Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer (EMEA) image - Rise Careers
Job details

Senior Security Engineer (EMEA)

Docker is a remote first company with employees across Europe, APAC and the Americas that simplifies the lives of developers who are making world-changing apps.  We raised our Series C funding in March 2022 for $105M at a $2.1B valuation. We continued to see exponential revenue growth last year.  Join us for a whale of a ride!

As an experienced Security Engineer at Docker, you’ll be a trusted advisor, collaborating closely with engineering and product teams to ensure security is a cornerstone of every product.  You’ll partner with leadership to shape product strategy, advocate for strong security controls and influence future product iterations. By leveraging your deep industry knowledge, you’ll lead the charge in implementing secure architecture and design principles, ensuring early detection and prevention of vulnerabilities.  Your expertise in security assessments and penetration testing will help identify and mitigate potential threats, while your mentorship and training efforts will foster  a security-conscious culture. This is a unique opportunity to make a foundational impact on the security of an innovative, fast-growing company by building scalable, proactive solutions that protect both our platform and the customers who trust us.

Responsibilities:

  • As a Senior Security Engineer, you will play a pivotal role in the integration of security into our software development lifecycle, enhancing the security posture of our applications

  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing

  • Partner closely with engineering to drive security architecture and processes that implement security controls across our software and systems

  • Design and enforce security configurations in cloud environments (e.g. AWS), including IAM roles, security groups, and VPC segmentation

  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure

  • Maintain cloud and infrastructure security: AWS Security Hub, AWS IAM, AWS Key Management (KMS), OPA for Terraform

  • Take ownership, define strategy, and drive improvement for part so our security program such as threat modeling, secrets management, or container security

  • Plan and perform product security assessments including architecture review, threat modeling, code review, pen testing and general security consulting to proactively build security controls

  • Partner with detection and response to create new capabilities or respond to security events

  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure

  • Serve as a security subject matter expert for software security and architecture

  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices

  • Have the ability to participate in our incident response team on-call rotation

Qualifications:

  • Professional Experience: Have at least 5+ years of experience security engineering roles, with a focus on product security, infrastructure security, ideally in a cloud-first environment

  • Software Development Experience: 3+ years of experience developing in Python or Golang 

  • Secure Coding Principles: Have knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines

  • Identity Management: Understand, authentication, authorization, including technologies like OAuth, SAML, OIDC, MFA, cryptography applications and Zero Trust principals.

  • Cloud Security: Strong cloud expertise with hands-on experience in cloud ecosystems (e.g: AWS, GCP, or Azure)

  • Container Security: Knowledge on securing containerized environments: (Docker, Kubernetes) and implementing runtime security tools

  • Endpoint Security: Previous experience evolving and enforcing policies to assist co-workers in maintaining corporate and cloud security

  • Compliance knowledge: Familiar with data privacy and compliance regulations (e.g, SOC 2, ISO 27xxx, GDPR, CCPA, FIPS) aligning security initiatives 

  • Communication Skills: Ability to explain complex security concepts clearly to both technical and non-technical stakeholders developers, executives and non-technical stakeholders

  • Experience in startups or High-Growth Environments: have previous experience in a fast-growing startup where security processes and policies were built from the ground up.

What to expect in the first 30 days:

  • Meet with security team, engineering teams, and leadership

  • Gain access to security tools, logs, dashboards and internal documentation

  • Complete security awareness training and compliance onboarding

  • Review application architecture, tech stack and data flow

  • Identify key entry points, APIs, authentication flows and dependencies

  • Identify security controls already in place (SAST, DAST, container security, API security)

  • Evaluate cloud security posture (AWS, GCP, Azure)

What to expect in the first 90 days:

  • Conduct threat modeling for a critical feature or service

  • Perform secure code reviews for major product components

  • Work with developers to fix vulnerabilities from previous security audits

  • Enhance incident response capabilities by participating in on-call rotations and post-incident activities

  • Create and maintain security runbooks for handling security vulnerabilities or project initiatives 

What to expect in the first year:

  • Support long-term security roadmap for improving security controls

  • Strengthen Zero Trust architecture and least privilege access controls

  • Enhance AI-based security monitoring and anomaly detection

  • Perform quarterly security reviews for major product updates

  • Conduct a penetration test or engage with external researchers

  • Support audits and ensure compliance with SOC 2, ISO 27xxx

  • Advocate for “security by design” in all product features

  • Lead security awareness campaigns and company-wide security events

We use Covey as part of our hiring and / or promotional process for jobs in NYC and certain features may qualify it as an AEDT. As part of the evaluation process we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound on April 13, 2024.

