Senior Security Engineer, Offensive Security

Docker, Inc.

United Kingdom

Remote

EUR 90,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Docker is seeking a Senior Security Engineer, Offensive Security, to drive offensive security across Docker products and cloud infrastructure. You will lead penetration tests, threat modeling, and exploit development, partnering with engineering to implement durable fixes and secure architectures.

You'll work across AWS, GCP, Azure, AI/ML products, and containerized environments, building automated tests and repeatable security processes in a fast-paced environment.

Qualifications

  • 3+ years in security engineering, including hands-on offensive security and penetration testing across apps and infrastructure.
  • 2+ years of hands-on development experience in Python or Golang.
  • Deep expertise in authentication, authorization, including OAuth, cryptography, and Zero Trust.
  • Strong hands-on experience securing cloud ecosystems (AWS, GCP, Azure).
  • Penetration testing across SaaS web apps and APIs, including manual exploitation.
  • Proficient with offensive tooling and techniques such as Burp Suite and OWASP.
  • Ability to write security tests and develop exploits/PoCs that find real vulnerabilities.

Responsibilities

  • Contribute to security initiatives aligned with business goals; ensure security is a core product ingredient.
  • Plan, scope, and perform penetration tests and red-team / adversary-emulation engagements.
  • Develop exploitable PoCs and provide actionable remediation guidance.
  • Build and maintain offensive security tooling and automation to expand coverage.
  • Conduct threat modeling and security reviews across Docker products and AI initiatives.
  • Collaborate with engineering to design secure architecture and controls.

Skills

Security engineering
Penetration testing
Python or Go
OAuth & Zero Trust
Cloud security (AWS/GCP/Azure)
Exploitation & PoCs
Offensive tooling & OWASP

Tools

Burp Suite

Job description

About Docker

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world’s largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

_______________________________________________________________________

As a Senior Security Engineer, Offensive Security, you'll help drive offensive security at Docker, putting our products, platforms, and cloud infrastructure under realistic adversarial testing to surface and drive out attack paths before real adversaries find them. You'll partner with engineering, product, and leadership to turn findings into durable fixes and to shape how security is designed into every Docker product.

You'll apply your expertise in penetration testing, threat modeling, and exploit development to find and eliminate risks across Docker products and infrastructure. Working across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products, you'll implement proactive security solutions that scale with Docker's growth.

This role offers the opportunity to help improve security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a fast-paced, technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem.

Responsibilities:
  • Contribute to security initiatives that align with business goals, helping ensure security is a core component of our products and infrastructure

  • Support and help implement key security programs such as automated security design reviews, and vulnerability management

  • Build deep knowledge of software security and architecture, and act as a go-to resource for engineering teams

  • Partner with engineering to design and implement security architecture and controls across Docker products and platforms

  • Plan, scope, and execute penetration tests and red-team / adversary-emulation engagements against Docker’s products and services

  • Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance, then retest fixes to confirm closure

  • Build and maintain offensive security tooling and automation to expand testing coverage and repeatability

  • Perform security reviews and threat modeling (design, architecture, and code) across Docker products and services, including emerging AI products, and write automated security tests and exploits

  • Serve on rotating on-call schedule to respond to security events, investigate threats, and coordinate remediation efforts

  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices

  • Participate in Security Incident response

Qualifications
  • Have 3+ years in security engineering, including hands‑on offensive security and penetration testing across applications and infrastructure

  • Possess 2+ years of hands‑on development experience in Python or Golang

  • Demonstrate deep expertise in authentication, authorization, including technologies like OAuth, cryptography applications and Zero Trust principles.

  • Have strong hands‑on experience with securing cloud ecosystems (e.g. AWS, GCP, Azure)

  • Have hands‑on penetration testing experience across SaaS web applications and APIs., including manual exploitation beyond automated scanners

  • Are proficient with offensive tooling and techniques such as. Burp Suite, and OWASP frameworks

  • Can write security tests and develop exploits and proof‑of‑concepts that find real vulnerabilities in a

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote-First Senior Security Engineer: Offensive Security
Remote-First Senior Security Engineer: Offensive Security

Docker, Inc. • United Kingdom

Remote
EUR 90,000 - 130,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

DRW Holdings, LLC • Greater London

Hybrid
GBP 120,000 - 180,000
Secure Developer
Secure Developer

Coltech • Romsey

On-site
GBP 60,000 - 80,000
Opportunity to work on real-world endpoint security systems
Collaborative engineering environment focused on security-by-design
Senior Software Engineer - Secure Sandbox Runtime (Remote)
Senior Software Engineer - Secure Sandbox Runtime (Remote)

Docker, Inc. • Greater London

Hybrid
GBP 119,000 - 193,000
Remote-first by design
Flexible schedule
Generous PTO
+7
Senior Software Engineer, Sandboxes (EU or East Coast Preferred)
Senior Software Engineer, Sandboxes (EU or East Coast Preferred)

Docker, Inc. • Greater London

On-site
GBP 119,000 - 193,000
Remote-first by design
Flexible schedule
Generous PTO
+7
Senior Offensive Security Engineer
Senior Offensive Security Engineer

United States Digital Space LLC • Newcastle upon Tyne

On-site
GBP 70,000 - 110,000
Senior Go Engineer - Secure Build & CI Platform (Remote)
Senior Go Engineer - Secure Build & CI Platform (Remote)

Docker, Inc • United Kingdom

On-site
GBP 119,000 - 193,000
Remote-first culture
Generous PTO
Home office support
+2
Cloud Security Engineer
Cloud Security Engineer

La Fosse • Greater London

On-site
GBP 70,000 - 90,000
Cloud / PreSales Engineer - (AWS, Docker, Docker Swarm)
Cloud / PreSales Engineer - (AWS, Docker, Docker Swarm)

Mayflower Recruitment Ltd • United Kingdom

On-site
GBP 50,000 - 70,000
Devops Engineer
Devops Engineer

Glocomms • City Of London

On-site
GBP 50,000 - 80,000