Senior Software Engineer, Secure Build

Backend Engineer · Senior · Full Time · Remote

England · RemoteUSD 161k – 261k1w ago
Apply for this role

Opens Docker's application page

Role

What you'll do.

Senior Software Engineer role on Docker's Secure Build team, responsible for designing and operating Go-based build infrastructure, container technologies, and CI/CD systems. This position requires 6+ years of backend engineering experience with distributed systems, Go expertise, and deep knowledge of containers, supply-chain security, and cloud-native infrastructure to deliver trusted build and CI capabilities.

Responsibilities

  • End-to-End Feature Ownership: Own features from technical design through production rollout, including observability, incident response, and ongoing maintenance. Drive secure-build and CI capabilities that solve developer and software agent problems while maintaining measurable outcomes and reliability standards.
  • Go Services Architecture and Development: Design, build, and operate high-performance Go services and APIs powering Docker's build and secure-CI infrastructure. Write maintainable, well-tested code that handles distributed systems challenges at scale, including service discovery, fault tolerance, and resilient communication patterns.
  • Supply-Chain Security Implementation: Develop isolation, identity, policy, provenance, attestation, and signing capabilities for trusted build and test jobs. Implement threat modeling-driven security designs that balance protection requirements with developer experience and deployment velocity.
  • Container and Build Technology Integration: Leverage OCI standards, BuildKit, Buildx, and isolated-execution technologies to deliver secure and reproducible build workflows. Integrate emerging container innovations with production infrastructure while maintaining backward compatibility and operational stability.
  • Platform Reliability and Operations: Maintain high availability of Docker Build Cloud and Auto Builds through targeted reliability improvements. Participate in paid on-call rotation, drive continuous improvements from incident analysis, and establish strong operational practices including observability, metrics, and incident response procedures.
  • Cross-Functional Platform Collaboration: Partner with Product, Security, Developer Experience, Registry, and other platform teams on end-to-end customer workflows. Communicate technical decisions, architectural trade-offs, and progress clearly in an async-first, remote-distributed environment with disciplined documentation.
  • Security Trade-Off Analysis: Apply security expertise to guide architectural decisions without blocking feature delivery. Use threat modeling to balance security boundaries, secrets management, and software supply-chain protections against developer usability and deployment timelines.
  • Developer and Agent Experience Design: Design build and CI workflows that prioritize developer experience for both human engineers and autonomous software agents. Ensure APIs and interfaces are intuitive, predictable, and support programmatic consumption patterns used by AI agents and CI/CD orchestration systems.

Qualifications

What we look for.

Technical

  • Production Go Development

    6+ years writing, testing, reviewing, and debugging maintainable Go services in production environments. Proficiency in concurrent programming patterns, error handling, testing frameworks, and building scalable backend systems.

  • Distributed Systems Architecture

    Strong backend engineering experience building and operating distributed systems at scale. Expertise in handling service-to-service communication, load balancing, data consistency, fault tolerance, and scaling challenges in production environments.

  • Container and CI/CD Technologies

    Hands-on experience with OCI standards, container runtimes, BuildKit, Buildx, Docker, or comparable container build systems. Familiarity with CI/CD platforms like GitHub Actions, Jenkins, or enterprise CI runners. Understanding of build optimization, layer caching, and artifact management.

  • Cloud-Native Infrastructure

    Demonstrated expertise with major cloud platforms (AWS, Azure, GCP) and cloud-native patterns. Experience with managed services, infrastructure-as-code, containerized deployment models, and cloud platform security features.

  • Software Supply-Chain Security

    Working knowledge of security boundaries, identity management, secrets handling, and software supply-chain risks. Understanding of provenance, attestation, artifact signing, and verification mechanisms that ensure build integrity.

  • Observability and Operational Excellence

    Strong operational mindset covering structured logging, metrics collection, distributed tracing, and alerting. Experience owning on-call rotations, performing incident response and post-mortems, and translating operational learnings into system improvements.

