Senior Security Engineer, Offensive Security @Docker

    8 days ago·Docker is hiring a remote Senior Security Engineer, Offensive Security·📍 England

    Overview

    The role of Senior Security Engineer, Offensive Security at Docker involves driving offensive security initiatives, testing products, platforms, and cloud infrastructure against realistic adversarial scenarios. As part of a globally distributed, remote-first team, the engineer will focus on enhancing security across Docker's offerings.

    Key Responsibilities

    • Contribute to security initiatives aligning with business goals and ensure security is integrated into products and infrastructure.
    • Support and implement key security programs like automated security design reviews and vulnerability management.
    • Act as a resource for engineering teams on software security and architecture.
    • Design and implement security architecture and controls across Docker products.
    • Conduct penetration tests and adversary-emulation engagements on Docker's products.
    • Create proof-of-concept exploits with risk-rated findings and actionable remediation guidance.
    • Build and maintain offensive security tooling for improved testing coverage.
    • Perform security reviews and threat modeling across all Docker products.
    • Educate teams on security practices and participate in incident response efforts.

    Requirements

    • 3+ years in security engineering, with offensive security and penetration testing experience.
    • 2+ years of hands-on experience in Python or Golang development.
    • Expertise in authentication, authorization, OAuth, cryptography, and Zero Trust principles.
    • Experience securing cloud ecosystems such as AWS, GCP, and Azure.
    • Proficiency with offensive tooling like Burp Suite and OWASP frameworks.
    • Capabilities in writing security tests and developing exploits for existing vulnerabilities.
    • Knowledge of AI/ML security risks and mitigation strategies.
    • Strong communication skills for conveying complex security concepts to various stakeholders.
    • Team-oriented mindset with a focus on cross-functional collaboration.
    • Preferred certifications include OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.

    Benefits

    • Remote-first culture with options to work from home and connect with offices in Seattle and Paris.
    • Flexible schedule management for work-life balance.
    • Generous PTO, quarterly wellness days, and an end-of-year break.
    • Support for home office setup and a technology stipend.
    • Annual learning and development stipend.
    • 16 weeks of paid parental leave after six months of employment.
    • Equity opportunities for all full-time employees.
    • Comprehensive medical, retirement, and paid holiday benefits.

    Location

    Remote work available; no visa sponsorship.

    How to Apply

    Interested candidates should follow the application process provided by Docker.

    Deadline

    No specific deadline mentioned.

    Get jobs in your inbox

    Join over 10,000 subscribers receiving our weekly newsletter.