Skip to content
DockerDocker

Senior Security Engineer, Docker Desktop

Owns the security posture of Docker Desktop through threat modeling, code and design reviews, vulnerability triage, and hands-on security improvements. The role requires senior security experience, strong Go proficiency, and deep knowledge of Linux and container runtime security.

About the job

Responsibilities

  • Partner with engineering and product teams throughout the development lifecycle to identify security risks early, from design review through code review and release.
  • Conduct threat modeling and security design reviews for new and evolving product features, focusing on authentication, authorization, and container runtime security.
  • Serve as the primary liaison to the central security organization, translating policy into practical engineering decisions.
  • Act as the first point of contact for vulnerability reports and CVEs: validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation.
  • Review Go code for privilege escalation, insecure defaults, injection risks, and improper credential handling.
  • Contribute security-focused improvements directly to the codebase.
  • Develop and maintain internal security documentation, guidelines, and runbooks.
  • Stay current on Linux security for containers, including namespaces, cgroups, seccomp, AppArmor, capabilities, and the OCI ecosystem.
  • Participate in an on-call rotation as needed, including evenings, weekends, and holidays.

Requirements

  • 6+ years of experience in security engineering, application security, or a closely related discipline, with experience at a senior or staff level.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Strong proficiency in Go and the ability to review and contribute to production-grade code.
  • Deep understanding of Linux fundamentals relevant to container security, including namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries.
  • Strong understanding of OCI specifications and container runtime security, including runc, containerd, and BuildKit.
  • Hands-on experience with identity and access management concepts, including OAuth 2.0, OIDC, token handling, and authentication flows.
  • Experience with security design reviews, threat modeling, and secure development workflows.
  • Familiarity with vulnerability management, CVE triage, CVSS scoring, coordinated disclosure, and external reporters.
  • Strong written and verbal communication skills.

Compensation & Equity

  • Canada: CA$271,150–CA$434,000 + equity
  • United States: $194,150–$312,950 + equity
  • EU: €113,860–€186,780 + equity

Benefits

  • Flexible remote-first work
  • Quarterly Whaleness Days and an end-of-year Whaleness break
  • Home office setup
  • 16 weeks of paid parental leave after 6 months of employment
  • Technology stipend equivalent to $100 USD net per month
  • PTO plan
  • Training stipend for conferences, courses, and classes
  • Equity participation
  • Medical benefits, retirement, and holidays varying by country

Skills

Go, Linux, Docker Desktop, Oci, Runc, Containerd, Buildkit, Oauth 2.0, OIDC, Threat Modeling, Cvss, Seccomp, Apparmor, Selinux

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Anthropic

Anthropic

San Francisco, CA
Platform Security Engineer, DRTM / Secure Launch
$320k+/yrHybrid8+ YOESecurity Engineering

Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.