  • Full-Stack Feature Delivery

    Proven ability to take features and services from ambiguous problem statements through technical design, implementation, production deployment, and operational monitoring. Track record of delivering measurable business or technical outcomes with clear success metrics.

Education

  • Bachelor's Degree in Computer Science, Engineering, or Related Field

    Formal education in computer science, software engineering, electrical engineering, mathematics, or equivalent discipline. Or equivalent practical software engineering experience with demonstrated technical depth and learning trajectory.

Experience

  • 6+ Years Software Engineering

    Minimum 6+ years of professional software engineering experience with demonstrated technical leadership on production systems. Track record of progressing from mid-level to senior responsibilities, including architectural decision-making and mentoring.

  • Production Systems at Scale

    Experience operating and improving systems handling significant traffic, data volume, or user base. Familiarity with production challenges including performance optimization, debugging complex issues, and maintaining reliability under load.

  • Backend Engineering Leadership

    Demonstrated technical leadership on backend systems; ability to architect solutions, make sound trade-offs between competing requirements, and drive end-to-end delivery across multiple stakeholders.

Skills

Required

  • Go Programming Language

    Expert-level proficiency in Go with production experience building scalable services. Strong understanding of Go concurrency patterns, testing, build systems, and ecosystem tools.

  • Backend Systems Design

    Ability to architect and implement resilient, maintainable backend systems. Experience with API design, service patterns, state management, and production deployment considerations.

  • Distributed Systems Concepts

    Deep understanding of distributed systems challenges including consistency models, fault tolerance, replication, consensus, and observability patterns applied in production scenarios.

  • Container Technology and OCI Standards

    Hands-on expertise with containerization, OCI image specifications, container runtimes, and build systems. Understanding of layer structure, registry protocols, and container orchestration fundamentals.

  • CI/CD Platforms and Build Systems

    Experience designing or operating CI/CD infrastructure, build pipelines, artifact management, and deployment automation. Knowledge of build optimization, reproducibility, and integration with development workflows.

  • Cloud Platform Engineering

    Practical experience with major cloud providers' core services, including compute, storage, networking, and managed services. Ability to design cloud-native architectures and leverage platform-specific capabilities.

  • Security Architecture and Threat Modeling

    Understanding of application security, identity and access management, secrets management, and threat modeling practices. Ability to identify and mitigate security risks while maintaining usability and performance.

  • Observability and Monitoring

    Proficiency in designing observable systems with structured logging, metrics, distributed tracing, and alerting. Experience using monitoring platforms to diagnose issues and guide optimization efforts.

  • Incident Response and On-Call Operations

    Experience responding to production incidents, performing root-cause analysis, writing incident reports, and implementing preventative measures. Comfort with on-call ownership and pager rotation responsibilities.

  • Asynchronous Communication

    Clear written communication suited to remote, async-first environments. Ability to document decisions, articulate trade-offs, and communicate progress through written channels for globally distributed teams.

Preferred

  • Kubernetes and Container Orchestration

    Nice to have

    Experience deploying and operating applications on Kubernetes, including workload management, networking, storage, and cluster administration. Understanding of container orchestration patterns and Kubernetes ecosystem.

  • Software Supply-Chain Security Standards

    Nice to have

    Familiarity with SLSA framework levels, in-toto attestation formats, SBOM generation and consumption, VEX specifications, Sigstore infrastructure, and cosign signing tools. Understanding of provenance and artifact verification.

  • Sandboxing and Isolation Technologies

    Nice to have

    Experience with sandboxing techniques, microVMs, untrusted workload execution, or multi-tenant infrastructure. Knowledge of isolation mechanisms for security and resource management in shared environments.

  • Hosted CI and Developer Infrastructure

    Nice to have

    Experience building or operating hosted CI runners, remote builders, or developer-platform infrastructure. Understanding of developer workflows, self-service capabilities, and platform reliability requirements.

