Qualifications
Key Responsibilities:Lead and continually enhance Docker's Identity and Access Management infrastructure, focusing on SSO, MFA enforcement, lifecycle management, and access governance.Conduct security reviews and inventory mapping of third-party integrations, driving security enhancements across our SaaS application ecosystem.Secure our core collaboration and documentation platforms, including email, document sharing, and communication tools.Define and implement device compliance policies for our corporate device fleet, ensuring a compliant device experience from end to end.Advance a Zero Trust security model across corporate infrastructure, applying conditional access based on identity verification.Establish and manage an approved application governance program across desktop, browser, developer tools, and third-party AI services, ensuring appropriate monitoring and risk-based controls are in place.Contribute to the incident response team by applying corporate IT and identity expertise during investigations and remediation efforts.Design and implement canaries across our endpoint fleet to enhance visibility and early warning capabilities.Participate in the on-call rotation for the Security team, managing detection and response to security incidents.Continuously improve the employee lifecycle experience regarding security policies.
About the job
At Docker, we simplify application development, empowering developers to concentrate on what truly matters. Our globally distributed, remote-first team is driven by a shared passion for innovation and exceptional developer experiences. With over 20 million monthly users and 20 billion image pulls, Docker stands as the leading tool for building, sharing, and running applications—endorsed by both startups and Fortune 100 companies. We're in a phase of rapid growth and are just getting started. Join us for an exciting journey!
As a Corporate Security Engineer, you will take ownership of Docker's identity infrastructure, endpoint security, SaaS governance, and device compliance programs. Collaborating closely with the IT Operations and Governance, Risk, and Compliance (GRC) teams, you will design and implement robust controls to safeguard Docker's environment.
This role provides a unique opportunity to enhance and develop security programs within a company whose products are trusted by millions of developers globally. You'll operate in a technically challenging setting where your security expertise will have a direct impact on both Docker's platform and the wider container ecosystem.
About Docker, Inc.
Docker is revolutionizing the way applications are developed, enabling developers to focus on their core tasks rather than the complexities of the infrastructure. With a commitment to innovation, Docker supports millions of users across the globe, making it an essential tool for modern software development.