Docker logo

Docker

Senior Security Engineer, Offensive Security

Region Restricted

Remote work allowed only within certain countries or regions.

Employer listed it 2 weeks ago · Found 10h ago

Been open since 2 weeks ago, still checked daily, but it has been live a while.

Salary

€118,860–€169,800

Location

Timezone

GMT

Contract

Full-time

Experience

Senior

Category

Software

Stated by the employer in the job description

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in United Kingdom, Portugal, Spain, Italy, Germany.

What the employer says

  • Source listing states candidate location: "England, Portugal, Spain, Italy, Germany, Remote"

What Nomaders makes of it

  • Applications outside the listed area are usually rejected
  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Docker

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

_______________________________________________________________________

As a Senior Security Engineer, Offensive Security , you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and to shape how security is designed into every Docker product.

You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth.

This role offers the opportunity to help improve security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a fast-paced, technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem.

Responsibilities:

Contribute to security initiatives that align with business goals, helping ensure security is a core component of our products and infrastructure

Support and help implement key security programs such as automated security design reviews, and vulnerability management

Build deep knowledge of software security and architecture, and act as a go-to resource for engineering teams

Partner with engineering to design and implement security architecture and controls across Docker products and platforms

Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker's products and services

Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure

Build and maintain offensive security tooling and automation to expand testing coverage and repeatability

Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits

Serve on rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts

Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices

Participate in Security Incident response

Qualifications

Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure

Possess 2+ years of hands-on development experience in Python or Golang

Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles.

Have strong hands-on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure)

Have hands-on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners

Requirements

  • ·Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure
  • ·Possess 2+ years of hands-on development experience in Python or Golang
  • ·Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles.
  • ·Have strong hands-on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure)
  • ·Have hands-on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners

Benefits

  • ·Remote-first by design – Work from your home, with offices in Seattle and Paris for connection and collaboration.
  • ·Flexibility that fits your life – We trust you to manage your schedule while delivering great work.
  • ·Time to recharge – Generous PTO, designated quarterly Whaleness Days, and a designated end-of-year Whaleness break.
  • ·Home office support – Set up your workspace for comfort and success.
  • ·Technology stipend – Equivalent to US$100 net per month to help support your work.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Docker, mentioning your remote working experience and working hours (GMT).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 10h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

€118,860–€169,800 · You'll be taken to the employer's careers page.