Senior Security Engineer managing security for Docker Desktop. Collaborating with engineering and security teams to ensure product security and integrity.
Responsibilities
Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
Conduct threat modeling and security design reviews for new and evolving product features, with particular focus on authentication, authorization, and container runtime security.
Serve as the team's primary liaison to the organization's security group, attending security syncs, relaying guidance, and translating central policy into practical engineering decisions.
Act as the first point of contact for incoming vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation with the relevant engineers.
Review Go code with a security mindset, identifying classes of issues such as privilege escalation, insecure defaults, injection risks, and improper credential handling.
Contribute security-focused improvements directly to the codebase where appropriate.
Develop and maintain internal security documentation, guidelines, and runbooks for the team.
Stay current on the Linux security landscape as it pertains to containers: namespaces, cgroups, seccomp, AppArmor, capabilities, and the evolving OCI ecosystem.
Requirements
6+ years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level.
Strong proficiency in Go, with the ability to review and contribute to production-grade code.
Deep understanding of Linux fundamentals relevant to container security: namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
Solid grasp of OCI specifications and container runtime security (e.g. runc, containerd, BuildKit).
Hands-on experience with identity and access management concepts: OAuth 2.0, OIDC, token handling, and auth flows in desktop or cloud-adjacent contexts.
Experience performing security design reviews, threat modeling, and participating in secure development workflows.
Familiarity with vulnerability management processes: CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters.
Strong written and verbal communication skills; comfortable bridging the gap between a dedicated security team and a product engineering team.
Benefits
Freedom & flexibility; fit your work around your life
Designated quarterly Whaleness Days plus end of year Whaleness break
Home office setup; we want you comfortable while you work
16 weeks of paid Parental leave
Technology stipend equivalent to $100 net/month
PTO plan that encourages you to take time to do the things you enjoy
Training stipend for conferences, courses and classes
Equity; we are a growing start-up and want all employees to have a share in the success of the company
Docker Swag
Medical benefits, retirement and holidays vary by country
Remote-first culture, with offices in Seattle and Paris
IT & Security Specialist managing IT operations, security, and infrastructure for Senstar, a leader in security technology. Hands - on role blending end - user support, cybersecurity, and infrastructure management.
HR Systems Security Specialist responsible for design, configuration, and administration of security within Workday and SAP. Collaborating with HR and stakeholders to ensure effective access design and compliance.
Cybersecurity advisor working within the DCYB to develop IT security measures. Collaborating with teams to fortify cybersecurity posture and ensuring data protection for citizens.
Consultant in remuneration and occupational health and safety at the Quebec Federation of Municipalities. Ensuring employee needs match organizational requirements and promoting a safe work environment.
Cybersecurity Administrator providing operational support for compliance activities in information security. Assisting vendor risk management, audit coordination, and vulnerability tracking.
Sr. Manager leading cloud security, compliance, and governance at Metergy Solutions Inc. Drive regulatory adherence and risk mitigation across diverse cloud environments with a focus on security by design.
Security Advisor responsible for designing telecommunications network architectures at Alithya. Ensuring all components meet functional and non - functional requirements while adapting to new trends in the field.
Technical Lead in Cybersecurity Engineering at Morgan Stanley driving security initiatives. Collaborate with tech leaders to ensure enterprise - wide cybersecurity effectiveness and compliance in Montreal.
Cyber Security Intern supporting the operation of Capital Power’s cyber security infrastructure. Engaging in daily operational tasks, security reviews, and incident investigations.
Financial Security Advisor selling life and health insurance products and developing client relationships. Analyzing needs and recommending personalized financial solutions in a hybrid work setup.