--- title: 'Senior Security Engineer, Offensive Security at Docker' canonical: 'https://feeny.ai/job/senior-security-engineer-offensive-security-docker-united-kingdom-m0d6eyq75z3v' type: 'job' last_seen: '2026-09-11' --- # Senior Security Engineer, Offensive Security at Docker - **Company:** Docker - **Location:** United Kingdom - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-09-09 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/docker/2a2f7652-d832-4729-bb6e-84fe0aaf6892 ## Job description ## About Docker Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default. _______________________________________________________________________ As a Senior Security Engineer, Offensive Security, you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and to shape how security is designed into every Docker product. You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth. This role offers the opportunity to help improve security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a fast-paced, technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem. Responsibilities: - Contribute to security initiatives that align with business goals, helping ensure security is a core component of our products and infrastructure - Support and help implement key security programs such as automated security design reviews, and vulnerability management - Build deep knowledge of software security and architecture, and act as a go-to resource for engineering teams - Partner with engineering to design and implement security architecture and controls across Docker products and platforms - Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker's products and services - Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure - Build and maintain offensive security tooling and automation to expand testing coverage and repeatability - Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits - Serve on rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts - Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices - Participate in Security Incident response ## Qualifications - Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure - Possess 2+ years of hands-on development experience in Python or Golang - Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles. - Have strong hands-on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure) - Have hands-on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners - Are proficient with offensive tooling and techniques such as. Burp Suite, and OWASP frameworks - Can write security tests and develop exploits and proof-of-concepts that find real vulnerabilities in a product - Understand AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks - Have practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows - Have a track record of building security programs and automations from scratch, applying risk-based prioritization - Have experience performing security reviews and building or improving security review automation - Have excellent communication skills, allowing you to explain complex security concepts clearly to technical and non-technical stakeholders - Understand industry standards, and actively keep up with emerging security technologies and models - Are a team player who drives security change via collaboration and cross-functional partnerships - Hold offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO - Have published CVEs, original security research, or conference talks Bonus if you: - Have experience with container escape, Kubernetes attack paths, or cloud red teaming - Have experience testing AI/ML systems for issues like prompt injection, model extraction, and data poisoning What to Expect First 30 days: - Meet with security team and key partners across engineering - Gain access to team owned systems, and internal documentation - Complete security awareness training and compliance onboarding - Review application architecture, tech stack and data flow - Review risk registry and annual roadmap - Familiarize oneself with team workflows and processes - Shadow a fellow security engineer during their on-call/secops rotations First 90 days: - Conduct security review on emerging Docker products - Scope and execute your first penetration test against a Docker product or service - Actively participate in architecture design reviews with the team - Contribute to a Security-owned project or initiative - Collaborate with Docker developers to validate and resolve discovered vulnerabilities - Enhance incident response capabilities by participating in on-call rotation and post-incident activities - Create and maintain security documentation and runbooks First Year Outlook - Contribute to the security roadmap for improving security controls - Strengthen Zero Trust architecture and least privilege access controls - Enhance security monitoring and anomaly detection - Perform security reviews for major product releases - Own and run recurring penetration tests and adversary-emulation exercises across Docker products, and engage with external researchers - Support audits and ensure compliance with SOC 2, ISO 27xxx - Advocate for “security by design” in all product features - Become well versed in Docker products and emerging AI technologies Docker does not offer visa sponsorship for this role. ## Compensation & Equity EU: €118,860 – €169,800+ equity ______________________________________________________________________ Posting Information - Open vacancy: This posting is for an existing open role. - AI in hiring: Docker may use AI-assisted tools during our recruiting process. - Interview recordings: Candidates will be invited to opt in to interview recordings to support interviewer calibration and consistent evaluations. Recordings are optional and require explicit consent. ______________________________________________________________________ ## Perks & Benefits - Remote-first by design – Work from your home, with offices in Seattle and Paris for connection and collaboration. - Flexibility that fits your life – We trust you to manage your schedule while delivering great work. - Time to recharge – Generous PTO, designated quarterly Whaleness Days, and a designated end-of-year Whaleness break. - Home office support – Set up your workspace for comfort and success. - Technology stipend – Equivalent to US$100 net per month to help support your work. - Learning & development – Annual stipend for conferences, courses, certifications, and continued learning. - Parental leave – 16 weeks of paid parental leave after six months of employment. - Equity for all full-time employees – Share in Docker's long-term