Senior Software Engineer, Sandboxes (EU or East Coast Preferred)

Senior Software Engineer · Senior · Full Time · Remote

England · RemoteUSD 161k – 261k1w ago
Apply for this role

Opens Docker's application page

Role

What you'll do.

Docker seeks a Senior Software Engineer to lead development of its Sandboxes product, a runtime environment enabling AI coding agents to execute safely in isolated microVMs on developers' machines. This remote-first role demands deep expertise in building secure, isolated runtime environments (containers, VMs, or sandboxes), strong technical leadership capabilities, and a proven track record shipping production infrastructure at scale. You'll design agent integration workflows, optimize sandbox performance across macOS/Windows/Linux, and drive architectural decisions for AI-native development infrastructure.

Responsibilities

  • Design and Lead Sandbox Product Evolution: Architect and drive improvements to the sandboxes product across agent integration, tool permissions, and developer-facing workflows, ensuring each component aligns with the broader AI-native development ecosystem.
  • Resolve Cross-Platform Runtime Issues: Investigate and resolve correctness, performance, and stability issues in the agent integration layer across macOS, Windows, and Linux, maintaining consistent behavior across heterogeneous environments.
  • Optimize Sandbox Lifecycle Management: Drive the reliability and performance of sandbox creation, session management, and teardown for AI agent workloads, ensuring minimal latency and resource overhead for developers.
  • Drive Architecture and Cross-Team Alignment: Collaborate with peers, Product, and adjacent teams to evolve the architecture as requirements grow, establishing clear technical direction and consensus on complex, ambiguous problems.
  • Mentor and Raise Engineering Standards: Mentor engineers on the team and set the bar in design reviews and code reviews, elevating the overall quality and craftsmanship of the engineering organization.
  • Engage with Developer Communities: Participate in the open source and agentic development communities around sandboxing, Model Context Protocol (MCP), and related ecosystems to stay at the forefront of industry innovation.
  • Ensure Production Reliability: Participate in on-call rotations and respond to critical stability issues affecting users, maintaining SLAs and building trust in Docker's infrastructure for mission-critical workloads.
  • Document and Share Knowledge: Document your work clearly and share knowledge with the rest of the team, ensuring institutional knowledge is preserved and team members can build on your contributions.

Qualifications

What we look for.

Technical

  • Sandbox, Container, or VM Runtime Development

    Deep hands-on experience building secure, isolated runtime environments such as sandboxes, containers, or virtual machines with proven expertise in production systems at scale.

  • Multi-Platform Development

    Strong experience developing and debugging runtime infrastructure across macOS, Windows, and Linux, with understanding of platform-specific isolation mechanisms and constraints.

  • Security and Isolation Architecture

    Ability to reason critically about isolation and security boundaries, understanding what a sandbox should and shouldn't expose, and designing secure defaults that are obvious to users.

  • AI Agent Ecosystem Knowledge

    Familiarity with the agentic software development ecosystem, understanding how coding agents work and how tools like Claude Code, Codex, or similar agents interact with their environment.

  • Developer Tools and Infrastructure

    Demonstrated experience building developer tools, desktop applications, or runtime infrastructure used directly by developers, with empathy for developer workflows and UX.

Education

  • Bachelor's Degree in Computer Science or Engineering

    Bachelor's degree in Computer Science, Engineering, or a related field required, or equivalent practical experience demonstrated through portfolio and track record.

Experience

  • 8+ Years of Software Engineering

    Minimum 8 years of professional software engineering experience with demonstrated technical leadership on production systems at scale.

  • Production Infrastructure Leadership

    Track record of shipping and owning infrastructure in production at scale, with experience driving architecture and technical strategy across multiple engineers or teams.

  • Autonomous Work in Remote Environments

    Proven ability to work with high autonomy in remote-first environments, communicating clearly across time zones and thriving in distributed team settings.

Skills

Required

  • Rust or Go

    Proficiency in systems programming languages commonly used in container and sandbox runtimes, with ability to write performant, safe code for infrastructure.

  • Linux Kernel and System Architecture

    Deep understanding of Linux kernel internals, namespaces, cgroups, and system-level isolation mechanisms used in container and sandbox implementations.

