Senior Security Engineer, Offensive Security

Docker · England

Senior Security Engineer, Offensive Security at Docker, based in England. This is a permanent role.

Salary
Competitive
Location
England
Contract
Permanent
Posted
10 hours ago
Closes
25 Sep 2026
Sector
Security Officer

Reference harvest:6183f08d6afbbcc10b784c4c0000006b

About the role

About Docker Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default. _______________________________________________________________________ As a Senior Security Engineer, Offensive Security , you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and to shape how security is designed into every Docker product. You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth. This role offers the opportunity to help improve security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a fast-paced, technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem. Responsibilities: Contribute to security initiatives that align with business goals, helping ensure security is a core component of our products and infrastructure Support and help implement key security programs such as automated security design reviews, and vulnerability management Build deep knowledge of software security and architecture, and act as a go-to resource for engineering teams Partner with engineering to design and implement security architecture and controls across Docker products and platforms Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker's products and services Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure Build and maintain offensive security tooling and automation to expand testing coverage and repeatability Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits Serve on rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices Participate in Security Incident response Qualifications Have 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure Possess 2+ years of hands-on development experience in Python or Golang Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles. Have strong hands-on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure) Have hands-on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners Are proficient with offensive tooling and techniques such as. Burp Suite, and OWASP frameworks Can write security tests and develop exploits and proof-of-concepts that find real vulnerabilities in a product Understand AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks Have practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows Have a track record of building security programs and automations from scratch, applying risk-based prioritization Have experience performing security reviews and building or improving security review automation Have excellent communication skills, allowing you to explain complex security concepts clearly to technical and non-technical stakeholders Understand industry standards, and actively keep up with emerging security technologies and models Are a team player who drives security change via collaboration and cross-functional partnerships Hold offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO Have published CVEs, original security resea…

Reference: harvest:6183f08d6afbbcc10b784c4c0000006b · Posted 10 hours ago · Closes 25 Sep 2026 · Listed via Docker

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via Docker. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary Competitive
Apply now