success as we continue to grow. - Comprehensive benefits – Medical, retirement, and paid holidays vary by country. - Docker swag – Because representing the whale never gets old. Docker is proud to be an equal opportunity employer. We are committed to building a team that reflects a broad range of backgrounds, experiences, and perspectives. We believe diverse teams build better products, make better decisions, and better serve our global community. ## #LI-REMOTE ## About Docker ## Company Overview - **One-liner**: Docker provides a suite of tools and platforms that enable developers to build, share, and run applications using containers, simplifying the entire software development lifecycle. - **Entity Type**: Private (Series C) - **Headquarters**: Palo Alto, California, USA - **Founded**: 2011 - **Founders**: Solomon Hykes, Sebastien Pahl, Kamel Founadi ## Core Business - **Primary Industry**: Developer Tools / DevOps / Containerization - **Target Customers**: B2B; primarily individual developers, small teams, and large enterprises (91% of the Fortune 100 run on Docker). - **Mission/Purpose**: "We simplify the lives of developers building world-changing apps." ## Products & Services - **[Docker Desktop](https://www.docker.com/products/docker-desktop/)**: A desktop application for building, running, and managing containers locally. It is the core product for individual developers and teams. (SaaS/Desktop App) - **[Docker Hub](https://hub.docker.com/)**: A cloud-based registry service for sharing container images, with over 20 billion pulls per month. (SaaS) - **[Docker Engine](https://www.docker.com/products/container-runtime/)**: The industry-standard container runtime that powers millions of containers worldwide. (Open Source/Infrastructure) - **[Docker Scout](https://www.docker.com/products/docker-scout/)**: A supply chain security tool that provides vulnerability analysis and remediation guidance for container images. (SaaS) - **[Docker Build Cloud](https://www.docker.com/products/build-cloud/)**: A cloud-based build service that accelerates image builds. (SaaS) ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed (private company) - **Key Metric (Funding)**: Total funding of ~$273M. The last round was a $105M Series C in March 2022, led by Bain Capital Ventures. - **Notable Investors/Partners**: Bain Capital Ventures, Benchmark, Insight Partners, Greylock, Tribe Capital, Google Cloud, AWS, Microsoft Azure. - **Growth Signals**: 20M+ developers actively use Docker products; 20B+ pulls per month on Docker Hub; 91% of the Fortune 100 run Docker; strong adoption of Docker Scout and Build Cloud. ## Competitive Advantages - **Massive Ecosystem & Community**: The de facto standard for containerization with an enormous user base and a vast library of pre-built images on Docker Hub. - **Developer Obsession**: Products are designed from the ground up for the developer experience, reducing friction in the "inner loop" of development. - **End-to-End Platform**: Covers the entire development lifecycle from local development (Desktop) to image sharing (Hub) to security (Scout) to production builds (Build Cloud). - **Enterprise Trust**: Widely adopted by the world's largest companies, providing a clear path from individual use to enterprise deployment. ## Strategic Focus - **Security & Supply Chain**: Deepening capabilities in software supply chain security with Docker Scout and integrating security earlier into the development workflow. - **Cloud Acceleration**: Expanding Docker Build Cloud and other cloud services to improve developer productivity and speed. - **Enterprise Adoption**: Strengthening features for large organizations, including admin controls, SSO, and compliance. - **AI/ML Workflows**: Simplifying the building and deployment of AI/ML applications using containers. ## Why Work Here - **Culture & Values**: Emphasizes "Humble Confidence," "Open Collaboration," and "Developer Obsession." They value transparency, autonomy, and respect. - **Remote-First**: Fully remote company with office hubs in Paris and Seattle. They embrace asynchronous work, flexible schedules, and trust employees to manage their work around their lives. - **Perks & Benefits**: 100% company-paid medical premiums for employees and dependents (US), flexible PTO, quarterly "Whaleness Days" (company-wide day off), generous parental leave, home office setup budget, monthly technology stipend, annual learning stipend, and equity. - **Engineering Culture**: Quarterly hackathons, a product used by millions, and a focus on data-driven decisions. The hiring process is designed to be transparent and equitable, typically taking 3-4 weeks. - **Diversity & Belonging**: Active Employee Resource Groups (ERGs) for Underrepresented Genders, DEIB, Mental Health, Caregivers, and Neurodivergent employees. ## Sources 1. [Docker About Page](https://www.docker.com/company/) 2. [Docker Careers Page](https://www.docker.com/careers/) 3. [Docker Hiring & Onboarding](https://www.docker.com/careers/hiring-onboarding/) 4. [Docker Benefits & Perks](https://www.docker.com/careers/benefits-and-perks/) 5. [Docker Homepage](https://www.docker.com/) ## Other roles at Docker - [Principal Solutions Architect, Professional Services (West Coast Preferred)](https://feeny.ai/job/principal-solutions-architect-professional-services-west-coast-preferred-docker-0nqcrx0yq1qa) — Canada - [Partner Sales Manager, Mid-Enterprise](https://feeny.ai/job/partner-sales-manager-mid-enterprise-docker-united-states-jn0vq1dwwxea) — United States - [Senior Director, Product Management](https://feeny.ai/job/senior-director-product-management-docker-seattle-aejfbzc9j20c) — Seattle, WA - [Office Manager](https://feeny.ai/job/office-manager-docker-seattle-vxhqmjgg76nx) — Seattle, WA - [Senior Marketing GTM Analytics Manager](https://feeny.ai/job/senior-marketing-gtm-analytics-manager-docker-canada-1bfxf8zp7twd) — Canada - [Senior Solutions Engineer, Mid-Enterprise](https://feeny.ai/job/senior-solutions-engineer-mid-enterprise-docker-canada-s2rb8sjekkv9) — Canada - [Partner Sales Manager (Central Preferred)](https://feeny.ai/job/partner-sales-manager-central-preferred-docker-united-states-2k01gzmxp2f9) — United States - [Account Executive, Strategic (EMEA)](https://feeny.ai/job/account-executive-strategic-emea-docker-united-kingdom-8cyppg5spqmd) — United Kingdom - [Senior Technical Account Manager](https://feeny.ai/job/senior-technical-account-manager-docker-canada-hwdn4a72tzb2) — Canada - [Principal GSI & SI Partnerships](https://feeny.ai/job/principal-gsi-si-partnerships-docker-united-states-3ae3s6gapf9f) — United States