Software Engineer III - Security
Software Engineering
Bengaluru, Karnataka, India
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Position Summary:
The Software Engineer III is responsible for researching, analyzing, and validating emerging cyber threats targeting applications, APIs, AI/LLM systems, cloud native environments, and modern enterprise infrastructure. This engineer develops proof of concept attacks, detection techniques, security validation frameworks, and security tools that help strengthen F5 Application Delivery and Security Platform (ADSP), including BIG-IP, NGINX, F5 AI Guardrails, F5 AI Gateway, and F5 Distributed Cloud solutions.
This role combines threat intelligence, offensive security research, automation, security tool development, and technical content creation to improve F5 security products and support technical marketing engineering with demos, validation assets, tools, and customer facing content. The engineer collaborates closely with Product Security, Engineering, Product Management, Security Research, Threat Intelligence, Technical Marketing Engineering, and architects to identify emerging attack trends, validate F5 protections, and create reusable technical assets.
Primary Responsibilities:
· Research emerging cyber threats targeting web applications, APIs, AI/LLM applications, cloud workloads, Kubernetes, and enterprise infrastructure.
· Analyze attacker tactics, techniques, and procedures using frameworks such as MITRE ATT&CK, MITRE ATLAS, OWASP Web Application Top 10, OWASP API Security Top 10, and OWASP LLM Top 10.
· Develop proof of concept exploits, attack simulations, and threat emulation scenarios to reproduce real world threat conditions.
· Design, implement, and maintain automated security validation frameworks, detection tools, and supporting security tools for threat detection, testing, and mitigation.
· Evaluate and validate F5 security products and platform capabilities against emerging threats and evolving attack techniques.
· Build reusable tools, scripts, demos, and validation assets that support technical marketing engineering use cases, customer demonstrations, and technical enablement.
· Publish and create technical content, demos, and security focused materials for internal teams and customers, highlighting F5 application delivery and security capabilities.
· Participate actively in code reviews by contributing scripts, incorporating feedback, and reviewing automation and tooling developed by team members.
· Contribute to repeatable methodologies for security testing, threat emulation, and use case validation across product and marketing engineering needs.
Knowledge and Skills:
· Strong knowledge of application security, API security, cloud security, and AI/LLM security.
· Strong understanding of OWASP Web Application Top 10, OWASP API Security Top 10, and OWASP LLM Top 10.
· Strong programming skills in Python for automation, tooling, validation, and security research.
· Knowledge of threat intelligence, attack techniques, threat detection, and security validation using frameworks such as MITRE ATT&CK and MITRE ATLAS is required.
· Strong knowledge of security and networking fundamentals.
· Experience building or supporting security tools, automation frameworks, validation environments, or threat simulation capabilities.
· Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, ffuf, sqlmap, or similar.
· Strong experience in networking and working knowledge of HTTP, DNS, TCP/IP required.
· Proficiency in L2/L3 network protocol testing.
· Experience with GitHub or other source control management tools preferred.
· Experience with CI/CD, Agile software development, and test automation.
· Ability to support technical marketing engineering through demos, validation assets, technical tools, and customer facing technical content.
· Strong organizational, analytical, troubleshooting, and problem solving skills.
Qualifications:
· 7+ years of professional experience in software development, testing, security validation, or security engineering, preferably in a Linux environment.
· Experience working with geographically dispersed teams preferred.
· BA/BS degree in computer science, engineering, or related field, or equivalent work experience.
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.