  • AI-Assisted Development Workflows

    Nice to have

    Experience building systems that support programmatic consumption by software agents and AI-assisted development tools. Understanding of agent workflows, API design for automation, and system behavior in agentic contexts.

  • Legacy System Modernization

    Nice to have

    Track record of successfully evolving legacy production systems while delivering new capabilities. Experience managing technical debt, coordinating migrations, and maintaining reliability during transformation.

Tech stack

Languages

GoProtocol Buffers

Frameworks

BuildKitBuildxgRPC

Databases

PostgreSQL

Tools

DockerOCI Image SpecificationSigstore and CosignCloud Platforms

Other

SLSA Frameworkin-totoSoftware Bill of Materials (SBOM)Vulnerability Exploit Exchange (VEX)Container Registries

Compensation

Pay and benefits.

Base·USD 160,900 – 260,700

Equity·Stock options

Benefits

  • Equity and Stock Options

    Meaningful equity stake in Docker as a growing company. Opportunity to participate in company success and build long-term wealth alongside salary compensation.

  • Flexible Work Arrangement

    Remote-first culture allowing engineers to work from anywhere globally. Design your work schedule around your life with freedom and flexibility in work location and hours.

  • Paid Parental Leave

    16 weeks of paid parental leave after 6 months of employment. Support for work-life balance during significant life transitions.

  • Home Office and Technology Support

    Dedicated home office setup stipend to ensure comfortable remote work environment. Technology stipend of $100 USD equivalent per month for hardware, software, and tools.

  • Professional Development and Training

    Training stipend for conferences, courses, and professional development. Support for continuous learning and skill advancement in software engineering and related areas.

  • Generous PTO and Time Off

    PTO plan encouraging time for personal enjoyment and rest. Designated Whaleness Days quarterly plus end-of-year Whaleness break for extended time off.

  • Comprehensive Health and Retirement

    Medical benefits, retirement plans, and holiday time that vary by country of employment. Full benefits package supporting long-term employee wellbeing.

  • Docker Swag and Culture

    Company swag and merchandise supporting Docker brand identity. Access to vibrant remote-first culture with offices in Seattle and Paris for optional in-person collaboration.

Full posting

Original listing.

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

The Secure Build team builds and operates the infrastructure behind Docker's container builds. The team owns Docker Build Cloud and Auto Builds while developing the next generation of trusted build and CI capabilities.

Software is being changed faster than ever, but CI remains a bottleneck and a major trust boundary. Developers and software agents need to run build and test work quickly without exposing secrets, losing local-to-cloud parity or accepting an unverifiable result. Our direction is to make Docker the trusted place CI runs and turn that constraint into an accelerator.

The technical work spans Go services, container and build technology, cloud infrastructure, isolated execution and software supply-chain security. It also requires disciplined operation of the production systems customers rely on today. Docker Build Cloud and Auto Builds will need targeted reliability and operational improvements while useful capabilities evolve towards a coherent Secure Build platform.

As a Senior Software Engineer, you will turn these problems into practical product and technical outcomes. You will own substantial work from discovery and design through production, make sound security and reliability trade-offs, and stay close to the experience of developers and the agents they delegate work to.

We make extensive use of AI-assisted engineering tools. We expect engineers to use them thoughtfully, validate their output and remain accountable for the quality and security of what ships.

Success in This Role Looks Like

You will succeed by becoming an end-to-end owner for secure, reliable build infrastructure. Within your first year, you should have delivered a material secure-build or CI capability, reduced operational risk in Docker Build Cloud or Auto Builds, and become a trusted partner to the teams and customers that consume the platform.

Responsibilities

  • Turn developer, agent and security problems into clear requirements, staged technical decisions and measurable outcomes.

  • Design, build and operate Go services and APIs that power Docker's build and secure-CI infrastructure.

  • Develop isolation, identity, policy, provenance, attestation and signing capabilities for trusted build and test jobs.

  • Work with container, OCI, BuildKit, cloud and isolated-execution technologies to deliver secure and reproducible workflows.