Please see the independent bias audit report covering our use of Covey here.

Perks (for Full-Time Employees Only)

  • Freedom & flexibility; fit your work around your life

  • Home office setup; we want you comfortable while you work

  • 16 weeks of paid Parental leave

  • Technology stipend equivalent to $100 net/month

  • PTO plan that encourages you to take time to do the things you enjoy

  • Quarterly, company-wide hackathons

  • Training stipend for conferences, courses and classes

  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

  • Docker Swag

  • Medical benefits, retirement and holidays vary by country

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

Due to the remote nature of this role, we are unable to provide visa sponsorship.

#LI-REMOTE

What You Should Know About Senior Security Engineer (EMEA), Docker

Join Docker as a Senior Security Engineer and be part of a remote-first company that’s making the lives of developers easier across the globe! As a pivotal member of our team, you’ll get to work closely with engineering and product teams, ensuring that security is integrated into every aspect of our solutions. Your role will encompass advocating for robust security measures, implementing secure architectural designs, and mentoring fellow team members to cultivate a culture of security awareness. You’ll leverage your extensive experience in security assessments and penetration testing to identify vulnerabilities early on and address potential threats before they can impact our systems. Your insights will directly influence product strategy, aligning security goals with the company’s mission to deliver groundbreaking applications. With your background in cloud security and experience in a cloud-first environment, you’ll design and enforce security configurations, and assist in maintaining our cloud and infrastructure security posture. At Docker, you’ll not only enhance our security framework but also have a significant impact on the future of our products and the trust our customers place in us. If you’re excited about building scalable, proactive security solutions in a fast-paced, innovative environment, this opportunity is a perfect fit!

Frequently Asked Questions (FAQs) for Senior Security Engineer (EMEA) Role at Docker
What responsibilities does a Senior Security Engineer at Docker have?

As a Senior Security Engineer at Docker, you will play a crucial role in integrating security into the software development lifecycle. Your responsibilities will include embedding security best practices within the SDLC, collaborating closely with engineering teams, and driving the implementation of security controls across systems. You'll also design security configurations in cloud environments, establish monitoring for potential breaches, and conduct thorough security assessments to help identify and mitigate vulnerabilities.

Join Rise to see the full answer
What qualifications are required for the Senior Security Engineer role at Docker?

To qualify for the Senior Security Engineer position at Docker, candidates should have at least 5 years of experience in security engineering, particularly focusing on product and infrastructure security in cloud environments. You'll need a strong grasp of secure coding principles, cloud security practices, and experience with security testing tools. Additionally, familiarity with identity management technologies and compliance regulations is highly beneficial.

Join Rise to see the full answer
What can I expect during my first year as a Senior Security Engineer at Docker?

In your first year as a Senior Security Engineer at Docker, you can expect to actively contribute to strengthening our security framework. You will support and implement a long-term security roadmap, enhance our zero trust architecture, and conduct audits ensuring compliance with policies like SOC 2 and ISO 27xxx. You will also promote 'security by design' in product features and lead awareness campaigns to enrich the overall security culture within the company.

Join Rise to see the full answer
How does Docker support the growth and development of its Senior Security Engineers?

Docker is committed to the professional growth of its Senior Security Engineers by offering opportunities for continuous learning through conferences, courses, and training stipends. You’ll participate in quarterly hackathons to enhance your skills, and receive support while advocating for security best practices within your teams. Additionally, Docker provides a flexible and inclusive work environment where you can thrive.

Join Rise to see the full answer
What should I prepare for when interviewing for the Senior Security Engineer position at Docker?

When preparing for an interview for the Senior Security Engineer role at Docker, focus on showcasing your technical expertise in cloud and product security, as well as your ability to communicate complex concepts clearly. Be ready to discuss your experience with security assessments, secure coding practices, and your approach to fostering security in cross-functional teams. Highlight any previous experience in a high-growth or startup environment, as this can be valuable for the role.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer (EMEA)
Can you describe your experience with security assessments and how you conduct them?

In responding to this question, discuss specific methodologies you’ve used in conducting security assessments, such as architecture reviews and penetration tests. Highlight any tools or frameworks you utilize, and share examples of how your assessments have helped identify and rectify vulnerabilities in previous roles.

Join Rise to see the full answer
How do you integrate security best practices into the software development lifecycle?

Explain your understanding of secure coding principles and how you ensure that development teams adopt these practices. Discuss strategies for conducting security training, code reviews, and the implementation of security tools in CI/CD pipelines that you've successfully executed in the past.

