security Engineer, Incident Response — 1password · Remote
- Senior Security Engineer, Incident Response — Snowflake · Remote
- Principal Security Engineer - Incident Response — Ffive · Seattle
- Security Engineer - Detection & Response — Langchain · San Francisco, CA
- Security Incident Response Engineer — Stripe · Remote
- Security Incident Response Engineer — Acrisure · GA | MI
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Seattle · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)