
About Docker
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.
We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
About the Role
The DHI Content team builds and maintains Docker Hardened Images: a catalogue of security-hardened system packages, container images, and Helm charts designed to be minimal, up to date, and safe to use in security-conscious and regulated environments.
This is a supply-chain and open-source maintainer role rather than a conventional backend engineering role. You will work across upstream OSS projects, package and image definitions, Helm charts, Kubernetes, integration tests, vulnerability remediation, and the controls that prove content is ready to publish. The work is broad by design: customers should be able to select hardened packages and images and, where relevant, deploy them through hardened charts without the pieces drifting apart.
We are moving DHI content production towards a machine-first factory. As a Senior Supply Chain Security Engineer, you will own substantial content and improvement work from upstream discovery through release and ongoing maintenance, closing the loop on customer and security outcomes.
Responsibilities
- Author and maintain definitions for hardened system packages and container images, including build steps, upstream tracking, multi-architecture support, and reproducibility controls.
- Adapt and maintain upstream Helm charts so they work correctly with DHI images under non-root, restricted, and production-shaped Kubernetes security constraints.
- Track upstream releases, semver patterns, monorepos, dependency chains, and breaking changes, making pragmatic decisions about when to update, patch, pin, or deviate.
- Triage and remediate vulnerabilities across OS packages, application dependencies, images, and charts, including VEX and no-upstream-fix cases that require explicit security judgement.
- Write and improve Go-based integration tests, validators, and policy checks that prove packages, images, and charts behave correctly in real environments.
- Review human-authored and machine-authored pull requests against DHI standards, distinguish blocking issues from advice, and give contributors a clear path forward.
- Improve the DHI Factory by converting repeated work, review corrections, and escaped defects into automation, tests, validators, and reusable authoring patterns.
- Partner with Product, Security, Support, and customer-facing teams to turn demand and incidents into prioritised content and durable improvements.
- Engage constructively with upstream maintainers when hardened deployment requirements expose issues or useful improvements.
- Participate in the team's paid on-call rotation and drive learning from customer escalations, failed builds, and content defects.
- Communicate decisions, risks, and progress clearly in a remote, async-first environment.
Qualifications
Required
- Strong experience with containers, Linux, and Kubernetes in production or production-shaped environments.
- Practical experience reading, adapting, or maintaining Helm charts and diagnosing how chart templates, values, and workload security settings affect deployment behaviour.
- Experience maintaining software you did not originate, such as Linux packages, container images, open-source integrations, charts, or a comparable downstream distribution.
- Strong YAML and configuration-review skills, including care for conventions, consistency, and downstream impact across a large catalogue.
- Working knowledge of container and Kubernetes security, including non-root execution, UID/GID, capabilities, filesystem restrictions, image layers, and multi-architecture builds.
- Practical programming ability in Go or a comparable language, sufficient to write and review integration tests, validators, and content automation.
- Experience tracking upstream releases and reasoning about semver, breaking changes, dependency graphs, and reproducible builds.
- Maintainer mindset with familiarity in GitHub-heavy open-source workflows (pull requests, review, release tracking, and upstream contribution).
- Comfort using AI-assisted engineering critically while retaining ownership of security assertions, test evidence, and release quality.
- Clear written and spoken communication suited to a remote, async-first organization.
Helpful, but not required
- Experience as a maintainer for Alpine, Debian, Fedora, Wolfi, Homebrew, or another package ecosystem.
- Helm chart authorship or meaningful contribution to an upstream chart.
- Experience with SBOMs, VEX, SLSA, Sigstore, cosign, provenance, or artefact signing.
- Experience with apk, deb, rpm, Go modules, Maven, Gradle, npm, pip, Cargo, or other dependency ecosystems.
- Experience building automation for package, image, or chart creation, validation, and release.
- Experience with FIPS, FedRAMP, PCI, or other regulated and security-conscious environments.
Perks & Benefits
- Remote-first by design – Work from home, with offices in Seattle and Paris for connection and collaboration.
- Flexibility that fits your life – Manage your schedule while delivering great work.
- Time to recharge – Generous PTO, designated quarterly Whaleness Days, and an end-of-year Whaleness break.
- Home office support & Technology stipend – US$100 net per month to help support your home workspace.
- Learning & development – Annual stipend for conferences, courses, certifications, and continued learning.
- Parental leave – 16 weeks of paid parental leave after six months of employment.
- Equity & Comprehensive benefits – Equity grants, medical, retirement, and paid holidays vary by country.
- Visa sponsorship – Considered on a case-by-case basis based on business needs.
Timezone overlap
UTC-8–-4
Culture
Async-friendly
Benefits
Equity, PTO, Wellness, Home office, Internet, Learning, Conferences, Parental leave, Health, Pension, Visa
Open to
NA
Sign in to track applications and earn points.