Join Rise to see the full answer
What experience do you have with cloud security, particularly in AWS or other cloud platforms?

When answering, highlight your hands-on experience managing cloud security aspects and key services like AWS IAM, Security Hub, or any specific tools you’ve interacted with. Provide examples of how you have implemented security configurations and monitored cloud environments for compliance and risk management.

Join Rise to see the full answer
How do you stay updated on the latest security threats and trends?

Share the methods you use to stay informed about security trends, such as using industry publications, attending relevant conferences, and participating in online communities. Discuss any specific certifications or training that help keep your skills and knowledge current.

Join Rise to see the full answer
Can you give an example of a time you addressed a significant security incident?

Provide a detailed account of a security incident you handled, discussing the steps you took to investigate, mitigate, and remediate the situation. Emphasize any lessons learned and how this experience has influenced your approach to security in general.

Join Rise to see the full answer
What role does compliance play in your security engineering strategy?

Discuss your understanding of various compliance frameworks, such as SOC 2 or GDPR, and how they impact security engineering practices. You should be able to articulate the importance of aligning security initiatives with compliance objectives and the role that documentation and audits play in this process.

Join Rise to see the full answer
How have you contributed to fostering a security-conscious culture in your previous roles?

Describe the various methods you’ve implemented to promote security awareness within teams, such as workshops, training sessions, and the development of policies that encourage secure practices. Highlight successful initiatives that resulted in improved security awareness among team members.

Join Rise to see the full answer
What security tools have you utilized in your previous roles, and how have they improved security practices?

Here, you should mention specific security tools you’ve worked with, such as SAST, DAST, or monitoring solutions. Discuss how you've effectively integrated these tools into existing processes and how they’ve positively impacted the security posture of your previous organizations.

Join Rise to see the full answer
Can you walk us through your process for threat modeling?

Discuss the steps you take during threat modeling, including identifying assets, assessing threats and vulnerabilities, and determining the impact of potential risks. Share any frameworks or methodologies you follow to ensure a comprehensive approach to threat modeling.

Join Rise to see the full answer
How do you balance security needs with development speed in a fast-paced environment?

Intelligently address how you prioritize security without hindering development timelines. Talk about strategies such as integrating security checks within CI/CD processes, fostering collaboration between security and engineering teams, and understanding product requirements to find the right balance.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
KIHOMAC Hybrid No location specified
Posted 12 days ago

Join us as a Cybersecurity Tools Analyst to maintain operational security posture and enforce information systems security policies.

Photo of the Rise User

Be a vital part of Chino Valley Medical Center's team as an Application Analyst, focusing on enhancing healthcare applications and systems.

Photo of the Rise User
CVS Health Remote MD - Work from home
Posted 12 days ago

As a Senior LDAP Engineer, you'll play a crucial role in supporting LDAP systems at CVS Health, a leader in health solutions.

Photo of the Rise User
Posted 2 days ago

Join Hawk as an Information Security Officer and play a key role in safeguarding financial institutions against fraud and money laundering.

Ellement Consulting Remote No location specified
Posted 13 days ago

Join Ellement Consulting Group as an IT Generalist, where you'll provide essential support in a client-centric IT environment.

Photo of the Rise User
Posted 11 days ago

Join Peraton as a Technical Targeting Analyst and leverage your expertise to support critical national security missions.

Photo of the Rise User
Posted 5 days ago

Join T-Mobile as a Sr. Technical Solutions Engineer, where your expertise in networking and problem-solving will directly influence our customer satisfaction.

Photo of the Rise User
Posted 12 days ago

Join Peraton as a Technical Targeting Analyst, where you will support the Intelligence Community through complex technical data analysis.

Docker is an open platform for developers and system administrators to build, ship and run distributed applications. They are based in Palo Alto, California.

42 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager, US SLED at Dataminr
Photo of the Rise User
Someone from OH, Greenville just viewed Systems Engineer (Linux & Shell or Python scripting) at Visa
Photo of the Rise User
Someone from OH, Greenville just viewed Help Desk Technician - Youngstown at R.I.T.A.
Photo of the Rise User
Someone from OH, Mount Orab just viewed Backend Developer at G2i Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Product Marketing Manager at Cast & Crew
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager at Cast & Crew
o
Someone from OH, Cincinnati just viewed Administrative Assistant at osu
A
Someone from OH, Cincinnati just viewed Data Entry Clerk at Alphabe Insight Inc
Photo of the Rise User
Someone from OH, Cincinnati just viewed Machine Learning Engineer at Allstate
Photo of the Rise User
Someone from OH, Twinsburg just viewed Data Analyst/Power BI Developer at Datadog