Docker
Senior Security Engineer, Docker Desktop
Remote work allowed only within certain countries or regions.
Employer listed it 5 months ago · Found 10h ago
Been open since 5 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
$271,150–$434,000
Location
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in Canada, United Kingdom, Portugal, Spain, Italy, Germany, United States.
What the employer says
- Source listing states candidate location: "Canada, England, Portugal, Spain, Italy, Germany, United States, Remote"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Docker
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
_______________________________________________________________________
As a Senior Security Engineer embedded in the Desktop engineering team, you will own the security posture of a complex, cross-platform product that sits at the intersection of identity, OCI runtimes, and Linux kernel internals. You will be the team's primary security voice, reviewing features and code before they ship, partnering with our central security organization, and serving as the first line of triage for reported vulnerabilities.
This is a hands-on engineering role for someone who thinks in threat models and communicates clearly with both product engineers and security specialists alike.
Responsibilities:
Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
Conduct threat modeling and security design reviews for new and evolving product features, with particular focus on authentication, authorization, and container runtime security.
Serve as the team's primary liaison to the organization's security group, attending security syncs, relaying guidance, and translating central policy into practical engineering decisions.
Act as the first point of contact for incoming vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation with the relevant engineers.
Review Go code with a security mindset, identifying classes of issues such as privilege escalation, insecure defaults, injection risks, and improper credential handling.
Contribute security-focused improvements directly to the codebase where appropriate.
Develop and maintain internal security documentation, guidelines, and runbooks for the team.
Stay current on the Linux security landscape as it pertains to containers: namespaces, cgroups, seccomp, AppArmor, capabilities, and the evolving OCI ecosystem.
This role may require participation in an on-call rotation to provide support outside of standard business hours, including evenings, weekends, and holidays, as needed.
Qualifications:
6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
Strong proficiency in Go, with the ability to review and contribute to production-grade code.
Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
Hands-on experience with identity and access management concepts: OAuth 2.0, OIDC, token handling, and auth flows in desktop or cloud-adjacent contexts.
Experience performing security design reviews, threat modeling, and participating in secure development workflows.
Familiarity with vulnerability management processes: CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters.
Requirements
- ·6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
- ·Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- ·Strong proficiency in Go, with the ability to review and contribute to production-grade code.
- ·Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
- ·Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
Benefits
- ·Remote-first by design – Work from your home, with offices in Seattle and Paris for connection and collaboration.
- ·Flexibility that fits your life – We trust you to manage your schedule while delivering great work.
- ·Time to recharge – Generous PTO, designated quarterly Whaleness Days, and a designated end-of-year Whaleness break.
- ·Home office support – Set up your workspace for comfort and success.
- ·Technology stipend – Equivalent to US$100 net per month to help support your work.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at Docker, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 10h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$271,150–$434,000 · You'll be taken to the employer's careers page.