Senior Security Engineer – Offensive Security

Posted 13 hours ago

This is a fully remote position, open to applicants in United Kingdom, +4 more countries.

📋 Description

• Lead offensive security efforts at Docker by conducting realistic adversarial testing on products, platforms, and cloud infrastructure.

• Collaborate with engineering, product, and leadership teams to transform findings into lasting solutions and integrate security within Docker products.

• Utilize penetration testing, threat modeling, and exploit development across Docker's products and infrastructure.

• Deploy proactive security measures in AWS, GCP, Azure, containerized environments, and AI/ML products.

• Contribute to security initiatives that align with business objectives.

• Establish automated security design reviews and vulnerability management programs.

• Act as a software security and architecture resource for engineering teams.

• Design and implement security architecture and controls throughout Docker products and platforms.

• Plan, scope, and conduct penetration tests along with red-team/adversary-emulation engagements.

• Develop proof-of-concept exploits and risk-rated findings, along with remediation guidance; retest fixes.

• Create and maintain offensive security tools and automation.

• Conduct security reviews and threat modeling of designs, architectures, and code, including emerging AI products.

• Write automated security tests and exploits.

• Engage in rotating on-call duties, investigate threats, respond to security incidents, and coordinate remediation efforts.

• Educate and work collaboratively with engineering and product teams.

• Take part in security incident response activities.

• Support audits and ensure compliance with SOC 2 and ISO 27xxx standards.

• Oversee recurring penetration tests and adversary-emulation exercises while engaging with external researchers.


⛳️ Requirements

• 3+ years of experience in security engineering, including practical offensive security and penetration testing across applications and infrastructure.

• 2+ years of hands-on development experience with Python or Golang.

• Extensive knowledge in authentication, authorization, OAuth, cryptography applications, and Zero Trust principles.

• Strong practical experience in securing cloud ecosystems such as AWS, GCP, and Azure.

• Hands-on penetration testing experience with SaaS web applications and APIs, including manual exploitation beyond automated tools.

• Proficiency with Burp Suite and OWASP frameworks.

• Capability to write security tests and develop exploits and proof-of-concepts.

• Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.

• Practical experience utilizing LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows.

• Proven ability to build security programs and automations from the ground up using risk-based prioritization.

• Experience in conducting security reviews and enhancing or creating security review automation.

• Strong communication skills.

• Awareness of industry standards and emerging security technologies and models.

• Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.

• Publication of CVEs, original security research, or presentations at conferences.

• Bonus: Experience with container escape, Kubernetes attack paths, or cloud red teaming.

• Bonus: Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning.

• Note: Visa sponsorship is not available for this position.


🏝️ Benefits

• Remote-first work from home.

• Flexible work schedule.

• Generous paid time off (PTO).

• Quarterly Whaleness Days.

• End-of-year Whaleness break.

• Home office support.

• Technology stipend equivalent to US$100 net per month.

• Annual learning and development stipend for conferences, courses, certifications, and ongoing education.

• 16 weeks of paid parental leave after six months of employment.

• Equity opportunities for all full-time employees.

• Comprehensive medical benefits.

• Retirement benefits.

• Paid holidays.

• Docker swag.

People also viewed

Agile Defense8 hours ago

Senior Security Architect

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$150k – $155k/year
ApplyView job
Stripe9 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Guild Mortgage10 hours ago

Third-Party Security Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$94.9k – $136.1k/year
ApplyView job
Cambiar Education13 hours ago

Director, IT – Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $170k/year
ApplyView job
OpenZeppelin13 hours ago

Head of Information Security

Anywhere in the WorldFull-timeCybersecurity / Security Engineer
ApplyView job
Motive13 hours ago

Red Team Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$146k – C$190k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers