
About Docker
Docker is trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across Docker Desktop, Docker Hub, and Docker Scout.
As a Senior Security Engineer, Offensive Security, you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths. You'll partner with engineering, product, and leadership to turn findings into durable fixes and shape how security is designed into every Docker product.
Responsibilities
- Support and implement key security programs such as automated security design reviews and vulnerability management.
- Partner with engineering to design and implement security architecture and controls across Docker products and platforms.
- Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker's products and services.
- Develop proof-of-concept exploits, produce clear risk-rated findings with actionable remediation guidance, and retest fixes.
- Build and maintain offensive security tooling and automation to expand testing coverage.
- Perform security reviews and threat modeling across Docker products and services, including emerging AI products.
- Participate in the rotating on-call schedule for security events, threat investigation, and incident response.
- Collaborate with cross-functional teams to promote security practices and education.
Qualifications
- 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
- 2+ years of hands-on development experience in Python or Golang.
- Deep expertise in authentication, authorization (OAuth), cryptography, and Zero Trust principles.
- Strong hands-on experience securing cloud ecosystems (AWS, GCP, Azure).
- Hands-on penetration testing experience across SaaS web applications and APIs.
- Proficiency with offensive tooling such as Burp Suite and OWASP frameworks.
- Understanding of AI/ML security risks and mitigations (prompt injection, model extraction).
- Hold offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
- Published CVEs, original security research, or conference talks are a plus.
Timezone overlap
UTC+0β+3
Benefits
Equity, PTO, Parental leave, Learning, Conferences, Wellness, Home office, Equipment, Health, Bonus, Visa
Open to
Europe
Sign in to track applications and earn points.