> Markdown version of [/jobs/ext/2096064-senior-software-engineer-secure-build](https://www.wearedevelopers.com/jobs/ext/2096064-senior-software-engineer-secure-build). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Secure Build - **Company:** Docker - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £94,040.0 - £155,650.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cloud Computing, Software Debugging, Distributed Systems, Github, Reliability Engineering, Software Engineering, Cloud Platform System, Kubernetes, Information Technology, Oracle Cloud Infrastructure, Docker - **Published:** August 17, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5844297285 ## About the Role * 6+ years of software engineering experience, with demonstrated technical leadership on production systems at scale. * Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience * Strong backend engineering experience building and operating distributed systems in production. * Production experience with Go and the ability to write, test, review and debug maintainable Go services. * Experience with containers and build or CI systems, such as OCI, BuildKit, Buildx, GitHub Actions or comparable platforms. * Experience with cloud-native infrastructure and a major cloud platform. * A strong operational mindset covering observability, reliability, incident response and on-call ownership. * Evidence of taking a feature or service from an ambiguous problem through production operation and measurable results. * Working knowledge of security boundaries, identity, secrets and common software supply-chain risks. * A strong product mindset and care for developer workflows, including experiences used by software agents. * Clear written and spoken communication suited to a remote, async-first company. * Experience with Kubernetes. * Experience with SLSA, in-toto, SBOM, VEX, Sigstore, cosign, provenance or artefact signing. * Experience with sandboxing, microVMs, untrusted workload execution or multi-tenant infrastructure. * Experience building hosted CI runners, remote builders or developer-platform infrastructure. * Experience with agentic development workflows or building systems used programmatically by software agents. * Experience evolving a legacy production system while delivering new capabilities. ## Description * Turn developer, agent and security problems into clear requirements, staged technical decisions and measurable outcomes. * Design, build and operate Go services and APIs that power Docker's build and secure-CI infrastructure. * Develop isolation, identity, policy, provenance, attestation and signing capabilities for trusted build and test jobs. * Work with container, OCI, BuildKit, cloud and isolated-execution technologies to deliver secure and reproducible workflows. * Own features from technical design through rollout, observability, incident response and ongoing maintenance. * Keep Docker Build Cloud and Auto Builds reliable, make targeted improvements that reduce operational load, and help their capabilities evolve towards the wider Secure Build direction. * Make practical security trade-offs and use threat modelling to guide designs without blocking delivery. * Design for a clear developer experience, including workflows initiated or consumed by software agents. * Partner with Product, Security, Developer Experience, Registry and other platform teams on end-to-end customer workflows. * Participate in the team's paid on-call rotation and drive improvements from incidents and recurring operational work. * Communicate decisions, risks and progress clearly in a remote, async-first environment., * Build context on Docker Build Cloud, Auto Builds and the Secure Build product and technical direction. * Pair with the Secure Build team on core services, deployments and operational practices. * Ship a useful production change and take part in an operational review or incident-learning session. * Understand the secure-CI threat model and build relationships with DHI, Registry and Developer Experience. * Own a secure-build feature or reliability improvement from problem definition through production. * Contribute materially to the secure-CI architecture, including isolation, identity, policy or signed evidence. * Deliver an observable improvement to the reliability or operability of an existing build service. * Demonstrate strong product judgement across developer and agent workflows. * Be a trusted senior technical owner on the Secure Build team. * Deliver a material secure-CI or trusted-build capability used by customers or internal product teams. * Improve the reliability and maintainability of Docker Build Cloud and Auto Builds while helping their useful capabilities converge with the wider platform. * Contribute to the team's architecture for isolated execution, brokered access and verifiable build outcomes. * Help establish strong product, design, review and operational practices as the team grows. Docker considers visa sponsorship on a case-by-case basis based on business needs. ## Related Videos - [The Evolving Landscape of Application Development: Insights from Three Years of Research](https://www.wearedevelopers.com/videos/1459-the-evolving-landscape-of-application-development-insights-from-three-years-of-research) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Beyond SBOMs: The Future of Container Supply Chain Security](https://www.wearedevelopers.com/videos/100235-beyond-sboms-the-future-of-container-supply-chain-security) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)