Full-Time

Senior Security Engineer

Privacy, Eastern Time Zone Preferred

Posted on 1/21/2026

Docker

Docker

1,001-5,000 employees

Containerization platform for building apps

No salary listed

No H1B Sponsorship

Remote in USA + 6 more

More locations: Remote in Canada | Remote in UK | Remote in Germany | Remote in Spain | Remote in Italy | Remote in France

Remote

Remote-first role; no visa sponsorship; offices in Seattle and Paris.

Category
IT & Security (1)
Required Skills
Kubernetes
Microsoft Azure
Python
Docker
Vulnerability Analysis
SOC 2
AWS
Go
REST APIs
DevOps
Google Cloud Platform
Requirements
  • Six to eight years of experience in information technology, security engineering, governance, risk and compliance, privacy engineering, or closely related roles
  • Proven experience designing and implementing governance, risk and compliance programs with a strong emphasis on automation, engineering, and scalable processes
  • Hands-on experience implementing or operating privacy programs aligned with GDPR and ISO/IEC 27701, including privacy-by-design and privacy-by-default principles
  • Strong understanding of privacy engineering concepts such as data minimization, purpose limitation, data lifecycle management, and technical data protection controls
  • Proficiency in one or more programming or scripting languages such as Python or Golang, with experience building automation for compliance and privacy workflows
  • Experience working with APIs, webhooks, and integrating GRC, privacy, and security tooling
  • Hands-on experience with public cloud environments (AWS, Azure, or GCP), including applying privacy and data protection controls across backup systems, data lakes, and distributed cloud storage services
  • Experience integrating security and compliance requirements into SDLC and CI/CD pipelines using DevSecOps practices
  • Solid understanding of security frameworks and regulatory standards such as ISO 27xxx, SOC 2, GDPR, and NIST, and how they apply to SaaS environments
  • Knowledge of information security risk management and common security technologies (e.g., SIEM, vulnerability management, data loss prevention, endpoint protection)
  • Experience conducting security risk assessments, data protection impact assessments (DPIAs), and translating findings into actionable remediation plans
  • Strong project management skills with the ability to lead cross-functional initiatives involving engineering, product, legal, and compliance stakeholders
  • Ability to communicate complex technical, privacy, and compliance concepts clearly to both technical and non-technical audiences
  • Demonstrated ability to serve as a subject matter expert and trusted advisor on security, privacy, and compliance risks
  • Ability to thrive in a fast-paced, evolving environment and adapt to changing regulatory and business requirements
  • Nice to have: relevant industry certifications such as CISSP, CISA, CRISC, CIPP/E, CIPM, CIPT, or ISO/IEC 27701 Lead Implementer or Auditor
Responsibilities
  • Embed privacy-by-design principles into Docker products, services, and internal platforms, aligned with ISO/IEC 27001, ISO/IEC 27701, SOC 2, and global privacy regulations
  • Partner closely with Docker engineering and product teams to integrate privacy requirements into architecture decisions, SDLC processes, and CI/CD pipelines
  • Design, develop, and maintain automated GRC and privacy workflows to support compliance monitoring, control testing, DPIAs, risk assessments, reporting, and audit readiness
  • Implement and customize GRC and privacy tooling using APIs, scripting, and automation to streamline evidence collection, control validation, and compliance operations
  • Lead and automate data discovery, classification, and data mapping across Docker systems to maintain accurate Records of Processing Activities (RoPA) and support data lifecycle governance
  • Conduct and operationalize security risk assessments and Data Protection Impact Assessments (DPIAs), integrating findings into Docker’s risk register and remediation tracking
  • Define, implement, and validate data protection and data lifecycle controls, including data minimization, retention, deletion, and access controls
  • Build and maintain dashboards and security/privacy metrics to provide real-time visibility into risk, compliance posture, and program effectiveness
  • Support internal and external audits by providing high-quality, automated evidence and serving as a subject matter expert for security and privacy controls
  • Draft, maintain, and map security and privacy policies, standards, and procedures to relevant regulatory and industry frameworks
  • Conduct privacy reviews of existing and new products, features, and significant changes to ensure compliance requirements are met prior to release
  • Build awareness and enablement across Docker by educating teams on security, privacy, and compliance expectations and best practices
  • Stay current with evolving regulatory, privacy, and security standards and proactively assess their impact on Docker’s products and operations
  • Take part in on-call rotation for your team; respond to incidents, debug production issues, and drive continuous improvement of system reliability
Desired Qualifications
  • Nice to have: relevant industry certifications such as CISSP, CISA, CRISC, CIPP/E, CIPM, CIPT, or ISO/IEC 27701 Lead Implementer or Auditor

