FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Engineer – Offensive Security
Docker, IncSenior offensive security engineer protecting Docker’s container, cloud, and AI products. Conducting penetration tests, threat modeling, exploit development, and adversary emulation.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in offensive security, including penetration testing, threat modeling, and security architecture across cloud environments. Proficient in developing security solutions and automations while collaborating with engineering and product teams to enhance security measures.
Highest-signal resume keywords
Penetration TestingCloud Security (AWS, GCP, Azure)Python DevelopmentOffensive Security Certification (OSCP, OSWE, OSEP, GXPN, GPEN, CRTO)Security Architecture Design
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Penetration TestingThreat ModelingExploit DevelopmentSecurity AutomationSecurity Design ReviewsVulnerability ManagementSecurity TestingCloud Ecosystem SecurityAI/ML Security RisksContainer Security
Soft Skills
Excellent Communication SkillsCollaboration
Tools & Technologies
Burp SuiteOWASP FrameworksLLMsAgentic Tooling
Certifications & Qualifications
OSCPOSWEOSEPGXPNGPENCRTO
Industry Keywords
SOC 2ISO 27xxxZero Trust PrinciplesSaaS SecurityKubernetes Security
Tech Stack
Tools & technologiesAWSAzureCloudDockerGoGoogle Cloud PlatformKubernetesPython
About the role
Key responsibilities & impact- Drive offensive security at Docker through realistic adversarial testing of products, platforms, and cloud infrastructure
- Partner with engineering, product, and leadership to turn findings into durable fixes and embed security into Docker products
- Apply penetration testing, threat modeling, and exploit development across Docker products and infrastructure
- Implement proactive security solutions across AWS, GCP, Azure, containerized environments, and AI/ML products
- Contribute to security initiatives aligned with business goals
- Implement automated security design reviews and vulnerability management programs
- Serve as a software security and architecture resource for engineering teams
- Design and implement security architecture and controls across Docker products and platforms
- Plan, scope, and execute penetration tests and red-team/adversary-emulation engagements
- Develop proof-of-concept exploits and risk-rated findings with remediation guidance; retest fixes
- Build and maintain offensive security tooling and automation
- Perform security reviews and threat modeling of designs, architectures, and code, including emerging AI products
- Write automated security tests and exploits
- Participate in rotating on-call duties, investigate threats, respond to security events, and coordinate remediation
- Educate and collaborate with engineering and product teams
- Participate in security incident response
- Support audits and compliance with SOC 2 and ISO 27xxx
- Own recurring penetration tests and adversary-emulation exercises and engage with external researchers
Requirements
What you’ll need- 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure
- 2+ years of hands-on development experience in Python or Golang
- Deep expertise in authentication, authorization, OAuth, cryptography applications, and Zero Trust principles
- Strong hands-on experience securing cloud ecosystems such as AWS, GCP, and Azure
- Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners
- Proficiency with Burp Suite and OWASP frameworks
- Ability to write security tests and develop exploits and proof-of-concepts
- Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks
- Practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows
- Track record of building security programs and automations from scratch using risk-based prioritization
- Experience performing security reviews and building or improving security review automation
- Excellent communication skills
- Understanding of industry standards and emerging security technologies and models
- Offensive security certification such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO
- Published CVEs, original security research, or conference talks
- Experience with container escape, Kubernetes attack paths, or cloud red teaming is a bonus
- Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning is a bonus
- No visa sponsorship is offered for this role
Benefits
Comp & perks- Remote-first work from home
- Flexible schedule
- Generous PTO
- Quarterly Whaleness Days
- End-of-year Whaleness break
- Home office support
- Technology stipend equivalent to US$100 net per month
- Annual learning and development stipend for conferences, courses, certifications, and continued learning
- 16 weeks of paid parental leave after six months of employment
- Equity for all full-time employees
- Medical benefits
- Retirement benefits
- Paid holidays
- Docker swag