> Markdown version of [/jobs/ext/1406972-lead-architect-application-security](https://www.wearedevelopers.com/jobs/ext/1406972-lead-architect-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Architect - Application Security - **Company:** F5 Networks, Inc. - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $297,600.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Botnet, Software as a Service, Cloud Computing, Cyber Security, DDoS Mitigation, Software Design Patterns, Federal Information Processing Standards (FIPS), Fraud Prevention and Detection, Machine Learning, Nginx, OAuth, OpenID, Open Web Application Security, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Software Engineering, WebSocket, Policy as Code, SSL Certificate Management, Cloud Platform System, Istio, Software Security, Mitre Att&ck, Kubernetes, Malware Detection, Api Design, Ddos, Grpc, Big Ip, Legacy Systems - **Published:** July 23, 2026 - **Apply:** https://ffive.wd5.myworkdayjobs.com/f5jobs/job/San-Jose/Lead-Architect---Application-Security_RP1037588-1 ## About the Role * 20+ years of experience in software and security architecture roles, with at least 10 years focused specifically on application-layer security. * Proven track record architecting complex security systems in domains such as WAAP, API security, DDoS mitigation, bot protection, and malware detection. * Deep understanding of L7 protocols (HTTP/2, HTTP/3, WebSockets, gRPC) and application security standards (OWASP Top 10, NIST, MITRE ATT&CK). * Strong technical understanding of TLS, certificate management, identity and access protocols (OAuth2, OIDC, SAML), and secure session management. * Familiarity with zero trust architectures, policy-as-code, multi-tenant SaaS designs, and runtime enforcement in container-based platforms (Kubernetes, Istio, Envoy). * Demonstrated ability to set architectural strategy across product boundaries and influence senior engineering and product leadership. * Experience designing and implementing distributed cloud solutions at scale. * Understanding of containers and orchestration technologies. * Broad understanding of coding and programming languages. * Extensive knowledge of the software development process and corresponding technologies. * Excellent understanding of design patterns and architectural styles. * Proficient knowledge of the operation and development designs of agile software. Strong soft skills, including attention to detail, problem-solving and communication skills. ## Description F5 is seeking a Senior Architect for Application Security to lead technical strategy and architecture across its entire security portfolio, including WAF, DDoS mitigation, AI Security, Bot Defense, API Security, TLS inspection, and identity-aware access. This role drives the evolution of F5's security services across SaaS, hardware, and cloud-native platforms, ensuring they are integrated, scalable, and secure-by-design. As a senior technical leader, you will unify architectural direction, modernize legacy systems, and represent F5's security vision in both internal strategy and external engagements. You will: * Define the cross-portfolio application security architecture strategy, covering hardware, software, and cloud-native solutions, and align it to F5's long-term business and technology vision. * Establish architectural principles, patterns, and roadmaps that guide how WAF, WAAP, API security, DDoS, identity, client-side protection, AI/ML-powered detection and response, and related capabilities are designed, integrated, and delivered. * Lead architectural modernization efforts to evolve monolithic or appliance-based capabilities into composable, API-driven services within a SaaS-native security control plane. * Influence the security posture and innovation roadmap across F5 Distributed Cloud Services, BIG-IP, NGINX, and future platform initiatives. * Champion architectural governance and threat modeling across teams to ensure scalability, observability, resiliency, and secure-by-default practices are institutionalized. * Drive cross-functional alignment across product, engineering, SRE, and infrastructure teams to ensure seamless and secure user experiences across hybrid, multicloud, and edge deployments. * Mentor a community of senior architects and engineers, raising the bar for application security talent across the company. * Represent F5's technical vision in customer briefings, industry forums, regulatory discussions, and analyst engagements, serving as a technical ambassador for application security innovation. Job Duties and Responsibilities: * Design and validate architecture for WAAP services, distributed DDoS protection layers, advanced bot mitigation pipelines, client fingerprinting, fraud prevention engines, and access-aware enforcement controls. * Develop and evangelize reusable security frameworks and patterns across the product portfolio. * Collaborate with detection teams and data scientists to integrate machine learning, heuristics, and behavior analysis engines into runtime defense systems. * Define telemetry, feedback loops, and attack modeling infrastructure to continuously improve detection fidelity and response agility. * Work across organizational boundaries to ensure integration of security across the portfolio. * Guide compliance, privacy, and regulatory alignment by ensuring architecture supports evolving standards such as FIPS, FedRAMP, NIST CSF, ISO 27001, GDPR, and OWASP. * Drive architectural reviews, design validations, and threat models to ensure operational, security, and scalability concerns are addressed early. * Planning, tracking and scheduling software deliverables. ## Related Videos - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)