368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$114k – $234k per year (Estimated)
Location
Remote (United States, Canada)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Docker is a leading software platform that enables developers to build, share, and run applications inside lightweight, isolated containers. By packaging code together with all its dependencies, the technology ensures that applications run consistently across any computing environment - from local development machines to large-scale cloud infrastructure. The platform accelerates modern software development, simplifying microservices architecture, automated deployment pipelines, and cross-team collaboration.

About Docker

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

_______________________________________________________________________

The DHI Content team builds and maintains Docker Hardened Images: a catalogue of security-hardened system packages, container images and Helm charts designed to be minimal, up to date and safe to use in security-conscious and regulated environments.

This is a supply-chain and open-source maintainer role rather than a conventional backend engineering role. You will work across upstream OSS projects, package and image definitions, Helm charts, Kubernetes, integration tests, vulnerability remediation and the controls that prove content is ready to publish. The work is broad by design: customers should be able to select hardened packages and images and, where relevant, deploy them through hardened charts without the pieces drifting apart.

We are moving DHI content production towards a machine-first factory. Routine work should begin with a machine-produced change and pass through automated build, test, policy and review controls. Engineers add the most value by handling difficult ecosystems, making security judgements, improving standards and turning repeated human corrections into better tooling. You will use AI-assisted engineering extensively, but remain accountable for the evidence and quality behind every result.

As a Senior Supply Chain Security Engineer, you will own substantial content and improvement work from upstream discovery through release and ongoing maintenance. You will be expected to close the loop on customer and security outcomes, not only submit individual definition changes.

Success in This Role Looks Like

You will succeed by becoming a trusted end-to-end owner for hardened content. Within your first year, you should have delivered complex new or updated DHI content across packages, images and Helm charts, improved the factory or its quality gates, reduced recurring manual work and raised the capability of the engineers around you.

Responsibilities

  • Author and maintain definitions for hardened system packages and container images, including build steps, upstream tracking, multi-architecture support and reproducibility controls.

  • Adapt and maintain upstream Helm charts so they work correctly with DHI images under non-root, restricted and production-shaped Kubernetes security constraints.

  • Track upstream releases, semver patterns, monorepos, dependency chains and breaking changes, then make pragmatic decisions about when to update, patch, pin or deviate.

  • Triage and remediate vulnerabilities across OS packages, application dependencies, images and charts, including VEX and no-upstream-fix cases that require explicit security judgement.

  • Write and improve Go-based integration tests, validators and policy checks that prove packages, images and charts behave correctly in real environments.

  • Review human-authored and machine-authored pull requests against DHI standards, distinguish blocking issues from advice and give contributors a clear path forward.

  • Improve the DHI Factory by converting repeated work, review corrections and escaped defects into automation, tests, validators and reusable authoring patterns.

  • Help classify work into deterministic, specialist and judgement paths so people spend time where their expertise changes the outcome.

  • Partner with Product, Security, Support and customer-facing teams to turn demand and incidents into prioritised content and durable improvements.

  • Engage constructively with upstream maintainers when hardened deployment requirements expose issues or useful improvements.

  • Participate in the team's paid on-call rotation and drive learning from customer escalations, failed builds and content defects.

  • Communicate decisions, risks and progress clearly in a remote, async-first environment.

Qualifications

Required

  • Strong experience with containers, Linux and Kubernetes in production or production-shaped environments.

  • Practical experience reading, adapting or maintaining Helm charts and diagnosing how chart templates, values and workload security settings affect deployment behaviour.

  • Experience maintaining software you did not originate, such as Linux packages, container images, open-source integrations, charts or a comparable downstream distribution.

  • Strong YAML and configuration-review skills, including care for conventions, consistency and downstream impact across a large catalogue.

  • Working knowledge of container and Kubernetes security, including non-root execution, UID and GID, capabilities, filesystem restrictions, image layers and multi-architecture builds.

  • Practical programming ability in Go or a comparable language, sufficient to write and review integration tests, validators and content automation.

  • Experience tracking upstream releases and reasoning about semver, breaking changes, dependency graphs and reproducible builds.

  • A maintainer mindset: you catch drift, improve patterns for the next contributor and consider the effect of a change across many downstream consumers.

  • Familiarity with GitHub-heavy open-source workflows, including pull requests, review, release tracking and upstream contribution.

  • Comfort using AI-assisted engineering critically while retaining ownership of security assertions, test evidence and release quality.

  • A strong operational mindset and clear written and spoken communication suited to a remote, async-first company.

Helpful, but not required

  • Experience as a maintainer for Alpine, Debian, Fedora, Wolfi, Homebrew or another package ecosystem.

  • Helm chart authorship or meaningful contribution to an upstream chart.

  • Experience with SBOMs, VEX, SLSA, Sigstore, cosign, provenance or artefact signing.

  • Experience with apk, deb, rpm, Go modules, Maven or Gradle, npm, pip, Cargo or other dependency ecosystems.

  • Experience building automation for package, image or chart creation, validation and release.

  • Experience with FIPS, FedRAMP, PCI or other regulated and security-conscious environments.

What to Expect

First 30 Days

  • Build context on the DHI catalogue, its package, image and chart definitions, the DHI Factory and the team's definition of done.

  • Pair across both image and Helm chart work and ship a useful production change.

  • Learn the build, test, signing, publishing and vulnerability-remediation workflows.

  • Take part in reviews and an incident, escalation or failed-build learning session.

First 90 Days

  • Own a complex image and chart addition or update from upstream analysis through release.

