Auf einen Blick
- Aufgaben: Sichere die Docker Desktop-Plattform und arbeite an innovativen Sicherheitslösungen.
- Unternehmen: Docker, eine der beliebtesten Marken im Entwickler-Tooling.
- Vorteile: Flexible Arbeitszeiten, 16 Wochen bezahlter Elternurlaub und Weiterbildungsmöglichkeiten.
- Weitere Informationen: Dynamisches, remote-first Team mit großartigen Karrierechancen.
- Warum dieser Job: Gestalte die Sicherheit von Software, die von Millionen Entwicklern genutzt wird.
- Qualifikationen: Mindestens 6 Jahre Erfahrung in der Sicherheitsengineering und starke Go-Kenntnisse.
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.
We are a globally distributed, remote‑first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
As a Senior Security Engineer embedded in the Desktop engineering team, you will own the security posture of a complex, cross‑platform product that sits at the intersection of identity, OCI runtimes, and Linux kernel internals. You will be the team's primary security voice, reviewing features and code before they ship, partnering with our central security organization, and serving as the first line of triage for reported vulnerabilities.
This is a hands‑on engineering role for someone who thinks in threat models and communicates clearly with both product engineers and security specialists alike.
Responsibilities
- Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
- Conduct threat modeling and security design reviews for new and evolving product features, with particular focus on authentication, authorization, and container runtime security.
- Serve as the team's primary liaison to the organization's security group, attending security syncs, relaying guidance, and translating central policy into practical engineering decisions.
- Act as the first point of contact for incoming vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation with the relevant engineers.
- Review Go code with a security mindset, identifying classes of issues such as privilege escalation, insecure defaults, injection risks, and improper credential handling.
- Contribute security‑focused improvements directly to the codebase where appropriate.
- Develop and maintain internal security documentation, guidelines, and runbooks for the team.
- Stay current on the Linux security landscape as it pertains to containers: namespaces, cgroups, seccomp, AppArmor, capabilities, and the evolving OCI ecosystem.
Qualifications
- 6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Strong proficiency in Go, with the ability to review and contribute to production‑grade code.
- Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
- Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
- Hands‑on experience with identity and access management concepts: OAuth 2.0, OIDC, token handling, and auth flows in desktop or cloud‑adjacent contexts.
- Experience performing security design reviews, threat modeling, and participating in secure development workflows.
- Familiarity with vulnerability management processes: CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters.
- Strong written and verbal communication skills; comfortable bridging the gap between a dedicated security team and a product engineering team.
What To Expect
First 30 Days
You will onboard into the team and get hands‑on with the Docker Desktop codebase, architecture, and development workflow. You will meet your counterparts in the central security organization and learn how vulnerability reports are currently handled. The goal is to listen, ask questions, and build a clear picture of the product's current security posture, not to change anything yet.
First 90 Days
You will be an active participant in design and code reviews, bringing a security lens to features in flight. You will have taken ownership of the vulnerability intake process, handling your first end‑to‑end triage cycles with minimal guidance. You will have a working relationship with the engineers on the team and a growing sense of where the most meaningful security investments should be made.
One Year Outlook (First Year)
You will be the team's trusted authority on product security. You will have driven meaningful improvements to how the team approaches security across the development lifecycle, whether that's better threat‑modeling practices, improved auth flows, stronger container isolation defaults, or reduced time‑to‑remediation for reported issues. You will be a known presence in the broader security organization, and your work will be directly visible in the security and resilience of a product used by millions of developers every day.
Docker considers sponsorship on a case‑by‑case basis based on business needs.
Perks
- Freedom & flexibility; fit your work around your life
- Designated quarterly Whaleness Days plus end of year Whaleness break
- Home office setup; we want you comfortable while you work
- 16 weeks of paid Parental leave
- Technology stipend equivalent to $100 net/month
- PTO plan that encourages you to take time to do the things you enjoy
- Training stipend for conferences, courses and classes
- Equity; we are a growing start‑up and want all employees to have a share in the success of the company
- Docker Swag
- Medical benefits, retirement and holidays vary by country
- Remote‑first culture, with offices in Seattle and Paris
Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.
Compensation Range: €113,860 - €186,780
#J-18808-Ljbffr
Senior Security Engineer, Docker Desktop Arbeitgeber: Docker, Inc
Docker ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern Freiheit und Flexibilität bietet, um Arbeit und Leben in Einklang zu bringen. Mit einem remote-first Ansatz und einer Kultur, die Vielfalt und Inklusion schätzt, fördert Docker das persönliche Wachstum durch Schulungsstipendien und bietet attraktive Vorteile wie 16 Wochen bezahlten Elternurlaub sowie eine Beteiligung am Unternehmenserfolg. Hier haben Sie die Möglichkeit, an innovativen Sicherheitslösungen zu arbeiten und einen direkten Einfluss auf Produkte zu haben, die von Millionen von Entwicklern weltweit genutzt werden.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Senior Security Engineer, Docker Desktop erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Docker, Inc kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Docker, Inc zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Docker, Inc.
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Docker, Inc vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Docker, Inc könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Docker, Inc sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Docker, Inc auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!