  • Architecture Design and Technical Strategy

    Ability to design scalable architectures, think through performance tradeoffs, and drive technical decision-making across systems that span multiple components.

  • Security Principles and Threat Modeling

    Strong grasp of security principles, ability to conduct threat modeling for untrusted or semi-trusted workloads, and design systems with security as a first-class concern.

  • Cross-Platform Development

    Experience developing and shipping features across multiple operating systems with understanding of platform-specific constraints and optimization opportunities.

Preferred

  • Container Orchestration Experience

    Nice to have

    Familiarity with container orchestration platforms, Docker Engine internals, or container ecosystem tools that provide context for Docker's product vision.

  • Open Source Contribution

    Nice to have

    Active participation in open source projects related to containers, VMs, sandboxes, or developer tools demonstrates alignment with collaborative development culture.

  • AI and Machine Learning Infrastructure

    Nice to have

    Understanding of AI/ML infrastructure requirements, inference environments, or agent orchestration provides valuable context for emerging agentic workloads.

  • Performance Profiling and Optimization

    Nice to have

    Advanced expertise in profiling tools, identifying performance bottlenecks, and implementing optimizations in complex systems.

  • Product Thinking and Developer Empathy

    Nice to have

    Demonstrated ability to think beyond technical implementation, understanding user needs, and shipping products that delight developers.

Tech stack

Languages

RustGoC/C++Python

Frameworks

containerdOCI (Open Container Initiative)QEMU/KVM

Databases

Key-Value Stores (etcd, Redis)

Tools

Docker DesktopDocker HubDocker ScoutLinux namespaces and cgroupsGit and GitHub

Other

Distributed Systems DesignModel Context Protocol (MCP)Microservices Architecture

Compensation

Pay and benefits.

Base·USD 160,900 – 260,700

Equity·Stock options

Benefits

  • Equity Participation

    Equity stake in Docker's future success as a growing startup, aligning personal financial interests with company growth and innovation.

  • Quarterly Whaleness Days and Year-End Break

    Designated quarterly time off plus extended break at year-end to ensure sustained well-being and prevent burnout in a remote-first culture.

  • Home Office Setup Support

    Company-provided home office setup and environment customization to ensure comfort and productivity while working remotely.

  • 16 Weeks Paid Parental Leave

    Generous 16-week paid parental leave after 6 months of employment, demonstrating commitment to family-friendly policies and work-life balance.

  • Technology and Learning Stipend

    Monthly technology stipend equivalent to $100 USD net for equipment and tools, plus separate training budget for conferences, courses, and professional development.

  • Flexible Time Off Policy

    Encouraged PTO plan designed for flexibility, allowing engineers to take time for personal pursuits, travel, and rejuvenation as needed.

  • International Healthcare and Retirement

    Comprehensive medical benefits and retirement plans tailored by country of residence, ensuring global coverage and financial security.

  • Remote-First Culture with Optional Offices

    Distributed team structure with optional offices in Seattle and Paris for those seeking occasional in-person collaboration and team connection.

  • Docker Swag

    Branded Docker merchandise and community collectibles celebrating membership in a beloved developer tooling brand.

Process

Interview steps.

  1. 01

    Application Review and Initial Screening

    Your application is reviewed for alignment with core requirements: 8+ years of software engineering experience, production infrastructure background, and proven technical leadership.

  2. 02

    Recruiter Conversation

    Initial conversation with Docker's recruiting team to discuss your background, career goals, timezone/location preferences for EU/East Coast positioning, and answer logistical questions.

  3. 03

    Technical Deep-Dive Interview

    Detailed technical conversation with senior engineers on the Sandboxes team covering your experience with runtime environments, sandbox/container architecture, security design, and cross-platform development challenges you've solved.

  4. 04

    Architecture and System Design Discussion

    Collaborative session exploring how you approach complex architectural problems, handle ambiguity, reason about tradeoffs, and drive consensus across teams—directly relevant to this role's scope.

  5. 05

    Product and Collaboration Assessment

    Conversation focused on your product thinking, collaboration skills, experience mentoring engineers, and ability to balance technical excellence with shipping velocity in remote environments.

