> Markdown version of [/jobs/ext/2704066-principal-software-engineer-docker-and-ecosystem](https://www.wearedevelopers.com/jobs/ext/2704066-principal-software-engineer-docker-and-ecosystem). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Software Engineer, Docker and Ecosystem - **Company:** Docker - **Location:** Seattle, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $219,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cyber Security, Continuous Integration, Software Debugging, Programming Tools, Distributed Systems, Open Source Technology, Systems Development Life Cycle, Service-Oriented Architecture, Software Deployment, Software Engineering, Reliability of Systems, Build Management, Containerization, Kubernetes, Information Technology, Enterprise Integration, Api Design, Docker, Legacy Systems - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-principal-software-engineer-docker-and-ecosystem-docker-com-8109307 ## About the Role * 12+ years of software engineering experience, with deep expertise in build security, software supply chain security, SDLC tooling or equivalent experience * Demonstrated understanding of the threat model around the software build process: how compromise gets introduced through dependencies, build environments, artifacts, and pipelines, and what actually mitigates it * Hands-on architectural experience with some meaningful subset of: artifact signing and verification, provenance and attestation, SBOM generation and consumption, dependency and package security, CI/CD pipeline security, base image trust, or vulnerability intelligence at scale * Working knowledge of supply chain security frameworks and standards, and their practical architectural implications * Expert-level understanding of API design, service architecture, and system integration patterns at scale * Proven track record architecting and delivering large-scale distributed systems serving millions of users and thousands of enterprise customers * Experience with cloud platforms (AWS, GCP, or Azure) and modern infrastructure patterns * Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience Strategic & Business Impact * Track record of establishing strategic technical plans that directly enabled business outcomes such as revenue growth, market expansion, or unblocked enterprise deals * Experience translating business strategy into technical architecture and roadmaps * Understanding of SaaS business models, enterprise sales cycles, and how security capabilities influence commercial outcomes * Experience making build-versus-buy decisions for critical platform components Leadership & Influence * Proven ability to drive large cross-company technical programs requiring coordination across multiple engineering organizations * Experience working with VPs and executives to set and execute technical strategy * Track record of influencing technical direction without direct authority, building consensus across teams with competing priorities * Strong communication skills, with the ability to present to executives and drive alignment at every level * Experience mentoring senior engineers and developing technical leadership Enterprise Platform Experience * Experience building products that serve enterprise customers with complex security and compliance requirements * Knowledge of enterprise security requirements and compliance frameworks such as SOC 2 and ISO 27001, and their architectural implications * Understanding of how enterprise security teams evaluate, procure, and operate tooling Preferred * Background at a security company, developer tools company, or infrastructure software company operating at significant scale * Experience with container technologies, Docker, Kubernetes, or developer productivity platforms * Experience with enterprise billing complexity, including contract management, usage-based pricing, and revenue recognition * Track record of migrating legacy systems while maintaining business continuity * Contributions to open source security tooling or participation in supply chain security standards work * External recognition as a technical leader through conference speaking, publications, or open source contributions * Advanced degree in Computer Science, Engineering, or a related technical field ## Description Technical Vision and Strategy * Own the multi-year technical vision for Docker's build security and software supply chain capabilities, spanning Docker Desktop, Docker Hub, Docker Hardened Images, Docker Verified Publishing, and the platforms that monetize them * Define what "trusted by default" means architecturally for a product used by 20 million developers, then sequence the work to get there * Translate Docker's commercial strategy into platform capabilities, partnering with the SVP of Engineering to turn organizational strategy into technical roadmaps that span teams and years * Establish the architectural principles and security standards that guide technical decisions across engineering, and set the bar other teams build against * Identify the investments with maximum leverage: capabilities built once that raise the security floor across every Docker product * Anticipate where supply chain threats and regulatory requirements are heading, and make sure our architecture is positioned before the market demands it Build Security Architecture * Architect the systems that detect and prevent threats introduced during the software build process, including compromised dependencies, malicious build steps, tampered artifacts, and untrusted base images * Design provenance and attestation infrastructure so that any artifact produced through Docker carries verifiable evidence of how, where, and from what it was built * Define Docker's approach to artifact signing, verification, and policy enforcement across the developer inner loop and CI/CD pipelines * Architect SBOM generation, dependency analysis, and vulnerability intelligence capabilities that give developers and security teams a truthful picture of what is actually in their software * Align Docker's architecture with emerging supply chain security frameworks and standards, and help shape them where we can * Design for a hard constraint: security controls that slow developers down get turned off. Everything here has to be fast enough and quiet enough that developers keep it on SDLC and Developer Workflow Integration * Architect how Docker's security capabilities integrate across the full software development lifecycle, from local development through CI/CD to production deployment * Design the interfaces and contracts that let Docker's tooling embed into the pipelines, registries, and platforms customers already run, rather than asking them to rebuild around us * Define the developer experience for security tooling, where the secure path is the fast path and the default path * Architect policy and enforcement models that satisfy enterprise security and compliance requirements without fragmenting the developer workflow * Drive convergence of security capabilities across Docker products, replacing product-specific implementations with shared platform primitives Technical Excellence and Influence * Work with leaders across engineering to drive strategy and execution * Mentor and develop Staff and Principal engineers, raising the technical bar across the organization * Represent Docker's security architecture externally through blog posts, conference talks, standards bodies, and technical community engagement * Participate in executive-level discussions, providing architectural perspective on business decisions * Take part in on-call rotation for your team, respond to incidents, debug production issues, and drive continuous improvement of system reliability ## Related Videos - [Beyond SBOMs: The Future of Container Supply Chain Security](https://www.wearedevelopers.com/videos/100235-beyond-sboms-the-future-of-container-supply-chain-security) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [The Evolving Landscape of Application Development: Insights from Three Years of Research](https://www.wearedevelopers.com/videos/1459-the-evolving-landscape-of-application-development-insights-from-three-years-of-research) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)