6 авг

security engineer

выше рынка на 170,2%
вакансия 884 219 ₽
в среднем 327 250 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

генерация резюме под вакансию

Загрузи резюме в профиль, чтобы сгенерировать временное CV под эту вакансию

сопроводительное письмо

Загрузи резюме в профиль, а нейросеть определит твою категорию. Затем ты сможешь генерировать сопроводительные письма для вакансий этой категории

описание

Docker provides developer tools and secure infrastructure for building, sharing, and running applications, including Docker Desktop, Docker Hub, and Docker Scout. Its products support more than 20 million monthly users and over 20 billion container image pulls.

задачи

  • Partner with engineering and product teams throughout the development lifecycle to identify security risks from design review through code review and release;
  • Conduct threat modeling and security design reviews for product features, focusing on authentication, authorization, and container runtime security;
  • Serve as the primary liaison to the central security organization, relay guidance, and translate policy into practical engineering decisions;
  • Act as the first point of contact for vulnerability reports and CVEs, validate severity, reproduce issues, coordinate disclosure timelines, and drive remediation;
  • Review Go code for privilege escalation, insecure defaults, injection risks, and improper credential handling;
  • Contribute security-focused improvements directly to the codebase;
  • Develop and maintain internal security documentation, guidelines, and runbooks;
  • Stay current on the Linux security landscape relevant to containers, including namespaces, cgroups, seccomp, AppArmor, capabilities, and the OCI ecosystem;
  • Participate in an on-call rotation outside standard business hours, including evenings, weekends, and holidays, as needed;
  • Onboard into the Docker Desktop codebase, architecture, and development workflow;
  • Participate in design and code reviews with a security focus;
  • Take ownership of the vulnerability intake process and handle end-to-end triage cycles;
  • Drive improvements to threat modeling, authentication flows, container isolation defaults, and remediation timelines.

требования

  • 6+ Years of experience in security engineering, application security, or a closely related discipline, with a track record at senior or staff level;
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience;
  • Strong proficiency in Go and the ability to review and contribute to production-grade code;
  • Deep understanding of Linux fundamentals relevant to container security, including namespaces, cgroups, capabilities, seccomp profiles, AppArmor/SELinux, rootless containers, and privilege boundaries;
  • Solid understanding of OCI specifications and container runtime security, including runc, containerd, and BuildKit;
  • Hands-on experience with identity and access management, OAuth 2.0, OIDC, token handling, and authentication flows;
  • Experience with security design reviews, threat modeling, and secure development workflows;
  • Familiarity with vulnerability management, CVE triage, CVSS scoring, coordinated disclosure, and working with external reporters;
  • Strong written and verbal communication skills, with the ability to bridge security and product engineering teams.

условия

  • €113,860 – €186,780 + Equity for the EU;
  • Visa sponsorship is considered case by case based on business needs;
  • Quarterly Whaleness Days and an end-of-year Whaleness break;
  • Home office setup;
  • 16 Weeks of paid parental leave after 6 months of employment;
  • Technology stipend equivalent to $100 USD net/month;
  • PTO plan;
  • Training stipend for conferences, courses, and classes;
  • Equity participation;
  • Medical benefits, retirement, and holidays vary by country.

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

прозрачные зарплаты в IT

Анонимные данные по зарплатам и грейдам

Посмотреть
График динамики зарплат
Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.