  • Own features from technical design through rollout, observability, incident response and ongoing maintenance.

  • Keep Docker Build Cloud and Auto Builds reliable, make targeted improvements that reduce operational load, and help their capabilities evolve towards the wider Secure Build direction.

  • Make practical security trade-offs and use threat modelling to guide designs without blocking delivery.

  • Design for a clear developer experience, including workflows initiated or consumed by software agents.

  • Partner with Product, Security, Developer Experience, Registry and other platform teams on end-to-end customer workflows.

  • Participate in the team's paid on-call rotation and drive improvements from incidents and recurring operational work.

  • Communicate decisions, risks and progress clearly in a remote, async-first environment.

Qualifications

Required

  • 6+ years of software engineering experience, with demonstrated technical leadership on production systems at scale.

  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience

  • Strong backend engineering experience building and operating distributed systems in production.

  • Production experience with Go and the ability to write, test, review and debug maintainable Go services.

  • Experience with containers and build or CI systems, such as OCI, BuildKit, Buildx, GitHub Actions or comparable platforms.

  • Experience with cloud-native infrastructure and a major cloud platform.

  • A strong operational mindset covering observability, reliability, incident response and on-call ownership.

  • Evidence of taking a feature or service from an ambiguous problem through production operation and measurable results.

  • Working knowledge of security boundaries, identity, secrets and common software supply-chain risks.

  • A strong product mindset and care for developer workflows, including experiences used by software agents.

  • Clear written and spoken communication suited to a remote, async-first company.

Helpful, but not required

  • Experience with Kubernetes.

  • Experience with SLSA, in-toto, SBOM, VEX, Sigstore, cosign, provenance or artefact signing.

  • Experience with sandboxing, microVMs, untrusted workload execution or multi-tenant infrastructure.

  • Experience building hosted CI runners, remote builders or developer-platform infrastructure.

  • Experience with agentic development workflows or building systems used programmatically by software agents.

  • Experience evolving a legacy production system while delivering new capabilities.

What to Expect

First 30 Days

  • Build context on Docker Build Cloud, Auto Builds and the Secure Build product and technical direction.

  • Pair with the Secure Build team on core services, deployments and operational practices.

  • Ship a useful production change and take part in an operational review or incident-learning session.

  • Understand the secure-CI threat model and build relationships with DHI, Registry and Developer Experience.

First 90 Days

  • Own a secure-build feature or reliability improvement from problem definition through production.

  • Contribute materially to the secure-CI architecture, including isolation, identity, policy or signed evidence.

  • Deliver an observable improvement to the reliability or operability of an existing build service.

  • Demonstrate strong product judgement across developer and agent workflows.

One Year Outlook (First Year)

  • Be a trusted senior technical owner on the Secure Build team.

  • Deliver a material secure-CI or trusted-build capability used by customers or internal product teams.

  • Improve the reliability and maintainability of Docker Build Cloud and Auto Builds while helping their useful capabilities converge with the wider platform.

  • Contribute to the team's architecture for isolated execution, brokered access and verifiable build outcomes.

  • Help establish strong product, design, review and operational practices as the team grows.

Docker considers visa sponsorship on a case-by-case basis based on business needs.

 

Compensation & Equity

EU: €94,040 – €155,650+ equity

United States: $160,900 – $260,700 + equity

Perks

  • Freedom & flexibility; fit your work around your life

  • Designated quarterly Whaleness Days plus end of year Whaleness break

  • Home office setup; we want you comfortable while you work

  • 16 weeks of paid Parental leave (after 6 months of employment)

  • Technology stipend equivalent to $100 USD net/month

  • PTO plan that encourages you to take time to do the things you enjoy

  • Training stipend for conferences, courses and classes

  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

  • Docker Swag

  • Medical benefits, retirement and holidays vary by country

  • Remote-first culture, with offices in Seattle and Paris

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

#LI-REMOTE

Redirects to Docker's application page.

Other roles

More at Docker.

View all 21 roles