1

Security Engineer Incident Response Jobs (NOW HIRING)

Security Engineer III - Incident Response Organization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience Eligibility: U.S. Citizenship Required (FedRAMP Authorization ...

AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: * Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt ...

Senior Security Engineer, Incident Response

$117K - $160K/yr

See yourself at Twilio Join the team as Twilio's next Senior Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer ...

Senior Security Engineer, Incident Response

$117K - $160K/yr

See yourself at Twilio Join the team as Twilio's next Senior Security Engineer, Incident Response About the job The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer ...

next page

Showing results 1-20

Security Engineer Incident Response information

See salary details

$61.5K

$152.8K

$205.5K

How much do security engineer incident response jobs pay per year?

As of Sep 9, 2026, the average yearly pay for security engineer incident response in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What does a security engineer incident response do?

A Security Engineer in Incident Response is responsible for detecting, investigating, and responding to security incidents within an organization. They analyze threats, contain breaches, and work to minimize damage caused by cyberattacks. Their role also involves improving security measures, documenting incidents, and collaborating with other IT and security teams to strengthen the company's defenses. Additionally, they may conduct post-incident reviews and help develop policies to prevent future incidents.

What are some common challenges faced by security engineers incident response, and how can they be addressed?

Security Engineers in Incident Response often face challenges such as rapidly evolving threats, managing large volumes of alerts, and coordinating response efforts across multiple teams. Staying updated with the latest attack techniques and regularly practicing incident response drills can help address these challenges. Effective communication, clear documentation, and collaboration with IT, legal, and management teams are crucial for successful incident handling and minimizing the impact of security incidents.

What are the key skills and qualifications needed to thrive as a security engineer incident response, and why are they important?

To thrive as a Security Engineer Incident Response, you need a solid understanding of cybersecurity principles, incident handling, and digital forensics, typically supported by a degree in computer science or a related field. Familiarity with SIEM tools, intrusion detection systems, and certifications like CISSP, CEH, or GIAC is highly valuable. Strong problem-solving abilities, attention to detail, and effective communication skills help you respond swiftly and collaborate with cross-functional teams during security incidents. These competencies are crucial for minimizing damage, ensuring rapid recovery, and strengthening an organization’s security posture.

What is the difference between Security Engineer Incident Response vs Security Analyst?

AspectSecurity Engineer Incident ResponseSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, GIAC certifications, CISSP (preferred)
Work EnvironmentIncident response teams, security operations centers (SOCs)Security operations centers, monitoring teams, threat analysis
Primary FocusResponding to security incidents, analyzing breaches, mitigating threatsMonitoring security alerts, analyzing vulnerabilities, reporting
Common UsageHandling security incidents, forensic analysis, threat mitigationSecurity monitoring, risk assessment, vulnerability management

While both roles involve cybersecurity and require similar certifications, Security Engineer Incident Response primarily focuses on responding to and managing security incidents, whereas Security Analysts concentrate on monitoring, analyzing threats, and identifying vulnerabilities. Both roles are essential in maintaining organizational security but differ in their core responsibilities and daily tasks.

What cities are hiring for Security Engineer Incident Response jobs?

Cities with the most Security Engineer Incident Response job openings:

What states have the most Security Engineer Incident Response jobs?

States with the most job openings for Security Engineer Incident Response jobs include:

What are popular job titles related to Security Engineer Incident Response jobs?

For Security Engineer Incident Response jobs, the most frequently searched job titles are:

Infographic showing various Security Engineer Incident Response job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Principal Security Engineer - Incident Response

Seattle, WA • On-site

F5, Inc.
IT Services • 1 - 5K employees

Full-time

Posted 18 days ago


Key responsibilities

  • Lead end-to-end response for cyber and product security incidents, including preparation, detection, containment, recovery, and post-incident learning.

  • Manage cyber crises by defining workstreams, driving decisions, coordinating cross-company stakeholders, and maintaining executive visibility through resolution.

  • Own F5's incident response program, including governance, standards, playbooks, severity model, metrics, and executive reporting.


