Source description
About the role
Job Description Join a high-impact security team leveraging advanced technologies and best practices to safeguard F5's enterprise and product environments. As a Security Engineer III, you will play a key role in handling sophisticated security incidents, performing deep-dive investigations, and supporting incident response efforts. You will serve as an escalation point for SOC L1/L2 analysts while driving improvements in detection capabilities, response processes, and overall security posture. Key Responsibilities - Lead and manage complex security incidents, including malware outbreaks, insider threats, APTs, and data exfiltration events - Perform root cause analysis (RCA) and recommend remediation strategies - Collaborate with IT, DevOps, and business teams during incident response activities - Design, tune, and optimize SIEM use cases and detection rules - Enhance alert quality by reducing false positives and improving detection accuracy - Implement automation through SOAR platforms - Act as the final escalation point for L1 and L2 SOC analysts - Mentor junior analysts and provide technical leadership - Develop and maintain security runbooks, documentation, and incident response playbooks - Prepare detailed incident reports and executive summaries - Conduct post-incident reviews and facilitate lessons learned sessions - Adhere to F5 information security policies to protect organizational assets - Perform additional responsibilities as needed while embodying F5 core behaviors. Required Skills & Experience - 7+ years of experience in SOC or cybersecurity, with strong incident response and L3 SOC expertise - Deep knowledge of SIEM platforms and EDR/XDR tools (e.g., Microsoft Defender, CrowdStrike) - Strong skills in log analysis and scripting (Python, PowerShell, Bash) - Experience in cloud security (Azure, AWS, GCP) and identity security (Active Directory, Azure AD) - Ability to perform effectively under pressure during high-severity incidents - Excellent communication, reporting, and documentation skills - Strong analytical thinking and problem-solving abilities Preferred Qualifications - Certifications such as CEH, ECSA, GCIH (SANS), or equivalent - Experience with ServiceNow, Azure DevOps (ADO), or similar case management tools - Strong collaboration and interpersonal skills - Demonstrated ability to lead and mentor junior team members - Ability to present technical findings and recommendations to leadership clearly Work Environment - Full time role with potential shift flexibility - Participation in a shared on-call rotation, including early mornings, evenings, weekends, and holidays - Primarily desk-based work with remote collaboration across global teams Job Description Join a high-impact security team leveraging advanced technologies and best practices to safeguard F5's enterprise and product environments. As a Security Engineer III, you will play a key role in handling sophisticated security incidents, performing deep-dive investigations, and supporting incident response efforts. You will serve as an escalation point for SOC L1/L2 analysts while driving improvements in detection capabilities, response processes, and overall security posture. Key Responsibilities - Lead and manage complex security incidents, including malware outbreaks, insider threats, APTs, and data exfiltration events - Perform root cause analysis (RCA) and recommend remediation strategies - Collaborate with IT, DevOps, and business teams during incident response activities - Design, tune, and optimize SIEM use cases and detection rules - Enhance alert quality by reducing false positives and improving detection accuracy - Implement automation through SOAR platforms - Act as the final escalation point for L1 and L2 SOC analysts - Mentor junior analysts and provide technical leadership - Develop and maintain security runbooks, documentation, and incident response playbooks - Prepare detailed incident reports and executive summaries - Conduct post-incident reviews and facilitate lessons learned sessions - Adhere to F5 information security policies to protect organizational assets - Perform additional responsibilities as needed while embodying F5 core behaviors. Required Skills & Experience - 7+ years of experience in SOC or cybersecurity, with strong incident response and L3 SOC expertise - Deep knowledge of SIEM platforms and EDR/XDR tools (e.g., Microsoft Defender, CrowdStrike) - Strong skills in log analysis and scripting (Python, PowerShell, Bash) - Experience in cloud security (Azure, AWS, GCP) and identity security (Active Directory, Azure AD) - Ability to perform effectively under pressure during high-severity incidents - Excellent communication, reporting, and documentation skills - Strong analytical thinking and problem-solving abilities Preferred Qualifications - Certifications such as CEH, ECSA, GCIH (SANS), or equivalent - Experience with ServiceNow, Azure DevOps (ADO), or similar case management tool
More at f5