Full-Time

Lead Architect

Application Security

F5

F5

5,001-10,000 employees

Multi-cloud app security and delivery platform

Compensation Overview

$297.6k - $446.4k/yr

+ Incentive compensation + Bonus + Restricted stock units

Company Historically Provides H1B Sponsorship

Seattle, WA, USA + 1 more

More locations: San Jose, CA, USA

Hybrid

Hybrid work is required in San Jose or Seattle.

Category
Cybersecurity (1)
Required Skills
gRPC
Kubernetes
FedRAMP
Agile
Threat modeling
Machine Learning
Docker
Istio
SAML
Nginx
Observability

Get referred to F5

See people who can refer or advise you

Requirements
  • 20+ years of experience in software and security architecture roles, including at least 10 years focused specifically on application-layer security.
  • A proven track record architecting complex security systems in web application and API protection, API security, distributed denial-of-service mitigation, bot protection, and malware detection.
  • Deep understanding of Layer 7 protocols, including HTTP/2, HTTP/3, WebSockets, and gRPC, and application security standards including OWASP Top 10, NIST, and MITRE ATT&CK.
  • Strong technical understanding of Transport Layer Security, certificate management, identity and access protocols including OAuth2, OIDC, and SAML, and secure session management.
  • Familiarity with zero trust architectures, policy-as-code, multi-tenant software-as-a-service designs, and runtime enforcement in container-based platforms including Kubernetes, Istio, and Envoy.
  • Demonstrated ability to set architectural strategy across product boundaries and influence senior engineering and product leadership.
  • Experience designing and implementing distributed cloud solutions at scale.
  • Understanding of containers and orchestration technologies.
  • Broad understanding of coding and programming languages.
  • Extensive knowledge of the software development process and corresponding technologies.
  • Excellent understanding of design patterns and architectural styles.
  • Proficient knowledge of agile software development.
  • Strong attention to detail, problem-solving, and communication skills.
Responsibilities
  • Define the cross-portfolio application security architecture strategy across hardware, software, and cloud-native solutions, aligning it with F5’s long-term business and technology vision.
  • Establish architectural principles, patterns, and roadmaps for web application and API protection, API security, distributed denial-of-service mitigation, identity, client-side protection, artificial intelligence and machine-learning-powered detection and response, and related capabilities.
  • Lead architectural modernization efforts to evolve monolithic or appliance-based capabilities into composable, API-driven services within a software-as-a-service-native security control plane.
  • Influence the security posture and innovation roadmap across F5 Distributed Cloud Services, BIG-IP, NGINX, and future platform initiatives.
  • Champion architectural governance and threat modeling across teams to institutionalize scalability, observability, resiliency, and secure-by-default practices.
  • Drive cross-functional alignment across product, engineering, site reliability engineering, and infrastructure teams for secure user experiences across hybrid, multicloud, and edge deployments.
  • Mentor a community of senior architects and engineers and raise application security capability across the company.
  • Represent F5’s technical vision in customer briefings, industry forums, regulatory discussions, and analyst engagements.
  • Design and validate architecture for web application and API protection services, distributed denial-of-service protection layers, advanced bot mitigation pipelines, client fingerprinting, fraud prevention engines, and access-aware enforcement controls.
  • Develop and evangelize reusable security frameworks and patterns across the product portfolio.
  • Collaborate with detection teams and data scientists to integrate machine learning, heuristics, and behavior analysis engines into runtime defense systems.
  • Define telemetry, feedback loops, and attack-modeling infrastructure to improve detection fidelity and response agility.
  • Work across organizational boundaries to integrate security across the portfolio.
  • Guide compliance, privacy, and regulatory alignment by ensuring architecture supports FIPS, FedRAMP, NIST CSF, ISO 27001, GDPR, and OWASP.
  • Drive architectural reviews, design validations, and threat models to address operational, security, and scalability concerns early.
  • Plan, track, and schedule software deliverables.