Job description

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Principal Security Engineer - Incident Response & Crisis Management
Organization: F5 Office of the CISO | Application Delivery, Security, and AI Resilience
Eligibility: U.S. Citizenship Required (FedRAMP Authorization & Compliance)
Position Summary
We are seeking a Principal Security Engineer / Incident Response Lead to serve as the Incident Commander and strategic program lead within the Office of the CISO. In this senior role, you will orchestrate enterprise-scale response efforts, drive cyber crisis management, and elevate incident response maturity across F5's corporate infrastructure, hybrid multicloud environments, core product lines (BIG-IP, NGINX, Distributed Cloud, WAAP), and emerging AI-enabled services.
You will act as the primary escalation point during high-impact security events, translating complex forensic investigations into clear executive communications and driving cross-functional alignment across Engineering, SRE, Legal, Communications, and Executive Leadership.
Key Responsibilities
Incident Command & Cyber Crisis Leadership
  • Serve as the Incident Commander for enterprise-wide, high-severity cyber and product security incidents from detection through post-incident review.
  • Define and lead response workstreams, coordinate cross-functional teams, and maintain executive visibility throughout crisis resolution.
  • On-Call Availability: Participate in and lead the rotating 24/7 on-call escalation rotation for major security incidents.

IR Program Strategy & AI Security Readiness
  • Own and evolve F5's global Incident Response roadmap, playbooks, severity matrix, governance standards, and executive metrics.
  • Architect incident response frameworks for AI-enabled applications, LLMs, AI gateways, APIs, and model runtime data paths.
  • Drive AI-assisted security operations, automated triage, and response orchestration to eliminate manual overhead.

Executive Stakeholder & Regulatory Engagement
  • Author high-impact technical summaries, root-cause analyses (RCAs), customer notifications, and board-level briefing materials.
  • Represent the Incident Response program in compliance audits, regulatory reviews, and key customer escalations.

Operational Resilience, Metrics & Mentorship
  • Define and track key resilience metrics (MTTD, MTTC, MTTR, blast-radius reduction) and conduct high-fidelity tabletop simulations.
  • Mentor security engineers and incident responders, establishing technical standards, investigation playbooks, and operational best practices.

Qualifications & Requirements
Citizenship & Compliance (Mandatory)
  • Must be a U.S. Citizen (required to support F5's FedRAMP authorization, federal compliance mandates, and government-regulated environments).

Experience & Availability
  • 10+ years of progressive cybersecurity experience with deep expertise in Incident Command, SOC leadership, Threat Hunting, Product Security, or Digital Forensics in large-scale SaaS/cloud environments.
  • Willingness and availability to participate in a rotating 24/7 on-call escalation schedule.

Technical Mastery
  • Advanced understanding of application delivery architectures, load balancing, reverse proxies, WAF/WAAP, API gateways, DDoS mitigation, and Kubernetes ingress security.
  • Proven expertise investigating complex telemetry across AWS/Azure/GCP, SIEMs, EDR platforms (e.g., CrowdStrike), identity providers, and network/edge devices.
  • Working knowledge of modern adversary tradecraft (MITRE ATT&CK), API attack vectors, and emerging AI/LLM threat landscapes.

Leadership & Frameworks
  • Demonstrated ability to command high-stress situations and influence senior engineering and executive stakeholders without direct authority.
  • Comprehensive familiarity with industry frameworks: FedRAMP, NIST SP 800-61 / 800-53, ISO 27001, SOC 2, and PCI-DSS.

Success Measures (First 12-18 Months)
  • Mature and standardize global incident command playbooks across hybrid cloud and AI workloads.
  • Lead high-severity crisis investigations to swift containment while maintaining stakeholder trust and SLA adherence.
  • Drive measurable improvements in MTTD/MTTR across enterprise and product environments.
  • Ensure IR processes fully satisfy FedRAMP continuous monitoring and compliance requirements.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $182,200.00 - $273,200.00
F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5's benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com)
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.