Docker

Engineering

SeniorSupplyChainSecurityEngineer

€84–140k Canada FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Supply Chain Security Engineer at Docker. Skills: Supply Chain Security, Container Security, Kubernetes, Docker, Helm, Go. Authoring and maintaining image definition files that track upstream OSS project releases, define build steps, and keep our catalogue current across dozens of images. Adapting upstream Helm charts (cert-manager, grafana, mongodb, kyverno, and many more) to work with DHI images”

Industry & Context.

Engineering
Problems you'll solve

handling security constraints, non-root contexts, and Kubernetes compatibility concerns; handling major version breaks and dependency chains; catching subtle issues before they reach customers

What They're Looking For.

Must Have

6+ years of backend engineering experience with production-grade systems, Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience, familiarity with the container and Kubernetes ecosystem, Comfort with YAML as a primary working medium, Understanding of container security basics, Some Go ability, A maintainer mindset, Familiarity with GitHub-heavy open source workflows

Nice to Have

Experience as a package maintainer (any Linux distribution, Homebrew, etc.), Helm chart authorship or contribution experience, Familiarity with supply chain tooling (Sigstore, SBOM, SLSA), Experience in a regulated or security-conscious environment

What You'll Do.

Authoring and maintaining image definition files that track upstream OSS project releases

and keep our catalogue current across dozens of images

Adapting upstream Helm charts (cert-manager

and many more) to work with DHI images

handling security constraints

and Kubernetes compatibility concerns

Tracking upstream version releases and semver patterns across monorepos and standard repos

handling major version breaks and dependency chains

Writing Go-based integration tests that validate images and charts behave correctly in real Kubernetes environments

Triaging CVEs and contributing to security hardening decisions across images

Reviewing peers' definitions and chart PRs against established conventions and catching subtle issues before they reach customers

How You'll Work.

Team & Collaboration

Reviewing peers' definitions and chart PRs

Full Job Description

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout. We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default. Docker Hardened Images (DHI) is Docker's catalogue of security-hardened, enterprise-grade container images and Helm charts - built to be minimal, up-to-date, and safe to deploy in regulated and security-conscious environments. We're looking for someone to join the team that makes this possible. This is not a traditional software engineering role. You'll spend most of your time working with YAML definition files, upstream OSS projects, and the container and Kubernetes ecosystems - packaging and adapting software rather than building it from scratch. If you've ever maintained packages for a Linux distribution, contributed to a Helm chart upstream, or worked as a platform/infrastructure engineer with a strong security lean, this will feel familiar. RESPONSIBILITIES - Authoring and maintaining image definition files that track upstream OSS project releases, define build steps, and keep our catalogue current across dozens of images - Adapting upstream Helm charts (cert-manager, grafana, mongodb, kyverno, and many more) to work with DHI images - handling security constraints, non-root contexts, and Kubernetes compatibility concerns - Tracking upstream version releases and semver patterns across monorepos and standard repos, handling major version breaks and dependency chains - Writin

Free ATS check

Applying for this Senior Supply Chain Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Docker?

Real rants from real employees. Read before you apply.

Read Company Rants →