  6. 06

    Leadership and Remote Work Discussion

    Final conversation with hiring manager or senior leader exploring your technical vision for the Sandboxes product, how you drive clarity on ambiguous problems, and your experience thriving in remote-first cultures.

Full posting

Original listing.

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

The Docker Sandboxes team is building the runtime that lets AI coding agents run safely on a developer's machine: disposable, isolated microVM sandboxes that each get their own Docker daemon, filesystem, and network.

This is the core of Docker's sbx product: developers can give an agent the autonomy it needs to get real work done without it ever touching the host, and tear the whole environment down when it's finished.

The successful candidate is a technical, product-minded engineer with deep experience building secure, isolated runtime environments (sandboxes, containers, or VMs) and a track record of shipping and owning that kind of infrastructure in production at scale. They think naturally about isolation and security boundaries, understand the tradeoffs involved in running untrusted or semi-trusted workloads safely, and can reason confidently about a system that spans multiple surface areas.

They can drive clarity and consensus on hard, ambiguous problems that cross team and component boundaries, raise the bar for engineering quality wherever they work, thrive in a remote-first environment, communicate clearly across time zones, work with our users, while bringing curiosity and craftsmanship to hard problems.

Please note: this role is currently prioritizing candidates currently located in the Eastern time zone (US or Canada), or in the EU.

Responsibilities

  • Design, develop, and lead improvements to the sandboxes product across agent integration, tool permissions, and developer-facing workflows.

  • Investigate and resolve correctness, performance, and stability issues in the agent integration layer across macOS, Windows, and Linux.

  • Drive the reliability and performance of sandbox creation, session management, and teardown for AI agent workloads.

  • Collaborate with peers, Product, and adjacent teams to evolve the architecture as requirements grow.

  • Mentor engineers on the team and set the bar in design reviews and code reviews.

  • Engage with the open source and agentic development community around sandboxing, MCP, and related ecosystems.

  • Participate in on-call rotations and respond to critical stability issues affecting users.

  • Document your work clearly and share knowledge with the rest of the team.

Qualifications

  • 8+ years of software engineering experience, with demonstrated technical leadership on production systems at scale.

  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience

  • Experience building developer tools, desktop applications, or runtime infrastructure used directly by developers.

  • Familiarity with the agentic software development ecosystem: how coding agents work and how tools like Claude Code, Codex, or similar agents interact with their environment.

  • Ability to reason about isolation and security boundaries: what a sandbox should and shouldn't expose, and how to make safe defaults obvious to users.

  • Experience driving architecture and technical strategy across multiple engineers or teams.

  • Strong written and verbal communication skills.

  • Comfortable working with a high degree of autonomy in a remote-first environment.

What to Expect

First 30 Days

  • Build an understanding of our codebase.

  • Meet the people on your team and those adjacent to it.

  • Build an understanding of the products we are shipping and our near-term technical priorities.

  • Deliver small fixes or improvements.

First 90 Days

  • Lead the design and development of a significant improvement or feature of the local sandboxes stack.

  • Engage with our open source project and the relevant upstream communities.

  • Shape the team's technical direction, and drive architecture discussions.

One Year Outlook (First Year)

  • Deliver measurable improvements to the correctness and performance of sandboxes.

  • Become a recognized technical owner of key parts of the codebase and a go-to technical leader for the local runtime.

  • Help us define the longer-term technical strategy for the filesystem layer in a way that fits with Product and Business goals, and rally the team behind it.

Docker considers visa sponsorship on a case-by-case basis based on business needs.

Compensation & Equity

EU: €94,040 – €155,650+ equity

United States: $160,900 – $260,700 + equity

Perks

  • Freedom & flexibility; fit your work around your life

  • Designated quarterly Whaleness Days plus end of year Whaleness break

  • Home office setup; we want you comfortable while you work

  • 16 weeks of paid Parental leave (after 6 months of employment)

  • Technology stipend equivalent to $100 USD net/month

  • PTO plan that encourages you to take time to do the things you enjoy

  • Training stipend for conferences, courses and classes

  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

  • Docker Swag

  • Medical benefits, retirement and holidays vary by country

  • Remote-first culture, with offices in Seattle and Paris

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

#LI-REMOTE

Redirects to Docker's application page.

Other roles

More at Docker.

View all 21 roles