Senior Security Engineer, Offensive Security
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Docker, trusted by over 20 million monthly users and 20 billion container image pulls, is a globally distributed, remote-first team building tools that define how software gets built and delivered. As AI agents redefine software development, Docker provides sandboxed environments, verified images, and secure infrastructure to make autonomous workflows trustworthy by default.
As a Senior Security Engineer, Offensive Security, you'll drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to uncover and eliminate attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and shape how security is designed into every Docker product.
You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth.
Responsibilities:
Contribute to security initiatives that align with business goals, ensuring security is a core component of our products and infrastructure.
Support and implement key security programs such as automated security design reviews and vulnerability management.
Build deep knowledge of software security and architecture, serving as a go-to resource for engineering teams.
Partner with engineering to design and implement security architecture and controls across Docker products and platforms.
Plan, scope, and execute penetration tests and red-team/adversary-emulation engagements against Docker's products and services.
Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure.
Build and maintain offensive security tooling and automation to expand testing coverage and repeatability.
Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits.
Serve on a rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts.
Educate and collaborate with cross-functional teams to promote security practices.
Participate in security incident response.
Qualifications:
Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
Possess 2+ years of hands-on development experience in Python or Golang.
Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications, and Zero Trust principles.
Have strong hands-on experience with securing cloud ecosystems (e.g., AWS, GCP, Azure).
Have hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.
Are proficient with offensive tooling and techniques such as Burp Suite and OWASP frameworks.
Can write security tests and develop exploits and proof-of-concepts that find real vulnerabilities in a product.
Understand AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
Have practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows.
Have a track record of building security programs and automations from scratch, applying risk-based prioritization.
Have experience performing security reviews and building or improving security review automation.
Have excellent communication skills, allowing you to explain complex security concepts clearly to technical and non-technical stakeholders.
Understand industry standards and actively keep up with emerging security technologies and models.
Are a team player who drives security change via collaboration and cross-functional partnerships.
Hold offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
Have published CVEs, original security research, or conference talks.
Bonus if you:
Have experience with container escape, Kubernetes attack paths, or cloud red teaming.
Have experience testing AI/ML systems for issues like prompt injection, model extraction, and data poisoning.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Docker
Explore Top Companies in this Space
LocalStack
Developer Tools / Cloud Computing / Enterprise Software
Biomapas
Environmental Science / Geospatial Technology / Research Tools / Sustainability
WaterAid
Nonprofit / Public Health / Development / Advocacy
BrandBastion
Technology / Digital Marketing / Brand Protection / Enterprise Software
Docker
View Company ProfileDocker is a pioneering enterprise software and developer tools company that fundamentally revolutionized how modern applications are built, shipped, and deployed. Founded in 2013, the company introduced the industry-standard containerization platform, shifting the global tech landscape away from heavy, resource-intensive virtual machines. Under the hood, Docker provides a comprehensive suite of tools—including Docker Desktop, Docker Engine, and Docker Hub—that allow developers to package applications with all of their dependencies into standardized, lightweight, and highly portable executable containers. This ensures that software runs identically across any environment, effectively eliminating the infamous "it works on my machine" problem. Their primary target audience spans individual software engineers, agile DevOps teams, and massive Fortune 500 enterprises transitioning to microservices and cloud-native architectures. What sets Docker apart in the massive cloud ecosystem is its incredibly passionate, community-driven developer base and its indispensable role as the foundational building block for modern CI/CD pipelines and container orchestration systems like Kubernetes.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.









