Docker, Inc

Docker, Inc

Senior Security Engineer, Docker Desktop

Canada · Senior

Sponsorship not specifiedDetected 85 days ago
GoCode ReviewDockerLinuxOAuthAgentic AICybersecurityCommunicationMicrosoft Office

About the role

  • Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls.
  • As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
  • You will be the team's primary security voice, reviewing features and code before they ship, partnering with our central security organization, and serving as the first line of triage for reported vulnerabilities.

Responsibilities

  • Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
  • Conduct threat modeling and security design reviews for new and evolving product features, with particular focus on authentication, authorization, and container runtime security.
  • Act as the first point of contact for incoming vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation with the relevant engineers.
  • Develop and maintain internal security documentation, guidelines, and runbooks for the team.
  • This role may require participation in an on-call rotation to provide support outside of standard business hours, including evenings, weekends, and holidays, as needed.
  • We are committed to building a team that represents a variety of backgrounds, perspectives, and skills.

Requirements

  • 6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Strong proficiency in Go, with the ability to review and contribute to production-grade code.
  • Hands-on experience with identity and access management concepts: OAuth 2.0, OIDC, token handling, and auth flows in desktop or cloud-adjacent contexts.
  • Familiarity with vulnerability management processes: CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters.
  • we want you comfortable while you work
  • Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
  • Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
  • Experience performing security design reviews, threat modeling, and participating in secure development workflows.
  • Strong written and verbal communication skills
  • comfortable bridging the gap between a dedicated security team and a product engineering team.
  • FIRST 30 DAYS
  • You will onboard into the team and get hands-on with the Docker Desktop codebase, architecture, and development workflow. You will meet your counterparts in the central security organization and learn how vulnerability reports are currently handled. The goal is to listen, ask questions, and build a clear picture of the product's current security posture, not to change anything yet.
  • FIRST 90 DAYS

Nice to have

  • Designated quarterly Whaleness Days plus end of year Whaleness break

Compensation

  • Technology stipend equivalent to $100 USD net/month

Benefits

  • Home office setup
  • 16 weeks of paid Parental leave (after 6 months of employment)
  • Technology stipend equivalent to $100 USD net/month
  • PTO plan that encourages you to take time to do the things you enjoy
  • Training stipend for conferences, courses and classes
  • Medical benefits, retirement and holidays vary by country
  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

Company info

  • we are a growing start-up and want all employees to have a share in the success of the company
  • The more inclusive we are, the better our company will be.

Equal opportunity

  • equal opportunity.

Visa & Work Authorization

  • Docker considers visa sponsorship on a case-by-case basis based on business needs.

This listing is sourced directly from Docker, Inc's careers page and normalized into a canonical job model.