PitchMeAI
Docker, Inc

Senior Security Engineer, Docker Desktop

Docker, Inc · United States

  • Hybrid
  • Full-time
  • CA$434,000 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Own security for Docker Desktop product.
  • Review code and features for security.
  • Handle vulnerability reports and triage.
  • Work with Linux and container security.
  • Remote-first, flexible work environment.

About the role

About Docker

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

About the Role

As a Senior Security Engineer embedded in the Desktop engineering team, you will own the security posture of a complex, cross-platform product that sits at the intersection of identity, OCI runtimes, and Linux kernel internals. You will be the team's primary security voice, reviewing features and code before they ship, partnering with our central security organization, and serving as the first line of triage for reported vulnerabilities. This is a hands-on engineering role for someone who thinks in threat models and communicates clearly with both product engineers and security specialists alike.

Responsibilities

  • Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
  • Conduct threat modeling and security design reviews for new and evolving product features, with particular focus on authentication, authorization, and container runtime security.
  • Serve as the team's primary liaison to the organization's security group, attending security syncs, relaying guidance, and translating central policy into practical engineering decisions.
  • Act as the first point of contact for incoming vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation with the relevant engineers.
  • Review Go code with a security mindset, identifying classes of issues such as privilege escalation, insecure defaults, injection risks, and improper credential handling.
  • Contribute security-focused improvements directly to the codebase where appropriate.
  • Develop and maintain internal security documentation, guidelines, and runbooks for the team.
  • Stay current on the Linux security landscape as it pertains to containers: namespaces, cgroups, seccomp, AppArmor, capabilities, and the evolving OCI ecosystem.
  • This role may require participation in an on-call rotation to provide support outside of standard business hours, including evenings, weekends, and holidays, as needed.

Qualifications

  • 6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Strong proficiency in Go, with the ability to review and contribute to production-grade code.
  • Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
  • Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
  • Hands-on experience with identity and access management concepts: OAuth 2.0, OIDC, token handling, and auth flows in desktop or cloud-adjacent contexts.
  • Experience performing security design reviews, threat modeling, and participating in secure development workflows.
  • Familiarity with vulnerability management processes: CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters.
  • Strong written and verbal communication skills; comfortable bridging the gap between a dedicated security team and a product engineering team.

What To Expect

First 30 Days
You will onboard into the team and get hands-on with the Docker Desktop codebase, architecture, and development workflow. You will meet your counterparts in the central security organization and learn how vulnerability reports are currently handled. The goal is to listen, ask questions, and build a clear picture of the product's current security posture, not to change anything yet.
First 90 Days
You will be an active participant in design and code reviews, bringing a security lens to features in flight. You will have taken ownership of the vulnerability intake process, handling your first end-to-end triage cycles with minimal guidance. You will have a working relationship with the engineers on the team and a growing sense of where the most meaningful security investments should be made.
One Year Outlook (First Year)
You will be the team's trusted authority on product security. You will have driven meaningful improvements to how the team approaches security across the development lifecycle, whether that's better threat modeling practices, improved auth flows, stronger container isolation defaults, or reduced time-to-remediation for reported issues. you will be a known presence in the broader security organization, and your work will be directly visible in the security and resilience of a product used by millions of developers every day.

Perks

  • Freedom & flexibility; fit your work around your life
  • Designated quarterly Whaleness Days plus end of year Whaleness break
  • Home office setup; we want you comfortable while you work
  • 16 weeks of paid Parental leave (after 6 months of employment)
  • Technology stipend equivalent to $100 USD net/month
  • PTO plan that encourages you to take time to do the things you enjoy
  • Training stipend for conferences, courses and classes
  • Equity; we are a growing start-up and want all employees to have a share in the success of the company
  • Docker Swag
  • Medical benefits, retirement and holidays vary by country
  • Remote-first culture, with offices in Seattle and Paris

Key skills/competency

  • Senior Security Engineer
  • Docker Desktop
  • Application Security
  • Go Programming Language
  • Linux Security
  • Container Security
  • Threat Modeling
  • Vulnerability Management
  • Identity and Access Management
  • OCI Specifications

Skills & topics

  • Senior Security Engineer
  • Application Security
  • Go
  • Linux
  • Containers
  • Docker Desktop
  • Threat Modeling
  • Vulnerability Management
  • IAM
  • OCI

How to get hired

  • Tailor your resume: Highlight your 6+ years of security engineering experience, Go proficiency, and Linux/container security expertise.
  • Showcase relevant projects: Detail your experience with threat modeling, security design reviews, and vulnerability management.
  • Prepare for technical questions: Be ready to discuss Go code, Linux fundamentals, OCI specs, and IAM concepts.
  • Demonstrate communication skills: Emphasize your ability to bridge the gap between engineering and security teams.
  • Research Docker's culture: Understand their remote-first approach and commitment to developer tooling innovation.

Technical preparation

Practice Go code reviews for security flaws.,Review Linux container security concepts thoroughly.,Understand OCI specs and runtime security.,Prepare IAM scenarios and solutions.

Behavioral questions

Describe a complex security risk you identified.,How do you collaborate with non-security engineers?,Tell me about a vulnerability you triaged.,How do you stay updated on security trends?

Frequently asked questions

What is the compensation range for the Senior Security Engineer role at Docker?
The compensation range for the Senior Security Engineer position at Docker is CA$271,150 - CA$434,000 annually. This range reflects the experience and responsibilities associated with a senior-level role in a high-demand field.
Is this Senior Security Engineer position remote or on-site at Docker?
This Senior Security Engineer role is a remote-first position. Docker embraces a remote-first culture, with offices in Seattle and Paris, allowing for flexibility in where you work.
What programming languages are most important for the Senior Security Engineer role at Docker?
Strong proficiency in Go is a key requirement for this Senior Security Engineer role. You will be expected to review and contribute to Go code with a security mindset.
What are the key technical areas for the Senior Security Engineer at Docker?
Key technical areas include deep understanding of Linux fundamentals for container security (namespaces, cgroups, seccomp), OCI specifications, container runtime security, and identity and access management (OAuth 2.0, OIDC).
What is the expected career growth for a Senior Security Engineer at Docker?
Within the first year, you are expected to become the team's trusted authority on product security, driving meaningful improvements and being a known presence in the broader security organization.
Does Docker offer visa sponsorship for the Senior Security Engineer position?
Docker considers visa sponsorship on a case-by-case basis, depending on business needs for the Senior Security Engineer role.
What kind of security responsibilities does a Senior Security Engineer have at Docker?
Responsibilities include partnering with engineering teams on security risks, conducting threat modeling, reviewing code, triaging vulnerabilities, and contributing to security improvements in the codebase.
How does Docker support employee well-being and professional development?
Docker offers perks like flexible work arrangements, dedicated 'Whaleness Days', home office setup, parental leave, technology and training stipends, and encourages PTO.