Senior Security Engineer, Privacy
Docker, Inc
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Overview
At Docker, Inc, we make app development easier so developers can focus on what matters. With a remote-first team that spans the globe and more than 20 million monthly users, Docker is the #1 tool for building, sharing, and running apps. Join us for a whale of a ride!
Role Summary
As a Senior Security Engineer, Privacy, you will serve as a trusted advisor at the intersection of security, privacy, and engineering. You will work closely with teams across security engineering, product, legal, and leadership to embed privacy-by-design and robust compliance frameworks into Docker’s products and infrastructure.
Responsibilities
- Embed privacy-by-design principles and align with ISO/IEC 27001, ISO/IEC 27701, SOC 2, and global privacy regulations.
- Collaborate with engineering and product teams to integrate privacy requirements into SDLC and CI/CD pipelines.
- Design, develop, and maintain automated workflows for risk management, compliance monitoring, and audit readiness.
- Implement and customize GRC and privacy tooling via APIs, scripting, and automation.
- Conduct risk assessments and data protection impact assessments (DPIAs), integrating findings into Docker’s risk register.
- Develop dashboards and metrics for real-time risk and compliance visibility.
- Support audits and provide automated evidence as a subject matter expert.
- Draft and maintain security, privacy policies, and standards aligned with regulatory frameworks.
- Educate teams on security, privacy, and compliance best practices.
Qualifications
6–8 years experience in IT, security engineering, GRC, or related roles. Proven experience in designing and automating GRC programs and privacy frameworks (GDPR, ISO/IEC 27701). Hands-on programming/scripting experience (Python or Golang) with cloud environments (AWS, Azure, GCP) and integration of security within SDLC and CI/CD pipelines. Strong ability to communicate complex technical concepts to varied audiences.
What to Expect
First 30 days: Learn Docker’s compliance landscape, meet key stakeholders, and review existing controls and policies.
First 90 days: Conduct risk assessments, map key compliance frameworks, and integrate privacy controls.
One-year Outlook: Lead compliance engineering, automate monitoring tools, support audit readiness and drive a culture of continuous security improvement.
Perks
- Flexible remote-first work culture.
- Home office setup and technology stipend.
- Paid parental leave, PTO, and training stipend.
- Equity participation and Docker swag.
- Comprehensive benefits including medical and retirement.
Key skills/competency
- Privacy-by-design
- Compliance
- GRC
- Risk assessment
- Automation
- Scripting
- Cloud
- SDLC integration
- Regulatory frameworks
- Security engineering
How to Get Hired at Docker, Inc
- Research Docker, Inc's culture: Study their mission and global impact.
- Customize your resume: Highlight privacy automation and compliance skills.
- Review job requirements: Emphasize GRC and risk assessment experience.
- Prepare for technical interviews: Brush up on scripting and cloud integrations.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background