  • Resolve a meaningful CVE, dependency or compatibility problem with clear evidence and customer impact in mind.

  • Improve at least one factory control, integration test, validator or reusable content pattern.

  • Review across artefact types and help another engineer take on a broader piece of work.

One Year Outlook (First Year)

  • Be a trusted senior owner across hardened packages, images and Helm charts.

  • Deliver material catalogue growth or quality improvements without increasing human effort linearly with demand.

  • Reduce recurring manual work by moving a class of changes into a proven automated path.

  • Improve DHI's security posture, content availability and release reliability for customers.

  • Raise review quality and grow the team's ability to work across artefact and dependency ecosystems.

Docker considers visa sponsorship on a case-by-case basis based on business needs.

Compensation & Equity

Canada: CA$210,627 - CA$341,690 + equity

United States: $154,600 - $250,800 + equity

______________________________________________________________________

Posting Information

  • Open vacancy: This posting is for an existing open role.

  • AI in hiring: Docker may use AI-assisted tools during our recruiting process.

  • Interview recordings: Candidates will be invited to opt in to interview recordings to support interviewer calibration and consistent evaluations. Recordings are optional and require explicit consent.

______________________________________________________________________

Perks & Benefits

  • Remote-first by design - Work from your home, with offices in Seattle and Paris for connection and collaboration.

  • Flexibility that fits your life - We trust you to manage your schedule while delivering great work.

  • Time to recharge - Generous PTO, designated quarterly Whaleness Days, and a designated end-of-year Whaleness break.

  • Home office support - Set up your workspace for comfort and success.

  • Technology stipend - Equivalent to US$100 net per month to help support your work.

  • Learning & development - Annual stipend for conferences, courses, certifications, and continued learning.

  • Parental leave - 16 weeks of paid parental leave after six months of employment.

  • Equity for all full-time employees - Share in Docker's long-term success as we continue to grow.

  • Comprehensive benefits - Medical, retirement, and paid holidays vary by country.

  • Docker swag - Because representing the whale never gets old.

Docker is proud to be an equal opportunity employer. We are committed to building a team that reflects a broad range of backgrounds, experiences, and perspectives. We believe diverse teams build better products, make better decisions, and better serve our global community.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$25k – $69k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru • Pune
Java
Python
AI/ML
AI Agents
AWS Bedrock
Fine-tuning
Google ADK
LangGraph
LLM
LoRA
RAG
Semantic Search
LangChain
PEFT
A2A
Amazon SageMaker
AWS Strands Agents
NIST AI RMF
Semantic Search
Model Context Protocol
DevOps
Amazon EC2
Amazon EKS
AWS
Azure
CI/CD
CloudFormation
Docker
GCP
Git
GitOps
gRPC
Kubernetes
OpenTelemetry
Rest API
Terraform
Vector
Amazon S3
IAM
GitLab
Apply
$23k – $61k per year (Estimated) • In office • Full-Time • Pune
Go
Java
SQL
Java
Spring Boot
Databases
PostgreSQL
DevOps
Amazon EC2
AWS
AWS Fargate
CI/CD
CloudFormation
Docker
Git
Jenkins
Kubernetes
Terraform
Amazon ECS
GitLab
Apply
$27k – $70k per year (Estimated) • In office • Full-Time • Pune
JavaScript
SQL
TypeScript
Java
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
Oracle
Frontend
Angular
React.js
DevOps
AWS
CI/CD
Docker
Git
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Veracode
QA
Selenium
Swagger
Apply
$34k – $82k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Java
Python
Python
Asyncio
FastAPI
Databases
Amazon Aurora
AI/ML
AWS Bedrock
Google ADK
LangChain
LangGraph
LLM
RAG
A2A
LLM Guardrails
AI Agents
Model Context Protocol
DevOps
Amazon EKS
AWS
Envoy
Kubernetes
API Gateway
IAM
Cybersecurity
Zero Trust
Apply
$25k – $68k per year (Estimated) • In office • Full-Time • Pune
Java
Java
Spring Boot
Frontend
GraphQL
DevOps
AWS
Azure
Azure DevOps
CI/CD
CloudFormation
Docker
GCP
Jenkins
Kubernetes
Shift-Left
Terraform
GitLab
Cybersecurity
Shift-Left Security
Zero Trust
Apply
$103k – $219k per year (Estimated) • Remote • Full-Time • 7+ years exp
AI/ML
AI Agents
LLM
Model Context Protocol
DevOps
Azure
Docker
Kubernetes
Cybersecurity
Okta
SBOM
Apply
$184k – $337k per year (Estimated) • Remote • Full-Time • 12+ years exp • Bachelor's Degree
AI/ML
AI Agents
DevOps
Docker
Web3
Rollup
Apply
$135k – $244k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Clojure
Go
Clojure
Datomic
Databases
Apache Kafka
Google Cloud Spanner
AI/ML
AI Agents
DevOps
Docker
GitHub Actions
GitHub
Cybersecurity
Cosign
Sigstore
SLSA
Apply
$134k – $255k per year (Estimated) • Remote • Full-Time
AI/ML
AI Agents
DevOps
AWS
Azure
Docker
GCP
Marketing
Salesforce
Apply
$147k – $288k per year (Estimated) • Remote • Full-Time • 10+ years exp
AI/ML
AI Agents
LLM
LLM Guardrails
DevOps
Amazon EKS
CI/CD
Docker
GitOps
Grafana
Kubernetes
OpenTelemetry
Progressive Delivery
Prometheus
Terraform
AWS
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.