SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer, Offensive Security

Docker - Remote - Remote - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Docker is seeking a Senior Security Engineer focused on offensive security to drive proactive security testing across its products, platforms, and cloud infrastructure. You'll conduct penetration tests, red-team exercises, and threat modeling to surface attack paths before adversaries do, then partner with engineering and product teams to implement durable fixes. Key responsibilities include planning and executing penetration tests and adversary-emulation engagements against Docker products and services; developing proof-of-concept exploits with clear, risk-rated findings and actionable remediation guidance; building and maintaining offensive security tooling and automation to expand testing coverage; performing security reviews and threat modeling across Docker's product suite, including emerging AI products; writing automated security tests and exploits; serving on a rotating on-call schedule for security incident response; and educating cross-functional teams on security best practices. You'll work across cloud infrastructure (AWS, GCP, Azure), containerized environments, and AI/ML products. The role requires 3+ years in security engineering with hands-on offensive security and penetration testing experience, plus 2+ years of development experience in Python or Golang. You should have deep expertise in authentication, authorization (OAuth, cryptography, Zero Trust), cloud security, and hands-on penetration testing of SaaS applications and APIs beyond automated scanners. Experience with offensive tooling (Burp Suite, OWASP frameworks), security test development, and exploit creation is essential. Understanding of AI/ML security risks (prompt injection, data poisoning, model extraction, adversarial attacks) and practical experience using LLMs and agentic tooling for vulnerability discovery and pentesting workflows are required. You should have a track record of building security programs and automations from scratch with risk-based prioritization, experience performing security reviews and building review automation, and excellent communication skills for explaining complex concepts to technical and non-technical stakeholders. Offensive security certifications (OSCP, OSWE, OSEP, GXPN, GPEN, CRTO) and published CVEs, security research, or conference talks are preferred. Container escape, Kubernetes attack paths, and cloud red teaming experience are bonuses.

Similar roles