About this role
Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.
We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.
The DHI Content team builds and maintains Docker Hardened Images: a catalogue of security-hardened system packages, container images and Helm charts designed to be minimal, up to date and safe to use in security-conscious and regulated environments.
This is a supply-chain and open-source maintainer role rather than a conventional backend engineering role. You will work across upstream OSS projects, package and image definitions, Helm charts, Kubernetes, integration tests, vulnerability remediation and the controls that prove content is ready to publish. The work is broad by design: customers should be able to select hardened packages and images and, where relevant, deploy them through hardened charts without the pieces drifting apart.
We are moving DHI content production towards a machine-first factory. Routine work should begin with a machine-produced change and pass through automated build, test, policy and review controls. Engineers add the most value by handling difficult ecosystems, making security judgements, improving standards and turning repeated human corrections into better tooling. You will use AI-assisted engineering extensively, but remain accountable for the evidence and quality behind every result.
As a Senior Supply Chain Security Engineer, you will own substantial content and improvement work from upstream discovery through release and ongoing maintenance. You will be expected to close the loop on customer and security outcomes, not only submit individual definition changes.
SUCCESS IN THIS ROLE LOOKS LIKE
You will succeed by becoming a trusted end-to-end owner for hardened content. Within your first year, you should have delivered complex new or updated DHI content across packages, images and Helm charts, improved the factory or its quality gates, reduced recurring manual work and raised the capability of the engineers around you.
RESPONSIBILITIES
- Author and maintain definitions for hardened system packages and container images, including build steps, upstream tracking, multi-architecture support and reproducibility controls.
- Adapt and maintain upstream Helm charts so they work correctly with DHI images under non-root, restricted and production-shaped Kubernetes security constraints.
- Track upstream releases, s