Enable job alerts via email!

Senior Security Engineer (EMEA)

Docker

United Kingdom

Remote

USD 60,000 - 100,000

21 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative company is seeking a Senior Security Engineer to enhance the security of its software development lifecycle. This role involves collaborating with engineering teams to embed security practices, design secure cloud configurations, and conduct security assessments. You will lead initiatives that ensure robust security measures are in place, fostering a culture of security awareness. With a focus on proactive solutions, you'll play a crucial role in protecting the platform and its users. Join a dynamic environment that values flexibility and diversity, and make a significant impact in a fast-growing organization.

Benefits

Freedom & flexibility

Home office setup

16 weeks of paid Parental leave

Technology stipend

PTO plan

Quarterly hackathons

Training stipend

Equity

Docker Swag

Medical benefits

Qualifications

  • 5+ years in security engineering with focus on product and infrastructure security.
  • Experience with cloud environments like AWS, GCP, or Azure.
  • Knowledge of secure coding and security testing tools.

Responsibilities

  • Integrate security into the software development lifecycle.
  • Design security configurations in cloud environments.
  • Conduct security assessments and drive security initiatives.

Skills

Security Engineering

Python

Golang

Secure Coding Principles

Cloud Security

Container Security

Compliance Knowledge

Communication Skills

Education

Bachelor's Degree in Computer Science or related field

Tools

AWS Security Hub

SAST

DAST

Terraform

Job description

Docker is a remote first company with employees across Europe, APAC and the Americas that simplifies the lives of developers who are making world-changing apps. We raised our Series C funding in March 2022 for $105M at a $2.1B valuation. We continued to see exponential revenue growth last year. Join us for a whale of a ride!

As an experienced Security Engineer at Docker, you'll be a trusted advisor, collaborating closely with engineering and product teams to ensure security is a cornerstone of every product. You'll partner with leadership to shape product strategy, advocate for strong security controls and influence future product iterations. By leveraging your deep industry knowledge, you'll lead the charge in implementing secure architecture and design principles, ensuring early detection and prevention of vulnerabilities. Your expertise in security assessments and penetration testing will help identify and mitigate potential threats, while your mentorship and training efforts will foster a security-conscious culture. This is a unique opportunity to make a foundational impact on the security of an innovative, fast-growing company by building scalable, proactive solutions that protect both our platform and the customers who trust us.

Responsibilities:

  • As a Senior Security Engineer, you will play a pivotal role in the integration of security into our software development lifecycle, enhancing the security posture of our applications.
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing.
  • Partner closely with engineering to drive security architecture and processes that implement security controls across our software and systems.
  • Design and enforce security configurations in cloud environments (e.g. AWS), including IAM roles, security groups, and VPC segmentation.
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure.
  • Maintain cloud and infrastructure security: AWS Security Hub, AWS IAM, AWS Key Management (KMS), OPA for Terraform.
  • Take ownership, define strategy, and drive improvement for parts of our security program such as threat modeling, secrets management, or container security.
  • Plan and perform product security assessments including architecture review, threat modeling, code review, pen testing and general security consulting to proactively build security controls.
  • Partner with detection and response to create new capabilities or respond to security events.
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure.
  • Serve as a security subject matter expert for software security and architecture.
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices.
  • Have the ability to participate in our incident response team on-call rotation.

Qualifications:
  • Professional Experience: Have at least 5+ years of experience in security engineering roles, with a focus on product security, infrastructure security, ideally in a cloud-first environment.
  • Software Development Experience: 3+ years of experience developing in Python or Golang.
  • Secure Coding Principles: Have knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines.
  • Identity Management: Understand authentication, authorization, including technologies like OAuth, SAML, OIDC, MFA, cryptography applications and Zero Trust principles.
  • Cloud Security: Strong cloud expertise with hands-on experience in cloud ecosystems (e.g: AWS, GCP, or Azure).
  • Container Security: Knowledge on securing containerized environments (Docker, Kubernetes) and implementing runtime security tools.
  • Endpoint Security: Previous experience evolving and enforcing policies to assist co-workers in maintaining corporate and cloud security.
  • Compliance knowledge: Familiar with data privacy and compliance regulations (e.g, SOC 2, ISO 27xxx, GDPR, CCPA, FIPS) aligning security initiatives.
  • Communication Skills: Ability to explain complex security concepts clearly to both technical and non-technical stakeholders.
  • Experience in startups or High-Growth Environments: have previous experience in a fast-growing startup where security processes and policies were built from the ground up.

What to expect in the first 30 days:
  • Meet with security team, engineering teams, and leadership.
  • Gain access to security tools, logs, dashboards and internal documentation.
  • Complete security awareness training and compliance onboarding.
  • Review application architecture, tech stack and data flow.
  • Identify key entry points, APIs, authentication flows and dependencies.
  • Identify security controls already in place (SAST, DAST, container security, API security).
  • Evaluate cloud security posture (AWS, GCP, Azure).

What to expect in the first 90 days:
  • Conduct threat modeling for a critical feature or service.
  • Perform secure code reviews for major product components.
  • Work with developers to fix vulnerabilities from previous security audits.
  • Enhance incident response capabilities by participating in on-call rotations and post-incident activities.
  • Create and maintain security runbooks for handling security vulnerabilities or project initiatives.

What to expect in the first year:
  • Support long-term security roadmap for improving security controls.
  • Strengthen Zero Trust architecture and least privilege access controls.
  • Enhance AI-based security monitoring and anomaly detection.
  • Perform quarterly security reviews for major product updates.
  • Conduct a penetration test or engage with external researchers.
  • Support audits and ensure compliance with SOC 2, ISO 27xxx.
  • Advocate for "security by design" in all product features.
  • Lead security awareness campaigns and company-wide security events.

Perks (for Full-Time Employees Only)
  • Freedom & flexibility; fit your work around your life.
  • Home office setup; we want you comfortable while you work.
  • 16 weeks of paid Parental leave.
  • Technology stipend equivalent to $100 net/month.
  • PTO plan that encourages you to take time to do the things you enjoy.
  • Quarterly, company-wide hackathons.
  • Training stipend for conferences, courses and classes.
  • Equity; we are a growing start-up and want all employees to have a share in the success of the company.
  • Docker Swag.
  • Medical benefits, retirement and holidays vary by country.

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

Due to the remote nature of this role, we are unable to provide visa sponsorship.

#LI-REMOTE
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Infrastructure Engineer - Security Platforms

Only for registered members

Windsor

Remote

GBP 60.000 - 100.000

3 days ago
Be an early applicant

Security Engineer

Only for registered members

Greater London

Remote

GBP 60.000 - 100.000

Today
Be an early applicant

Senior Infrastructure Security Engineer - Cloud

Only for registered members

Remote

GBP 60.000 - 100.000

2 days ago
Be an early applicant

Cloud Security Engineer

Only for registered members

Remote

USD 60.000 - 100.000

3 days ago
Be an early applicant

Product/Applications Security Engineer

Only for registered members

Remote

GBP 45.000 - 85.000

5 days ago
Be an early applicant

Senior Security Engineer, Threat Detection and Response

Only for registered members

Remote

GBP 60.000 - 80.000

30+ days ago

Senior Staff Application Security Engineer

Only for registered members

Remote

GBP 80.000 - 100.000

30+ days ago

Senior Product Security Engineer

Only for registered members

London

On-site

GBP 60.000 - 100.000

3 days ago
Be an early applicant

Senior Security Engineer

Only for registered members

Welwyn Garden City

Hybrid

GBP 50.000 - 90.000

Today
Be an early applicant