Lead Architect – Application Security

F5 - San Jose, CA

Hiring: Lead Architect – Application Security Company: F5 Location: San Jose, CA Job Posted Time: 2026-09-10 13:30:23 Employment Type: Hybrid Target Skills & Keywords : Agile, DDoS, Envoy, FedRAMP, GDPR, HTTP/2, HTTP/3, Istio, Kubernetes, Machine Learning, Nginx, OAuth2, OIDC, OWASP, SAML, SaaS, TLS, User Experience, WAF, WebSocket, Workday, Zero Trust, gRPC About the job Experience: •20+ years of experience in software and security architecture roles, with at least 10 years focused specifically on application-layer security. •At least 10 years focused specifically on application-layer security. Required Skills: •Define the cross-portfolio application security architecture strategy, covering hardware, software, and cloud-native solutions, and align it to F5’s long-term business and technology vision. •Establish architectural principles, patterns, and roadmaps that guide how WAF, WAAP, API security, DDoS, identity, client-side protection, AI/ML-powered detection and response, and related capabilities are designed, integrated, and delivered. •Lead architectural modernization efforts to evolve monolithic or appliance-based capabilities into composable, API-driven services within a SaaS-native security control plane. •Influence the security posture and innovation roadmap across F5 Distributed Cloud Services, BIG-IP, NGINX, and future platform initiatives. •Champion architectural governance and threat modeling across teams to ensure scalability, observability, resiliency, and secure-by-default practices are institutionalized. •Drive cross-functional alignment across product, engineering, SRE, and infrastructure teams to ensure seamless and secure user experiences across hybrid, multicloud, and edge deployments. •Mentor a community of senior architects and engineers, raising the bar for application security talent across the company. •Represent F5’s technical vision in customer briefings, industry forums, regulatory discussions, and analyst engagements, serving as a technical ambassador for application security innovation. Qualifications: •Proven track record architecting complex security systems in domains such as WAAP, API security, DDoS mitigation, bot protection, and malware detection. •Comprehensive expertise in L7 protocols (HTTP/2, HTTP/3, WebSockets, gRPC) and application security standards (OWASP Top 10, NIST, MITRE ATT&CK). •Strong technical understanding of TLS, certificate management, identity and access protocols (OAuth2, OIDC, SAML), and secure session management. •Operational familiarity with zero trust architectures, policy-as-code, multi-tenant SaaS designs, and runtime enforcement in container-based platforms (Kubernetes, Istio, Envoy). •Demonstrated ability to set architectural strategy across product boundaries and influence senior engineering and product leadership. •Understanding of containers and orchestration technologies. •Broad understanding of coding and programming languages. •Extensive knowledge of the software development process and corresponding technologies. •Excellent understanding of design patterns and architectural styles. •Proficient knowledge of the operation and development designs of agile software. Compensation: •$297,600 - $446,400 / year •You may also be offered incentive compensation, bonus, restricted stock units, and benefits Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!