Principal Software Engineer, Docker Hardened Images
Sets the technical direction for Docker Hardened Images, architecting secure image and Helm-chart delivery across the catalogue. The role requires 10+ years of backend and distributed-systems experience, deep Kubernetes and supply-chain security expertise, and strong cross-organizational technical influence.
About the job
Responsibilities
- Own the architecture for Docker Hardened Images (DHI) as a platform, including how images and Helm charts are authored, secured, distributed, and evolved.
- Define and drive multi-quarter technical roadmaps for container hardening, balancing upstream velocity, supply chain security, customer compliance, and catalogue scalability.
- Translate customer, operational, and upstream signals into catalogue-wide architectural changes.
- Align engineering, product, security, infrastructure, executives, and customer-facing teams on technical strategy, tradeoffs, and sequencing.
- Represent Docker in enterprise customer engagements, escalations, and upstream open-source communities.
- Set organization-wide standards for image definitions, Helm chart adaptation, hardening, and supply chain tooling.
- Solve complex packaging problems involving upstream dynamics, security tradeoffs, multi-architecture constraints, and customer impact.
- Shape integration-test infrastructure and developer tooling strategy.
- Mentor staff and senior engineers through design, review, and architectural leadership.
- Participate in the paid on-call rotation, respond to incidents, debug production issues, and improve reliability.
Requirements
- 10+ years of backend engineering experience, including production-grade distributed systems at scale.
- Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Ability to set multi-quarter roadmaps and align engineering, product, and executive stakeholders.
- Deep expertise in containers and Kubernetes, including ecosystems such as cert-manager, Kyverno, Grafana, and Istio.
- Mastery of container supply chain security concepts including provenance, attestations, SBOMs, signing, and SLSA.
- Strong software engineering fundamentals in code review, testing, source control, and CI/CD.
- Go proficiency sufficient to shape infrastructure and test-harness design.
- Track record of technical influence without authority across teams or organizations.
- Experience with upstream open-source communities and security-relevant technical direction.
- Ability to communicate complex technical strategy across remote, distributed teams and to technical and non-technical audiences.
Nice to Have
- Experience as a package maintainer for a Linux distribution, Homebrew, or a comparable ecosystem.
- Hands-on experience implementing or operationalizing Sigstore, SBOM, or SLSA tooling at organizational scale.
- Experience in regulated environments such as FedRAMP, FIPS, or PCI.
- Prior Principal or Distinguished individual-contributor experience on a platform, security, or developer-tools team.
- Experience engaging enterprise customers on container security architecture.
Compensation & Benefits
- Canada: CA$245,913–CA$397,139 plus equity.
- United States: $180,500–$291,500 plus equity.
- Remote-first culture with offices in Seattle and Paris.
- Flexible work arrangements and quarterly wellness days.
- Home office setup support.
- 16 weeks of paid parental leave after six months of employment.
- Technology stipend equivalent to $100 USD net per month.
- PTO plan, training stipend, equity, medical benefits, retirement benefits, holidays, and company swag; benefits vary by country.
Skills
Go, Kubernetes, Docker, Helm, Container Security, Sbom, Slsa, Sigstore, CI/CD, Distributed Systems, Linux, Kyverno, Istio, Grafana, Git
Similar jobs
Backend Engineering jobsFounding senior engineer responsible for creating and operating Payabli’s Payments Core infrastructure, including ledgers, exactly-once money movement, multi-rail orchestration, settlement, and reconciliation. Requires 12+ years of production payments or financial-systems experience at major scale.
Leads the architecture and phased delivery of Vanta’s enterprise organizational model, including multi-tenant structures, data isolation, permissions, and complex audit workflows. Requires 15+ years of backend engineering experience and a record of driving multi-quarter initiatives across teams.
Leads the architecture and phased delivery of an enterprise organizational model spanning tenancy, data isolation, permissions, audits, and residency requirements. Requires 15+ years of backend engineering experience and a record of driving complex initiatives across teams.
Leads technical vision, architecture, and V2 development of Redis Feature Store for large-scale ML infrastructure. Requires 8+ years backend experience, expertise in Python/Go/Rust, cloud platforms, and data tools; mentors team and engages enterprise customers.
Principal engineer responsible for the architecture, scalability, reliability, and long-term technical strategy of Fetch’s advertising platform. The role requires deep distributed-systems expertise, production experience with high-volume backend systems, and hands-on technical leadership across organizations.