Overview
The role of Senior Security Engineer, Offensive Security at Docker involves driving offensive security initiatives, testing products, platforms, and cloud infrastructure against realistic adversarial scenarios. As part of a globally distributed, remote-first team, the engineer will focus on enhancing security across Docker's offerings.
Key Responsibilities
- Contribute to security initiatives aligning with business goals and ensure security is integrated into products and infrastructure.
- Support and implement key security programs like automated security design reviews and vulnerability management.
- Act as a resource for engineering teams on software security and architecture.
- Design and implement security architecture and controls across Docker products.
- Conduct penetration tests and adversary-emulation engagements on Docker's products.
- Create proof-of-concept exploits with risk-rated findings and actionable remediation guidance.
- Build and maintain offensive security tooling for improved testing coverage.
- Perform security reviews and threat modeling across all Docker products.
- Educate teams on security practices and participate in incident response efforts.
Requirements
- 3+ years in security engineering, with offensive security and penetration testing experience.
- 2+ years of hands-on experience in Python or Golang development.
- Expertise in authentication, authorization, OAuth, cryptography, and Zero Trust principles.
- Experience securing cloud ecosystems such as AWS, GCP, and Azure.
- Proficiency with offensive tooling like Burp Suite and OWASP frameworks.
- Capabilities in writing security tests and developing exploits for existing vulnerabilities.
- Knowledge of AI/ML security risks and mitigation strategies.
- Strong communication skills for conveying complex security concepts to various stakeholders.
- Team-oriented mindset with a focus on cross-functional collaboration.
- Preferred certifications include OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
Benefits
- Remote-first culture with options to work from home and connect with offices in Seattle and Paris.
- Flexible schedule management for work-life balance.
- Generous PTO, quarterly wellness days, and an end-of-year break.
- Support for home office setup and a technology stipend.
- Annual learning and development stipend.
- 16 weeks of paid parental leave after six months of employment.
- Equity opportunities for all full-time employees.
- Comprehensive medical, retirement, and paid holiday benefits.
Location
Remote work available; no visa sponsorship.
How to Apply
Interested candidates should follow the application process provided by Docker.
Deadline
No specific deadline mentioned.