Senior Security Engineer, Offensive Security
Core
Drive offensive security at Docker by conducting penetration testing, threat modeling, and exploit development to secure products, platforms, and cloud infrastructure against adversarial attacks.
Role type
Senior IC offensive security engineer (penetration testing & red teaming)
Builds
Docker Desktop, Docker Hub, Docker Scout, and AI/ML products
Domain
Developer tooling, containerization, cloud infrastructure (AWS/GCP/Azure), and AI/ML security
Deliverable
production ML models | product features
Required skills
penetration testing, threat modeling, exploit development, authentication/authorization (OAuth, Zero Trust), cloud security (AWS/GCP/Azure), SaaS/API security, offensive tooling (Burp Suite, OWASP), AI/ML security (prompt injection, data poisoning, model extraction), LLM/agentic tooling automation, security program building, security review automation
Preferred skills
container escape, Kubernetes attack paths, cloud red teaming, AI/ML system testing, CVE publication, security research, conference talks
Technologies
Python, Golang, Burp Suite, OWASP frameworks, AWS, GCP, Azure, LLMs, agentic tooling
Responsibilities
Plan and execute penetration tests and red-team engagements; develop proof-of-concept exploits and remediation guidance; build offensive security tooling and automation; perform security reviews and threat modeling for products and AI features; respond to security incidents; educate cross-functional teams on security practices
Seniority
Senior, hands-on IC