Docker builds, shares, and runs applications in isolated containers by packaging an application and its dependencies into a container image that runs consistently across different systems. It provides tools like Docker Desktop for local development, Docker Hub as a container image repository, and a command-line interface to build, run, and manage containers. It differentiates itself with a large ecosystem, an official image repository, and integrated tools that support an end-to-end container workflow. The company aims to help developers consistently build, share, and run software across any environment, using a freemium model with subscription tiers and additional services.

Company Size

1,001-5,000

Company Stage

Series C

Total Funding

$526M

Headquarters

Palo Alto, California

Founded

2013

Simplify Jobs

Simplify's Take

What believers are saying

  • AI agent security market creates new wedge with NanoClaw partnership and Docker Sandboxes.
  • Enterprise security bundling opportunity through testing, scanning, and isolation product stack expansion.
  • Developer-to-enterprise conversion funnel strengthens via open-source top-of-funnel to paid subscription motion.

What critics are saying

  • Mirantis owns Docker Enterprise assets and competes directly for same enterprise workload buyers.
  • GitHub Actions and cloud-native CI/CD tools commoditize Docker's developer workflow differentiation.
  • Docker Desktop and Hub monetization depends on price increases that risk developer churn.

What makes Docker unique

  • Docker Sandboxes provide micro-VM isolation for autonomous AI agents with kernel-level security.
  • Integrated testing and security stack via AtomicJar and Nestybox acquisitions strengthen enterprise upsell.
  • 70,000+ commercial customers and $165M ARR demonstrate broad developer and enterprise adoption.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Docker who can refer or advise you

Benefits

Flexible Work Hours

Home Office Stipend

Parental Leave

Phone/Internet Stipend

Unlimited Paid Time Off

Professional Development Budget

Company Equity

Health Insurance

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
TechCrunch
Mar 13th, 2026
Docker partners with NanoClaw creator weeks after viral AI agent tool launch

NanoClaw creator Gavriel Cohen has struck a deal with Docker to integrate Docker Sandboxes into his open-source AI agent-building tool, capping a whirlwind six weeks since the project's launch. Cohen built NanoClaw in a weekend as a secure alternative to OpenClaw, using just 500 lines of code compared to OpenClaw's 800,000. The project exploded after AI researcher Andrej Karpathy praised it on X, garnering 22,000 GitHub stars and 4,600 forks. Cohen has since shut down his AI marketing startup, which was on track for $1 million in annual recurring revenue, to launch NanoCo around the project. The company plans to offer commercial services including forward deployed engineers to help companies build secure AI agents, though specific monetisation plans remain under development. VCs are already calling, Cohen says.

The Register
Mar 13th, 2026
NanoClaw integrates Docker Sandboxes for secure AI agent isolation

NanoClaw, an open source AI agent platform, now runs inside Docker Sandboxes through a partnership with Docker, enhancing security for AI agents operating autonomously. Docker Sandboxes are micro VMs that provide stronger isolation than containers by running with their own kernel, creating two layers of protection. The integration addresses security concerns arising from AI agents' unpredictable behaviour and need to modify systems. Each agent runs in its own container within a micro VM, preventing access to host machines even if the agent hallucinates or misbehaves. Docker Sandboxes are currently supported on macOS and Windows, with Linux support coming soon. Docker COO Mark Cavage described the technology as enabling developers to "put YOLO in a box", allowing AI agents to run autonomously for extended periods whilst maintaining security boundaries.

Business Insider France
Jan 8th, 2024
Business Insider

Business Insider tells the global tech, finance, markets, media, healthcare, and strategy stories you want to know.

TechCrunch
Dec 11th, 2023
Docker acquires AtomicJar, a testing startup that raised $25M in January | TechCrunch

Docker acquired AtomicJar, the commercial company behind Testcontainers, just a year after the company raised $25M.

GlobeNewswire
Jun 27th, 2023
Docker Continues Investment in Performance and Flexibility of Docker Desktop with Acquisition of Mutagen

SAN FRANCISCO, June 27, 2023 (GLOBE NEWSWIRE) -- Docker, Inc.® today revealed its latest efforts to improve the scope and performance of the Docker...

INACTIVE