F5 offers multi-cloud application services and security to keep apps secure and available across different hosting environments. Its products include web application and API protection (WAF and API security), bot defense, fraud prevention, and application delivery features like load balancing and access management. The solutions protect and accelerate applications wherever they run, combining security with delivery in a single toolkit, sold as licenses, subscriptions, and support contracts, plus professional services. The goal is to help customers securely deliver fast, reliable applications across any cloud or data center while reducing abuse and ensuring smooth user access.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

Seattle, Washington

Founded

1996

Get referred to F5

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q3 FY2026 revenue reached $865 million, up 11%, and guidance rose to 9%-10%.
  • September 2026 AI launches target agentic enterprise spend at Salesforce and MuleSoft customers.
  • Management expects double-digit systems growth and strong FY2027 demand from AI and refreshes.

What critics are saying

  • July 2026 advisories hit BIG-IP, NGINX, and BIG-IP Next, eroding trust.
  • CVE-2026-59762 and CVE-2026-6476 expose DoS and privilege-escalation risks in core products.
  • If another zero-day hits BIG-IP, customers accelerate migrations to cloud-native rivals.

What makes F5 unique

  • F5's June 22, 2026 AI Security Platform embeds runtime guardrails into live traffic.
  • September 2, 2026 MuleSoft integration puts F5 AI Guardrails inside Agent Fabric.
  • BIG-IP and NGINX span delivery, WAF, and multicloud control across hybrid estates.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Comprehensive medical, dental, & vision coverage

Paid employee life & disability insurance

Employee Assistance Program (EAP)

Competitive pay

Employee Stock Purchase Plan

401(k) with company match

Health and daycare saving accounts (HSA and FSAs)

Tuition assistance

Adoption assistance

20 days of vacation and 25 days of vacation after year 5

10 days of sick leave

8 Weeks Paid FMLA & Family Leave

11 paid holidays

Headspace (Meditation App)

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Sep 9th, 2026
Salesforce and F5 integrate AI security as both post 11% revenue growth

F5 and Salesforce announced an integration on 2 September, embedding F5 AI Guardrails into MuleSoft's Agent Fabric Omni Gateway. The partnership aims to address security risks in agentic AI deployments, including prompt injection and data leakage. F5 reported Q3 FY26 revenue of $865 million, up 11% year-over-year, with non-GAAP operating margin at 35.0%. Salesforce posted Q2 FY27 revenue of $11.3 billion, also up 11%, with non-GAAP operating margin of 34.1%. Salesforce raised full-year FY27 revenue guidance to $46.1 billion–$46.4 billion. Both companies operate at similar profitability levels. Salesforce leads in scale with $33.5 billion in cRPO backlog, whilst F5 benefits from specialised AI security positioning. Agentforce ARR grew 210% year-over-year, nearing $3.9 billion.

Associated Press
Sep 9th, 2026
F5 launches Workforce AI Security to govern employee AI use and agent actions

F5 announced the upcoming availability of F5 Workforce AI Security, an agentless offering within its AI Security Platform that provides visibility and policy control over workforce AI activity. The product addresses how employees delegate work to AI agents that can access enterprise systems and manipulate data using user permissions. According to F5's 2026 State of Application Strategy Report, 66% of organisations already permit AI to automatically adjust policies and configurations. The new offering will enable organisations to govern workforce AI use, understand identity and intent, control agent actions before execution, and enforce policy across browsers, coding agents, and other tools. F5 Workforce AI Security extends capabilities F5 introduced to its AI Security Platform in June and August 2026. The product will be generally available beginning October 2026.

VMblog
Sep 4th, 2026
F5 and MuleSoft, a Salesforce company, collaborate to deliver inline security and governance for Agent Fabric and agentic AI applications.

