Senior Security Engineer, Offensive Security

Docker · England

RemoteWorkplace
1d agoPosted · Sep 9
AshbySource
$154ksecurity engineer median
Apply now Opens the original posting at Docker. PivotHop does not host applications.
Experience2+ years

Skills in this posting

Benefits

The posting

About Docker

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

_______________________________________________________________________

As a Senior Security Engineer, Offensive Security , you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and to shape how security is designed into every Docker product.

You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth.

This role offers the opportunity to help improve security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a fast-paced, technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem.

Responsibilities

Contribute to security initiatives that align with business goals, helping ensure security is a core component of our products and infrastructure

Support and help implement key security programs such as automated security design reviews, and vulnerability management

Build deep knowledge of software security and architecture, and act as a go-to resource for engineering teams

Partner with engineering to design and implement security architecture and controls across Docker products and platforms

Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker's products and services

Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure

Build and maintain offensive security tooling and automation to expand testing coverage and repeatability

Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits

Serve on rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts

Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices

Participate in Security Incident response

Qualifications

Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure

Possess 2+ years of hands-on development experience in Python or Golang

Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles.

Have strong hands-on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure)

Have hands-on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners

Are proficient with offensive tooling and techniques such as. Burp Suite, and OWASP frameworks

Can write security tests and develop exploits and proof-of-concepts that find real vulnerabilities in a product

Understand AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks

Have practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows

Have a track record of building security programs and automations from scratch, applying risk-based prioritization

Have experience performing security reviews and building or improving security review automation

Have excellent communication skills, allowing you to explain complex security concepts clearly to technical and non-technical stakeholders

Understand industry standards, and actively keep up with emerging security technologies and models

Are a team player who drives security change via collaboration and cross-functional partnerships

Hold offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO

Have published CVEs, original security research, or conference talks

Bonus if you

Have experience with container escape, Kubernetes attack paths, or cloud red teaming

Have experience testing AI/ML systems for issues like prompt injection, model extraction, and data poisoning

What to Expect

First 30 days

Meet with security team and key partners across engineering

Gain access to team owned systems, and internal documentation

Complete security awareness training and compliance onboarding

Review application architecture, tech stack and data flow

Review risk registry and annual roadmap

Familiarize oneself with team workflows and processes

Shadow a fellow security engineer during their on-call/secops rotations

First 90 days

Conduct security review on emerging Docker products

Scope and execute your first penetration test against a Docker product or service

Actively participate in architecture design reviews with the team

Contribute to a Security-owned project or initiative

Collaborate with Docker developers to validate and resolve discovered vulnerabilities

Enhance incident response capabilities by participating in on-call rotation and post-incident activities

Create and maintain security documentation and runbooks

First Year Outlook

Contribute to the security roadmap for improving security controls

Strengthen Zero Trust architecture and least privilege access controls

Enhance security monitoring and anomaly detection

Perform security reviews for major product releases

Own and run recurring penetration tests and adversary-emulation exercises across Docker products, and engage with external researchers

Support audits and ensure compliance with SOC 2, ISO 27xxx

Advocate for “security by design” in all product features

Become well versed in Docker products and emerging AI technologies

Docker does not offer visa sponsorship for this role.

Compensation & Equity

EU: €118,860 – €169,800+ equity

______________________________________________________________________

Posting Information

Open vacancy: This posting is for an existing open role.

AI in hiring: Docker may use AI-assisted tools during our recruiting process.

Interview recordings: Candidates will be invited to opt in to interview recordings to support interviewer calibration and consistent evaluations. Recordings are optional and require explicit consent.

The PivotHop read

Where these skills also reach

More security engineer roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves