Docker - Staff Supply Chain Security Engineer, Docker Hardened Images
Requirements
• 10+ years of backend engineering experience, including extensive work on production-grade, distributed systems at scale. • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience. • Ability to set multi-quarter technical roadmaps and align stakeholders (engineering, product, and executives) on strategy and tradeoffs. • Deep expertise in the container and Kubernetes ecosystem: you have strong, grounded opinions about cert-manager, kyverno, grafana, istio, and similar projects, and you can reason about tradeoffs at the ecosystem level, not just the image level. • Mastery of container supply chain security concepts (provenance, attestation, SBOM, signing, SLSA) and experience driving posture decisions across an organization rather than implementing them on a single project. • Strong software engineering fundamentals: code review, testing, source control, CI/CD, and Go sufficient to shape infrastructure and harness design. • Track record of technical influence without authority across multiple teams or organizations, raising quality through design docs, standards, review, and mentorship. • Experience navigating upstream OSS communities as a decision-maker, representing a downstream organization's requirements and shaping upstream direction on security-relevant issues. • Comfort working across remote, distributed teams and communicating complex technical strategy clearly to both technical and non-technical audiences. • Experience as a package maintainer at a Linux distribution, Homebrew, or comparable ecosystem. • Hands-on experience implementing or operationalizing supply chain tooling (Sigstore, SBOM, SLSA) at org scale. • Experience in regulated environments (FedRAMP, FIPS, PCI) with direct exposure to compliance requirements shaping engineering decisions. • Prior Principal or Distinguished IC experience on a platform, security, or developer-tools team. • Experience engaging directly with enterprise customers on container security architecture. • Align with leadership on the most critical org-wide technical risks and opportunities in container supply chain security. • Develop a point of view on DHI's current architectural constraints and where the highest-leverage interventions are. • Begin mapping the cross-functional landscape: product priorities, upstream pressures, customer compliance signals, and engineering gaps. • Drive an architectural decision that unblocks multiple teams and reduces systemic risk across the catalogue. • Establish a feedback loop from customer, operational, and upstream signals into the multi-quarter roadmap. • Engage upstream OSS communities on at least one DHI-relevant issue with meaningful influence on direction. • Deliver a major platform or standards evolution with broad adoption across DHI and adjacent teams. • Create durable alignment across engineering, product, and security on catalogue architecture, supply chain posture, and hardening strategy. • Raise the technical ceiling for the engineers around you, measurably improving review quality, architectural consistency, and the team's ability to operate independently at a higher level.
Responsibilities
• Setting catalogue-wide technical direction - defining the conventions, patterns, and architectural decisions that govern how images and Helm charts are authored across DHI, and evolving them as the catalogue grows • Owning the hardest packaging problems - images and charts with complex upstream dynamics (rapid release cadence, monorepo quirks, painful major-version breaks, intricate dependency chains, niche multi-arch issues) where the right answer isn't obvious • Authoring and maintaining image definition files that track upstream OSS releases, define build steps, and keep the catalogue current - and shaping the templates and tooling others use to do the same • Adapting upstream Helm charts (cert-manager, grafana, mongodb, kyverno, istio, and many more) to work with DHI images - handling security constraints, non-root contexts, and Kubernetes compatibility concerns, and codifying the patterns that make this repeatable • Driving security hardening strategy - leading CVE triage approaches, hardening decisions, and supply chain posture (Sigstore, SBOM, SLSA) across the catalogue, not just individual images • Designing and writing Go-based integration test infrastructure that validates images and charts behave correctly in real Kubernetes environments, and improving the harness others build on • Raising the bar through review and mentorship - reviewing peers' definition and chart PRs, catching subtle issues before they reach customers, and helping other engineers grow into harder problems • Partnering across teams with product, security, and customer-facing functions to translate customer needs and regulatory pressures into catalogue priorities and technical decisions • Engaging upstream - representing DHI in upstream OSS communities (chart maintainers, project maintainers) on issues that affect security-hardened deployments • Take part in the paid on-call rotation for the team; respond to incidents, debug production issues, and drive continuous improvement of system reliability
Benefits
• Freedom & flexibility; fit your work around your life • Designated quarterly Whaleness Days plus end of year Whaleness break • 16 weeks of paid Parental leave (after 6 months of employment) • Technology stipend equivalent to $100 USD net/month • PTO plan that encourages you to take time to do the things you enjoy • Training stipend for conferences, courses and classes • Equity; we are a growing start-up and want all employees to have a share in the success of the company • Medical benefits, retirement and holidays vary by country • Remote-first culture, with offices in Seattle and Paris • Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT