SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 297,600 - 446,400 / annual
F5 is seeking a Lead Architect for Application Security to define and drive the technical strategy and architecture across its entire security portfolio. This role encompasses WAF, DDoS mitigation, AI Security, Bot Defense, API Security, TLS inspection, and identity-aware access—spanning SaaS, hardware, and cloud-native platforms.
You will define cross-portfolio application security architecture strategy covering hardware, software, and cloud-native solutions, aligned to F5's long-term business and technology vision. You'll establish architectural principles, patterns, and roadmaps guiding how WAF, WAAP, API security, DDoS, identity, client-side protection, and AI/ML-powered detection and response capabilities are designed, integrated, and delivered.
Key responsibilities include leading architectural modernization efforts to evolve monolithic or appliance-based capabilities into composable, API-driven services within a SaaS-native security control plane. You'll influence the security posture and innovation roadmap across F5 Distributed Cloud Services, BIG-IP, NGINX, and future platform initiatives. You'll champion architectural governance and threat modeling across teams to ensure scalability, observability, resiliency, and secure-by-default practices are institutionalized.
You'll drive cross-functional alignment across product, engineering, SRE, and infrastructure teams to ensure seamless and secure user experiences across hybrid, multicloud, and edge deployments. You'll mentor a community of senior architects and engineers, raising the bar for application security talent across the company. You'll represent F5's technical vision in customer briefings, industry forums, regulatory discussions, and analyst engagements.
Design and validate architecture for WAAP services, distributed DDoS protection layers, advanced bot mitigation pipelines, client fingerprinting, fraud prevention engines, and access-aware enforcement controls. Develop and evangelize reusable security frameworks and patterns across the product portfolio. Collaborate with detection teams and data scientists to integrate machine learning, heuristics, and behavior analysis engines into runtime defense systems. Define telemetry, feedback loops, and attack modeling infrastructure to continuously improve detection fidelity and response agility. Guide compliance, privacy, and regulatory alignment by ensuring architecture supports evolving standards such as FIPS, FedRAMP, NIST CSF, ISO 27001, GDPR, and OWASP.