Senior Security Engineer – Offensive Security

🔥 13 hours ago

🌐 United Kingdom, Portugal, +3 more countries – Remote

infoinfo

💵 €118.9k - €169.8k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Docker, Inc

Docker, Inc

51 - 200 employees

💼 Consulting

☁️ SaaS

💰 $105M Series C on 2022-03

Consulting • SaaS

Docker, Inc is a company that simplifies the lives of developers by tackling the complexity of app development. They offer tools that allow developers to bring their ideas to life through containerization and orchestration, making the development process easier and more efficient. Docker's products, including Docker Desktop and Docker Hub, are widely adopted by millions of developers worldwide, enhancing workflows and providing an integrated development pipeline.

📋 Description

• Drive offensive security at Docker through realistic adversarial testing of products, platforms, and cloud infrastructure • Partner with engineering, product, and leadership to turn findings into durable fixes and embed security into Docker products • Apply penetration testing, threat modeling, and exploit development across Docker products and infrastructure • Implement proactive security solutions across AWS, GCP, Azure, containerized environments, and AI/ML products • Contribute to security initiatives aligned with business goals • Implement automated security design reviews and vulnerability management programs • Serve as a software security and architecture resource for engineering teams • Design and implement security architecture and controls across Docker products and platforms • Plan, scope, and execute penetration tests and red-team/adversary-emulation engagements • Develop proof-of-concept exploits and risk-rated findings with remediation guidance; retest fixes • Build and maintain offensive security tooling and automation • Perform security reviews and threat modeling of designs, architectures, and code, including emerging AI products • Write automated security tests and exploits • Participate in rotating on-call duties, investigate threats, respond to security events, and coordinate remediation • Educate and collaborate with engineering and product teams • Participate in security incident response • Support audits and compliance with SOC 2 and ISO 27xxx • Own recurring penetration tests and adversary-emulation exercises and engage with external researchers

🎯 Requirements

• 3+ years in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure • 2+ years of hands-on development experience in Python or Golang • Deep expertise in authentication, authorization, OAuth, cryptography applications, and Zero Trust principles • Strong hands-on experience securing cloud ecosystems such as AWS, GCP, and Azure • Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners • Proficiency with Burp Suite and OWASP frameworks • Ability to write security tests and develop exploits and proof-of-concepts • Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks • Practical experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and pentesting workflows • Track record of building security programs and automations from scratch using risk-based prioritization • Experience performing security reviews and building or improving security review automation • Excellent communication skills • Understanding of industry standards and emerging security technologies and models • Offensive security certification such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO • Published CVEs, original security research, or conference talks • Experience with container escape, Kubernetes attack paths, or cloud red teaming is a bonus • Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning is a bonus • No visa sponsorship is offered for this role

🏖️ Benefits

• Remote-first work from home • Flexible schedule • Generous PTO • Quarterly Whaleness Days • End-of-year Whaleness break • Home office support • Technology stipend equivalent to US$100 net per month • Annual learning and development stipend for conferences, courses, certifications, and continued learning • 16 weeks of paid parental leave after six months of employment • Equity for all full-time employees • Medical benefits • Retirement benefits • Paid holidays • Docker swag

Apply Now

Similar Jobs

🕒 Yesterday

AISLE™

11 - 50

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Forward Deployed Engineer deploying AISLE’s AI-powered autonomous vulnerability-remediation platform. Integrating security systems and code across UK and EU government, defense, and enterprise environments.

🕒 2 days ago

Primer

51 - 200

💳 Fintech

Senior Security Engineer securing Primer’s global payments infrastructure through threat modelling, AppSec, compliance, and automation. Remote role supporting engineering teams across eligible countries.

🕒 6 days ago

Fika

11 - 50

🏥 Healthcare

💼 Consulting

🎲 Gambling

IT Security Specialist protecting Fika’s rural infrastructure nonprofit systems from cyber threats. Securing networks, cloud environments, endpoints, and compliance operations across global program offices.

🕒 September 3

Trail of Bits

51 - 200

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Senior Security Engineer red-teaming formally verified systems at Trail of Bits, a cybersecurity research and engineering firm. Building AI-driven vulnerability discovery, triage, and exploit-generation tooling.

🕒 September 2

NVIDIA

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

🤖 Artificial Intelligence

Senior Security Architect designing attestation and confidential-computing security for NVIDIA network devices. Leading next-generation architecture, research, and proof-of-concept development.