Docker
Senior Supply Chain Security Engineer (East Coast Preferred)
Remote work allowed only within certain countries or regions.
Employer listed it 4 months ago · Added today
Been open since 4 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
$210,627 to $341,690
Location
Work style
Async
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in Canada, United States.
What the employer says
- Source listing states candidate location: "Canada, United States, Remote"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Docker
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
_______________________________________________________________________
The DHI Content team builds and maintains Docker Hardened Images: a catalogue of security-hardened system packages, container images and Helm charts designed to be minimal, up to date and safe to use in security-conscious and regulated environments.
This is a supply-chain and open-source maintainer role rather than a conventional backend engineering role. You will work across upstream OSS projects, package and image definitions, Helm charts, Kubernetes, integration tests, vulnerability remediation and the controls that prove content is ready to publish. The work is broad by design: customers should be able to select hardened packages and images and, where relevant, deploy them through hardened charts without the pieces drifting apart.
We are moving DHI content production towards a machine-first factory. Routine work should begin with a machine-produced change and pass through automated build, test, policy and review controls. Engineers add the most value by handling difficult ecosystems, making security judgements, improving standards and turning repeated human corrections into better tooling. You will use AI-assisted engineering extensively, but remain accountable for the evidence and quality behind every result.
As a Senior Supply Chain Security Engineer, you will own substantial content and improvement work from upstream discovery through release and ongoing maintenance. You will be expected to close the loop on customer and security outcomes, not only submit individual definition changes.
Success in This Role Looks Like
You will succeed by becoming a trusted end-to-end owner for hardened content. Within your first year, you should have delivered complex new or updated DHI content across packages, images and Helm charts, improved the factory or its quality gates, reduced recurring manual work and raised the capability of the engineers around you.
Responsibilities
Author and maintain definitions for hardened system packages and container images, including build steps, upstream tracking, multi-architecture support and reproducibility controls.
Adapt and maintain upstream Helm charts so they work correctly with DHI images under non-root, restricted and production-shaped Kubernetes security constraints.
Track upstream releases, semver patterns, monorepos, dependency chains and breaking changes, then make pragmatic decisions about when to update, patch, pin or deviate.
Triage and remediate vulnerabilities across OS packages, application dependencies, images and charts, including VEX and no-upstream-fix cases that require explicit security judgement.
Write and improve Go-based integration tests, validators and policy checks that prove packages, images and charts behave correctly in real environments.
Review human-authored and machine-authored pull requests against DHI standards, distinguish blocking issues from advice and give contributors a clear path forward.
Improve the DHI Factory by converting repeated work, review corrections and escaped defects into automation, tests, validators and reusable authoring patterns.
Help classify work into deterministic, specialist and judgement paths so people spend time where their expertise changes the outcome.
Partner with Product, Security, Support and customer-facing teams to turn demand and incidents into prioritised content and durable improvements.
Engage constructively with upstream maintainers when hardened deployment requirements expose issues or useful improvements.
Participate in the team's paid on-call rotation and drive learning from customer escalations, failed builds and content defects.
Communicate decisions, risks and progress clearly in a remote, async-first environment.
Qualifications
Required
Requirements
- ·Strong experience with containers, Linux and Kubernetes in production or production-shaped environments.
- ·Practical experience reading, adapting or maintaining Helm charts and diagnosing how chart templates, values and workload security settings affect deployment behaviour.
- ·Experience maintaining software you did not originate, such as Linux packages, container images, open-source integrations, charts or a comparable downstream distribution.
- ·Strong YAML and configuration-review skills, including care for conventions, consistency and downstream impact across a large catalogue.
- ·Working knowledge of container and Kubernetes security, including non-root execution, UID and GID, capabilities, filesystem restrictions, image layers and multi-architecture builds.
Benefits
- ·Remote-first by design – Work from your home, with offices in Seattle and Paris for connection and collaboration.
- ·Flexibility that fits your life – We trust you to manage your schedule while delivering great work.
- ·Time to recharge – Generous PTO, designated quarterly Whaleness Days, and a designated end-of-year Whaleness break.
- ·Home office support – Set up your workspace for comfort and success.
- ·Technology stipend – Equivalent to US$100 net per month to help support your work.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at Docker, mentioning your remote working experience and working hours (Async).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 13h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$210,627 to $341,690 · You'll be taken to the employer's careers page.