F5 and MuleSoft, a Salesforce company, collaborate to deliver inline security and governance for Agent Fabric and agentic AI applications. F5 announced a technology integration with MuleSoft, bringing F5 AI Guardrails - part of the F5 AI Security Platform - directly into Agent Fabric. As enterprises rapidly scale AI agents and large language model (LLM) applications, this native integration provides security and platform engineering teams with centralized policy enforcement, real-time protection against malicious prompts, and enhanced auditability without re-architecting or replacing the systems already in use. As organizations scale agentic AI capabilities, security teams face a growing governance gap and frequently lack visibility into agentic traffic. They risk exposure from prompt injection, harmful outputs, and sensitive data leakage. The joint integration federates F5's runtime AI security into Agent Fabric's Omni Gateway, enabling enterprises to enforce unified guardrail policies across all prompts and outputs moving through their agentic workflows. Eliminating the governance gap for agentic AI. Until now, organizations deploying Agent Fabric and seeking to leverage F5 AI Guardrails have faced a trade-off: either route LLM traffic through a separate F5 inspection layer, creating additional operational complexity and fragmented telemetry, or rely solely on native gateway controls without extending F5 AI Guardrails policies directly into their MuleSoft-managed workflows. By federating F5 AI Guardrails into Agent Fabric, enterprises gain: * Unified governance and zero double-proxy overhead: Policy management for AI traffic lives in a single control plane. Agent Fabric's Omni Gateway routes LLM calls directly to the F5 AI Guardrails Scan API, inspecting inbound prompts and outbound completions inline before models are invoked or responses returned. * Support for Agentforce ecosystems: Organizations can apply consistent runtime security controls across Agentforce-powered agents, Agent Fabric workflows, and custom AI applications. * Proactive threat mitigation: The solution is designed to block prompt injection, jailbreaks, toxicity, and unauthorized topics while reducing personally identifiable information (PII) and protected data exposure at runtime. * Data residency and sovereign control: Flexible dual-deployment topology allows self-hosted Kubernetes deployments including private VPCs, allowing sensitive prompt and completion data to remain within customer boundaries. * Low-touch policy tuning: Security teams author and version scanners, blocklists, and sensitivity thresholds within the F5 console, which Omni Gateway picks up dynamically without requiring policy or code changes. * SOC back-correlation and compliance auditability: Decisions carry detailed telemetry and shared scan IDs for seamless correlation in the F5 console, simplifying compliance with regulations such as the EU AI Act, GDPR, and HIPAA. "AI agents are moving from experiments into the critical path of the enterprise," said Kunal Anand, Chief Product Officer at F5. "The biggest risk in agentic AI is that agents will move faster than enterprise security and governance models can keep up. By integrating the F5 AI Security Platform directly into Agent Fabric, we are putting protection in the path of every prompt and response, where it can operate in real time. That lets organizations move faster with AI while preserving the control, visibility, and accountability their most important business processes demand." "We built Agent Fabric as the neutral solution to support enterprises running agents across a mix of models and platforms," said Andrew Comstock, SVP & GM at MuleSoft. "By extending Agent Fabric's existing LLM API and AI services to support F5 AI Guardrails as a first-class provider, we're making it even easier for customers to scale their agentic enterprise on the security tooling they know and trust." David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/

Associated Press
Sep 2nd, 2026
F5 and MuleSoft integrate AI security guardrails into Agent Fabric for enterprise agentic AI protection

F5 and MuleSoft have integrated F5 AI Guardrails into Agent Fabric to provide inline security for AI agent applications. The integration addresses growing security challenges as enterprises scale AI deployments, including risks from prompt injection, harmful outputs, and data leakage. The solution enables unified governance without requiring additional infrastructure. Agent Fabric's Omni Gateway routes calls directly to F5's Scan API, inspecting prompts and responses before model invocation. Security teams can manage policies centrally whilst maintaining data residency control through flexible deployment options. The integration supports Agentforce ecosystems and provides threat mitigation against jailbreaks and unauthorized data exposure. It includes compliance features for regulations including the EU AI Act, GDPR, and HIPAA. F5 AI Guardrails for Agent Fabric is now generally available. The companies will demonstrate the integration at Dreamforce in San Francisco from 15-17 September 2026.

Associated Press
Sep 1st, 2026
F5 launches AI-powered WAF with 98% threat detection and virtual patching in minutes

F5 has announced enhancements to its AI-powered web application firewall and virtual patching capabilities to combat faster cyber threats driven by frontier AI. The company's WAF for Distributed Cloud now features anomaly detection and agentic threat intelligence, built on technology from its Fletch acquisition. In internal testing, the solution achieved 98% threat detection efficacy whilst reducing false positives to 1%. The system uses real-time machine learning to assign risk scores to each request, defending against zero-day attacks and polymorphic exploits. The platform enables security teams to deploy virtual patches in minutes rather than weeks, giving organisations time to address vulnerabilities without forcing immediate code rewrites. New features include continuous traffic analysis, automated virtual patching, and enhanced infrastructure remediation workflows. The capabilities are now available on F5's Application Delivery and Security Platform.