
Senior Security Engineer – Offensive Security
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in United Kingdom, +4 more countries.
• Lead offensive security efforts at Docker by conducting realistic adversarial testing on products, platforms, and cloud infrastructure.
• Collaborate with engineering, product, and leadership teams to transform findings into lasting solutions and integrate security within Docker products.
• Utilize penetration testing, threat modeling, and exploit development across Docker's products and infrastructure.
• Deploy proactive security measures in AWS, GCP, Azure, containerized environments, and AI/ML products.
• Contribute to security initiatives that align with business objectives.
• Establish automated security design reviews and vulnerability management programs.
• Act as a software security and architecture resource for engineering teams.
• Design and implement security architecture and controls throughout Docker products and platforms.
• Plan, scope, and conduct penetration tests along with red-team/adversary-emulation engagements.
• Develop proof-of-concept exploits and risk-rated findings, along with remediation guidance; retest fixes.
• Create and maintain offensive security tools and automation.
• Conduct security reviews and threat modeling of designs, architectures, and code, including emerging AI products.
• Write automated security tests and exploits.
• Engage in rotating on-call duties, investigate threats, respond to security incidents, and coordinate remediation efforts.
• Educate and work collaboratively with engineering and product teams.
• Take part in security incident response activities.
• Support audits and ensure compliance with SOC 2 and ISO 27xxx standards.
• Oversee recurring penetration tests and adversary-emulation exercises while engaging with external researchers.
• 3+ years of experience in security engineering, including practical offensive security and penetration testing across applications and infrastructure.
• 2+ years of hands-on development experience with Python or Golang.
• Extensive knowledge in authentication, authorization, OAuth, cryptography applications, and Zero Trust principles.
• Strong practical experience in securing cloud ecosystems such as AWS, GCP, and Azure.
• Hands-on penetration testing experience with SaaS web applications and APIs, including manual exploitation beyond automated tools.
• Proficiency with Burp Suite and OWASP frameworks.
• Capability to write security tests and develop exploits and proof-of-concepts.
• Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
• Practical experience utilizing LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows.
• Proven ability to build security programs and automations from the ground up using risk-based prioritization.
• Experience in conducting security reviews and enhancing or creating security review automation.
• Strong communication skills.
• Awareness of industry standards and emerging security technologies and models.
• Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
• Publication of CVEs, original security research, or presentations at conferences.
• Bonus: Experience with container escape, Kubernetes attack paths, or cloud red teaming.
• Bonus: Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning.
• Note: Visa sponsorship is not available for this position.
• Remote-first work from home.
• Flexible work schedule.
• Generous paid time off (PTO).
• Quarterly Whaleness Days.
• End-of-year Whaleness break.
• Home office support.
• Technology stipend equivalent to US$100 net per month.
• Annual learning and development stipend for conferences, courses, certifications, and ongoing education.
• 16 weeks of paid parental leave after six months of employment.
• Equity opportunities for all full-time employees.
• Comprehensive medical benefits.
• Retirement benefits.
• Paid holidays.
• Docker swag.
Agile Defense
Stripe
Guild Mortgage
Cambiar Education
Get handpicked remote jobs straight to your inbox weekly.