Principal Security Engineer, Incident Response

F5 Inc

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$182,200–$273,200 / yr
Posted
7 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $228k
$115k most similar roles pay here $290k

This role pays more than 88% of similar roles. Most pay $156,600–$208,800 — the shaded band above. At the midpoint, this role pays about $228k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About F5 Inc

F5, Inc. is an American technology company specializing in application security, multi-cloud management, online fraud prevention, application delivery networking, application availability and performance, and network security, access, and authorization.

F5 Inc currently has 25 open roles on FindRole.

Listed pay typically runs $152,200–$228,400 across 25 roles with salary data.

Most-posted roles

View all roles at F5 Inc

At a glance

TL;DR · Principal Security Engineer, Incident Response

Principal Security Engineer - Incident Response serves as the Incident Commander and strategic program lead within the Office of the CISO. This role involves orchestrating enterprise-scale response efforts, managing cyber crises, and improving incident response maturity across corporate infrastructure, hybrid multicloud environments, and AI-enabled services. The individual will manage global incident response roadmaps, develop playbooks, and conduct high-fidelity tabletop simulations while translating complex forensic investigations into executive communications. Key responsibilities include coordinating cross-functional teams during high-severity events and ensuring compliance with FedRAMP, NIST, and ISO standards. Technical requirements include expertise in application delivery architectures, load balancing, WAF/WAAP, API gateways, and Kubernetes ingress security. The role requires proficiency with AWS, Azure, GCP, SIEMs, EDR platforms like CrowdStrike, and knowledge of MITRE ATT&CK frameworks to secure products including BIG-IP and NGINX.

What does a Security Engineer earn?

Median $185250 from 84 postings across 39 companies.

See salary data

What you'll do

  • Serve as the Incident Commander for high-severity cyber and product security incidents from detection through post-incident review.
  • Lead 24/7 on-call escalation rotations to manage major security incidents across corporate and product environments.
  • Develop and maintain global incident response playbooks, severity matrices, and governance standards.
  • Architect incident response frameworks specifically for AI-enabled applications, LLMs, and API gateways.
  • Translate complex forensic investigations into technical summaries and reports for executive leadership and board members.
  • Represent the Incident Response program during compliance audits and regulatory reviews to ensure FedRAMP requirements are met.
  • Track key resilience metrics such as MTTD and MTTR while conducting high-fidelity tabletop simulations.
  • Mentor security engineers by establishing technical standards and investigation best practices.

What we're looking for

  • Must be a U.S. Citizen for FedRAMP authorization and government compliance requirements.
  • 10+ years of progressive cybersecurity experience in Incident Command, SOC leadership, Threat Hunting, Product Security, or Digital Forensics.
  • Willingness to participate in a rotating 24/7 on-call escalation schedule.
  • Advanced knowledge of application delivery architectures, load balancing, WAF/WAAP, API gateways, and Kubernetes ingress security.
  • Proven expertise investigating telemetry across AWS/Azure/GCP, SIEMs, EDR platforms, identity providers, and network devices.
  • Working knowledge of MITRE ATT&CK, API attack vectors, and emerging AI/LLM threat landscapes.
  • Ability to influence senior engineering and executive stakeholders during high-stress situations.
  • Familiarity with industry frameworks including FedRAMP, NIST SP 800-61/800-53, ISO 27001, SOC 2, and PCI-DSS.

More like this

Similar roles

Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Principal Security Engineer

Microsoft

16 days ago $142,800$274,800
Threat Modeling Security Architecture Automation Distributed Systems APIs Risk Management Cyber Security Anomaly Detection Security Assessment Reference Architecture
6+ yrs exp

Principal Engineer, Operational Technology Security

Target

Brooklyn Park, MN 39 days ago $168,000$303,000
Operational Technology (OT) IoT Network Architecture Network Segmentation GCP AWS Azure SIEM DLP IDS IPS NIST ISO/IEC 27001 PCI-DSS ISA/IEC 62443 Patch Management Risk Management Vulnerability Management Threat Intelligence Incident Response
10+ yrs exp Hybrid

Security Incident Response Engineer

Stripe

Remote (Chicago, IL) +3 16 days ago $144,300$216,500
Python SQL Log Analysis Network Security Digital Forensics Incident Response Databricks Jupyter Trino PySpark Pandas Sci-kit Learn osquery Splunk LogScale UEBA SIEM SOAR DLP
3+ yrs exp Remote

Principal Security Engineer

Oracle

Switzerland 76 days ago $106,300$234,600
Hardware Security Firmware x86 ARM UEFI Root of Trust Secureboot Cryptography Intel SGX C C++ Java Python Ruby Go Rust Assembly CICD SPDM SmartNICs
8+ yrs exp