Enter a job title or keyword

Security Detection Engineer III

F5 Networks


Job Location:

Warsaw - Poland

Monthly Salary: Not provided by the employer
Posted: 27 August 2026 (2 days ago)
Application Deadline: 24 November 2026
Vacancies: 1 Vacancy

Job Summary

At F5 we strive to bring a better digital world to life. Our teams empower organizations across the globe to create secure and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity from protecting consumers from fraud to enabling companies to focus on innovation.

Everything we do centers around people. That means we obsess over how to make the lives of our customers and their customers better. And it means we prioritize a diverse F5 community where each individual can thrive.

The Security Engineer III Detection Engineering is a career-level security engineering professional responsible for developing testing deploying and continuously improving detection capabilities that support Security Operations. As part of the Security Operations Platform Engineering (SOPE) team this role focuses on transforming threat intelligence telemetry and security requirements into reliable actionable detections that improve visibility and reduce organizational risk. The engineer partners closely with Incident Response Threat Intelligence Logging Engineering and platform engineering teams to build scalable threat-driven detection capabilities while advancing automation detection coverage and operational maturity.

Primary Responsibilities

  • Develop andmaintaincustom detections using Detection-as-Code practices including version control peer review testing and CI/CD deployment workflows.

  • Analyze and improvedetection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK frameworkidentifyinggaps and prioritizing enhancements.

  • Partner withIncident Response Threat Intelligence Logging Engineering and security platform teams to translate emerging threats investigations and telemetry into actionable detection content.

  • Validate and tunedetections through adversary emulation atomic testing purple-team exercises and production feedback to improve signal quality and reduce false positives.

  • Automate andoptimizedetectionengineering workflows alert enrichment processes and operational activities to improve efficiency and scalability.

  • Supportonboardingofnew log sources and security telemetry by collaborating with engineering and infrastructure teams toestablishdetection coverage across new environments and technologies.

  • Create andmaintaindetectiondocumentation runbooks coverage assessments and technical standards whileparticipatingin an engineering on-call rotation.

  • Help define detection strategy for AI and agentic systems (prompt injection tool and function abuse agent identity and credential misuse data exfiltration via model outputs) andexplore using AI to accelerate detection engineering workflows.

Required Skills / Qualifications

  • Bachelors degree in Information Security Computer Science Engineering or related field or equivalent practical experience.

  • 5 years of experience in cybersecurity security engineering detection engineering security operations threat hunting ora relateddiscipline.

  • Experience developing tuning ormaintainingdetections within a SIEM EDR log analytics or security monitoring platform.

  • Experience with scripting automation or data analysis using Python PowerShell SQL KQL SPL or similar technologies.

  • Strong understanding of attacker techniques detection methodologies and frameworks such as MITRE ATT&CK.

  • Strong analytical problem-solving communication and cross-functional collaboration skills.

Preferred Skills / Qualifications

  • Experience implementing Detection-as-Code practices including Git-based workflows automated testing and CI/CD pipelines.

  • Experiencewith adversary emulation atomic testing purple-team exercises or detection validation frameworks.

  • Experience performing detection coverage analysis and developing ATT&CK-based coverage roadmaps.

  • Experience onboarding log sources and building detections across cloud endpoint network identity or SaaS environments.

  • Experience with platforms such as CrowdStrike Splunk Microsoft Sentinel Chronicle Elastic or similar security technologies.

  • Familiarity with AI/LLM threat models (prompt injection tool and function abuse agent identity and credential misuse data exfiltration via model outputs) or frameworks such as MITRE ATLAS and the OWASP LLM Top 10 and interest in applying AI to accelerate detection engineering workflows.

Work Environment

This is a full-time engineering role and is not a shift-based position.Participation in an engineering on-call rotation isand may occasionally require support outside normal business hours during critical incidents platform outages or detection-related operational events. The Security Engineer III may be engaged as a subject matter expert during security incidents but is not responsible for primary incident response or SOC operations. Travel may beup to 5% including occasional international travel.

#LI-SS5

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However the description may not be all-inclusive and responsibilities and requirements are subject to change.

Please note that F5 only contacts candidates through F5 email address (ending with @) or auto email notification from Workday (ending with or @).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race religion color national origin sex sexual orientation gender identity or expression age sensory physical or mental disability marital status veteran or military status genetic information or any other classification protected by applicable local state or federal laws. This policy applies to all aspects of employment including but not limited to hiring job assignment compensation promotion benefits training discipline and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting .


Required Experience:

IC


About Company

Company Logo

F5 application services ensure that applications are always secure and perform the way they should—in any environment and on any device.

View Profile View Profile