Lead Architect – Application Security
Job Duties and Responsibilities
- Design and validate architecture for WAAP services, distributed DDoS protection layers, advanced bot mitigation pipelines, client fingerprinting, fraud prevention engines, and access-aware enforcement controls.
- Develop and evangelize reusable security frameworks and patterns across the product portfolio.
- Collaborate with detection teams and data scientists to integrate machine learning, heuristics, and behavior analysis engines into runtime defense systems.
- Define telemetry, feedback loops, and attack modeling infrastructure to continuously improve detection fidelity and response agility.
- Work across organizational boundaries to ensure integration of security across the portfolio.
- Guide compliance, privacy, and regulatory alignment by ensuring architecture supports evolving standards such as FIPS, FedRAMP, NIST CSF, ISO 27001, GDPR, and OWASP.
- Drive architectural reviews, design validations, and threat models to ensure operational, security, and scalability concerns are addressed early.
- Planning, tracking and scheduling software deliverables.
Skills and Qualifications
- 20+ years of experience in software and security architecture roles, with at least 10 years focused specifically on application-layer security.
- Proven track record architecting complex security systems in domains such as WAAP, API security, DDoS mitigation, bot protection, and malware detection.
- Deep understanding of L7 protocols (HTTP/2, HTTP/3, WebSockets, gRPC) and application security standards (OWASP Top 10, NIST, MITRE ATT&CK).
- Strong technical understanding of TLS, certificate management, identity and access protocols (OAuth2, OIDC, SAML), and secure session management.
- Familiarity with zero trust architectures, policy-as-code, multi-tenant SaaS designs, and runtime enforcement in container-based platforms (Kubernetes, Istio, Envoy).
- Demonstrated ability to set architectural strategy across product boundaries and influence senior engineering and product leadership.
- Experience designing and implementing distributed cloud solutions at scale.
- Broad understanding of coding and programming languages.
- Extensive knowledge of the software development process and corresponding technologies.
- Excellent understanding of design patterns and architectural styles.
- Proficient knowledge of the operation and development designs of agile software.
- Strong soft skills, including attention to detail, problem-solving and communication skills.
Pay
The annual base pay for this position is: $297,600.00 - $446,400.00
F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits.
About the Role
F5 is seeking a Senior Architect for Application Security to lead technical strategy and architecture across its entire security portfolio, including WAF, DDoS mitigation, AI Security, Bot Defense, API Security, TLS inspection, and identity-aware access.
This role drives the evolution of F5’s security services across SaaS, hardware, and cloud-native platforms, ensuring they are integrated, scalable, and secure-by-design.
As a senior technical leader, you will unify architectural direction, modernize legacy systems, and represent F5’s security vision in both internal strategy and external engagements.
Qualifications
20+ years of experience in software and security architecture roles, with at least 10 years focused specifically on application-layer security.
Proven track record architecting complex security systems in domains such as WAAP, API security, DDoS mitigation, bot protection, and malware detection.
Deep understanding of L7 protocols (HTTP/2, HTTP/3, WebSockets, gRPC) and application security standards (OWASP Top 10, NIST, MITRE ATT&CK).
Strong technical understanding of TLS, certificate management, identity and access protocols (OAuth2, OIDC, SAML), and secure session management.
Familiarity with zero trust architectures, policy-as-code, multi-tenant SaaS designs, and runtime enforcement in container-based platforms (Kubernetes, Istio, Envoy).
Demonstrated ability to set architectural strategy across product boundaries and influence senior engineering and product leadership.
Experience designing and implementing distributed cloud solutions at scale.
Broad understanding of coding and programming languages.
Extensive knowledge of the software development process and corresponding technologies.
Excellent understanding of design patterns and architectural styles.
Proficient knowledge of the operation and development designs of agile software.
Strong soft skills, including attention to detail, problem-solving and communication skills.
Benefits
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
F5 is committed to providing equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws.
Contact Information
If you have questions regarding this position, please contact us at recruiting@f5.com.