Corporate Security Engineer

Docker

4h ago 0 views 0 applications
Full-time Remote
Canada
$194,400 - $243,000
Full-time
Security Engineer

Job Description

At Docker, we make app development easier so developers can focus on what matters. Our remote-first team spans the globe, united by a passion for innovation and great developer experiences. With over 20 million monthly users and 20 billion image pulls, Docker is the #1 tool for building, sharing, and running apps—trusted by startups and Fortune 100s alike. We’re growing fast and just getting started. Come join us for a whale of a ride!As a Corporate Security Engineer, you will be the primary technical owner of Docker's identity infrastructure, endpoint security, SaaS governance, and device compliance programs. You will work closely with the IT Operations, and GRC teams to design and implement the controls that keep Docker secure.This role offers the opportunity to build and mature security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem.Responsibilities:Own and continuously improve Docker's Identity and Access Management infrastructure, including SSO, MFA enforcement, lifecycle management, and access governanceDiscover, map inventory and conduct security reviews on third-party integrations and drive security improvements across our SaaS application ecosystemSecure and harden our core collaboration as well as documentation platforms, including email, document sharing, and communication toolsDefine and enforce device compliance policies across our corporate device fleet; own the end-to-end compliant device experienceMature a Zero Trust security model across corporate infrastructure, enforcing conditional access based on identityEstablish and maintain an approved application governance program across desktop, browser, developer tooling, and third-party AI services, with appropriate monitoring and risk-based controlsContribute to the team's incident response capability, bringing corporate IT and identity expertise to investigations and remediation effortsDesign and deploy canaries across our endpoint fleet, for increased visibility and early-warning capabilitiesParticipate in the Security team on-call rotation by managing detection and response to security events Own and continuously improve employee lifecycle security processes, ensuring robust controls at both onboarding and offboardingMaintain IT security evidence and documentation supporting compliance with SOC2 and ISO ISO 27xxxTake part in on-call rotation for your team; respond to incidents, debug production issues, and drive continuous improvement of system reliabilityQualifications6+ years in IT systems engineering with emphasis on automation, and hands-on experience in identity access management, and security best practicesDeep hands-on expertise with Enterprise IdP (SSO, MFA, lifecycle management, groups, API automation)Strong experience securing Google Workspace at an admin levelExperience with MDM solutions and endpoint hardeningSolid understanding of OAuth, SAML, OIDC, and modern identity and access patternsExperience governing SaaS applications at scale: inventory, risk assessment, integration auditsScripting or automation skills (Golang, Python, Bash, Terraform, or similar) for API integration workAbility to write and own technical design documents and risk assessmentsStrong cross-functional communication — able to work effectively with GRC, IT, legal, and non-technical stakeholdersExperience with compliance frameworks such as SOC2 or ISO 27xxxBonus:Experience with Zero-Trust Network Access solutions (ZTNA) and Endpoint Detection and Response (EDR) toolingFamiliarity with canary/deception-based detection techniquesExperience implementing Just-in-Time (JIT) access patterns and identity-as-code practicesExperience with implementing and rolling out Data Leak Prevention (DLP) solutionsWhat to expectFirst 30 days:Meet the Security, IT, and GRC teams Build a clear picture of Docker's tooling stack, security posture, and existing gapsAudit current identity, endpoint, and SaaS configurations to form an initial risk-prioritized view of the landscapeGet up to speed on the Corporate IT Security backlog and begin contributing to active workGain access to team owned systems, and internal documentationComplete security awareness training and compliance onboardingFamiliarize oneself with team workflows and processesShadow a fellow security engineer during their on-call rotationFirst 90 days:Deliver a risk-classified SaaS and integration inventory with a clear remediation roadmapLead the first phase of identity infrastructure improvements, including access governanceBegin hardening core collaboration platforms with a focus on the highest-risk configurationsActively participate in architecture design reviews with the teamBe the Tech Lead for a Corporate Security initiatives Enhance incident response capabilities by participating in on-call rotation and post-incident activitiesCreate and maintain security documentation and runbooks One Year OutlookIdentity infrastructure is rationalized and improved with most of access governance being automatedClear security baseline for corporate devices with metrics tracking on complianceSaaS governance is an ongoing, repeatable process - risks documented and accepted or remediatedDeception-based detection controls are live on endpoints in collaboration Enhance security monitoring and anomaly detectionSupport audits and ensure compliance with SOC 2, ISO 27xxxAdvocate for security best practices in enterprise system managementLead security awareness campaigns and company-wide security eventsDocker does not offer visa sponsorship for this role.We use Covey as part of our hiring and / or promotional process for jobs in NYC and certain features may qualify it as an AEDT. As part of the evaluation process we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound on April 13, 2024.Please see the independent bias audit report covering our use of Covey here.PerksFreedom & flexibility; fit your work around your lifeDesignated quarterly Whaleness Days plus end of year Whaleness breakHome office setup; we want you comfortable while you work16 weeks of paid Parental leaveTechnology stipend equivalent to $100 net/monthPTO plan that encourages you to take time to do the things you enjoyTraining stipend for conferences, courses and classesEquity; we are a growing start-up and want all employees to have a share in the success of the companyDocker SwagMedical benefits, retirement and holidays vary by countryRemote-first culture, with offices in Seattle and ParisDocker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.#LI-REMOTE