ForgeApply · Job listing
Senior Principal Software Engineer, Docker and Ecosystem
Docker
See all 25 open roles at Docker →
Tailor your resume for this Docker job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Docker's site with it. You review everything before it's sent. Free trial, no card required.
About this role
ABOUT DOCKER
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.
We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
_______________________________________________________________________
Docker is seeking a Senior Principal Engineer to serve as the technical visionary and architect for how software gets built, verified, and trusted.
Every day, millions of developers pull images, install dependencies, and ship builds to production. Each of those steps is a place where something can go wrong, or be made to go wrong. Compromised base images, malicious packages, tampered build steps, unsigned artifacts moving through pipelines nobody is watching. The industry calls this the software supply chain, and it has become one of the most consequential unsolved problems in software engineering.
Docker sits at the exact center of it. We are the layer where builds happen. That gives us a rare opportunity, and a real obligation, to make secure software delivery the default rather than an afterthought bolted on at the end.
This role sits in Docker and Ecosystems, the group that owns Docker’s most well known products and our emerging content and SDLC business. You will own the technical strategy for secure software delivery across all of it, defining what verifiable, tamper-resistant software delivery looks like at Docker's scale, then driving the architecture that makes it real for every developer and every enterprise customer using our products.
This is one of the highest-leverage individual contributor roles at the company. You will set multi-year technical direction, make architectural decisions that shape Docker's product portfolio, and work directly with the SVP of Engineering and executive team on strategy. You will not manage people. You will change what the industry considers table stakes.
RESPONSIBILITIES
Technical Vision and Strategy
- Own the multi-year technical vision for Docker's build security and software supply chain capabilities, spanning Docker Desktop, Docker Hub, Docker Hardened Images, Docker Verified Publishing, and the platforms that monetize them
- Define what "trusted by default" means architecturally for a product used by 20 million developers, then sequence the work to get there
- Translate Docker's commercial strategy into platform capabilities, partnering with the SVP of Engineering to turn organizational strategy into technical roadmaps that span teams and years
- Establish the architectural principles and security standards that guide technical decisions across engineering, and set the bar other teams build against
- Identify the investments with maximum leverage: capabilities built once that raise the security floor across every Docker product
- Anticipate where supply chain threats and regulatory requirements are heading, and make sure our architecture is positioned before the market demands it
Build Security Architecture
- Architect the systems that detect and prevent threats introduced during the software build process, including compromised dependencies, malicious build steps, tampered artifacts, and untrusted base images
- Design provenance and attestation infrastructure so that any artifact produced through Docker carries verifiable evidence of how, where, and from what it was built
- Define Docker's approach to artifact signing, verification, and policy enforcement across the developer inner loop and CI/CD pipelines
- Architect SBOM generation, dependency analysis, and vulnerability intelligence capabilities that give developers and security teams a truthful picture of what is actually in their software
- Align Docker's architecture with emerging supply chain security frameworks and standards, and help shape them where we can
- Design for a hard constraint: security controls that slow developers down get turned off. Everything here has to be fast enough and quiet enough that developers keep it on
SDLC and Developer Workflow Integration
- Architect how Docker's security capabilities integrate across the full software development lifecycle, from local development through CI/CD to production deployment
- Design the interfaces and contracts that let Docker's tooling embed into the pipelines, registries, and platforms customers already run, rather than asking them to rebuild around us
- Define the developer experience for security tooling, where the secure path is the fast path and the default path
- Architect policy and enforcement models that satisfy enterprise security and compliance requirements without fragmenting the developer workflow
- Drive convergence of security capabilities across Docker products, replacing product-specific implementations with shared platform primitives
Technical Excellence and Influence
- Work with leaders across engineering to drive strategy and execution
- Mentor and develop Staff and Principal engineers, raising the technical bar across the organization
- Represent Docker's security architecture externally through blog posts, conference talks, standards bodies, and technical community engagement
- Participate in executive-level discussions, providing architectural perspective on business decisions
- Take part in on-call rotation for your team, respond to incidents, debug production issues, and drive continuous improvement of system reliability
QUALIFICATIONS
REQUIRED
Salary insight
The midpoint of this range ($286k) is about 76% above the median disclosed salary for Seattle roles listed on ForgeApply ($162k across 1,742 jobs).
See full Software Engineer salary data for Seattle →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Docker role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Software Engineer (Containers) — Chainguard · Remote
- Senior Software Engineer – Platform (Containers & Kubernetes) — Aveva · San Leandro, California, United States
- Senior Principal Software Engineer — RTX · US-MN-ST LOUIS PARK-5775 ~ 5775 Wayzata Blvd ~ WAYZATA, Ste 630
- Senior Principal Software Engineer — Rocket · Remote
- Senior Software Engineer, DevOps — Uniteus · United States
- Senior Software Engineer, DevOps — Ixllearning · San Mateo, CA
- Sr. Software Engineer, DevOps — Akasa · San Francisco
- Senior Platform Engineer - Container Services — Adyen · Chicago
More like this: Software Engineer Jobs · Software Engineer Jobs in Seattle · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)