← Back to jobs

Manager, Engineering, Secure Build

docker

Remoto Canada
Uncategorized

Job Score

90 pts
Remote model (+90)

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

The Secure Build team builds and operates the infrastructure behind Docker's container builds. The team owns and runs Docker Build Cloud and Docker's Hub build systems, which run millions of builds a year for hundreds of organisations, and is building the next generation of that: secure, sandboxed CI that isolates each build step and produces hardened images with strong, verifiable provenance, including for customers in regulated and air-gapped environments. A current focus is a hardened build runner that executes each workflow step inside its own micro-VM sandbox.

We're looking for an Engineering Manager to lead this team. It's a small, very senior group that recently came together, with strong technical leadership spread across it. You'll own the team's delivery, growth, and operational excellence, keep its high-scale production systems healthy, and be a real part of setting the team's technical direction alongside the engineers who lead on different parts of the system.

The kind of person we're looking for

The successful candidate leads first. They're an experienced engineering manager at their best turning a senior team into a high-performing, value-delivering part of the wider Docker org: getting the process and team mechanics right, partnering well with Product, and navigating the personalities on and around the team. What sets them apart is that they stay deep in the technical work rather than steering from a distance. They're active in technical design and in the PRs, they help shape the technical direction, and they're happy to pick up code where it moves things forward. We're not after a 50-50 player-coach, and we're not after someone who's left the engineering behind either; the balance tilts to leading, but they're hands-on enough to be properly in the detail with the team. The team has strong technical leadership across it, and direction is set together rather than by any one person, so this isn't about being the best engineer in the room or the deepest supply-chain-security expert. It's about being engaged and credible enough to be a real part of how the team sets its direction, not standing apart from it. They care about security broadly: how modern attacks actually work, the OWASP Top 10, and where a build pipeline is exposed. They lead through judgement, unblocking, and direction-setting rather than process for its own sake, because that's what a senior, autonomy-heavy team responds to. They're comfortable owning the operational reality of production systems and on-call, and they're energised rather than thrown by ambiguity. Above all they care about growing the engineers around them and shipping something customers actually trust.

Responsibilities:

  • Lead a team of senior engineers operating Docker Build Cloud and Hub's build systems and building Docker's next generation of secure build infrastructure.

  • Own delivery: turn an ambiguous, high-stakes roadmap, including time-bound commitments to regulated and federal customers, into a concrete plan the team can execute predictably.

  • Get the team's process and mechanics right, and partner closely with Product to turn strategy into a roadmap the team believes in.

  • Stay deep in the technical work: active in design discussions and code review, hands-on in the code where it helps, rather than steering from a distance.

  • Be a real part of setting the team's technical direction, working with the engineers who lead on different parts of the system, while giving the whole team room to own technical decisions.

  • This role may require participation in an on-call rotation to provide support outside of standard business hours, including evenings, weekends, and holidays, as needed.

  • Be accountable for the reliability and operational excellence of the team's production services, including a healthy, humane on-call rotation.

  • Own the growth, development, and performance of each engineer on the team, and hire to strengthen it.

  • Work across the wider org - Product, sales, commercial and legal, the Hub/registry team, and security - to align the team and shield it from churn.

  • Hold a high bar for engineering excellence and raise the team's security hygiene.

Qualifications

  • 5+ years managing high-performing engineering teams, including engineers at or above their own level of technical seniority, with a track record of growing and retaining senior individual contributors.

  • 8+ years of professional, hands-on, full-time software engineering experience in backend, infrastructure, or platform engineering.

  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience

  • A leader first: strong on team process and mechanics, on partnering with Product, and on reading and navigating the personalities on and around a team to make it more than the sum of its parts.

  • Comfortable inheriting a team they didn't build: earning the trust of experienced engineers, and owning the full range of performance conversations, including the difficult ones, fairly and directly.

  • Technically deep and still hands-on: recent enough engineering chops to be active in design and code review, be a real part of setting technical direction with the team, and write code where it helps. Not the best engineer in the room or the deepest domain expert, but not a manager who's left the technical detail behind either.

  • A strong interest in security: how recent attacks have actually worked, the OWASP Top 10, and the build threat model. Familiarity with software supply chain security (SLSA, in-toto, provenance, signing such as cosign, SBOMs, vulnerability scanning) is valued, but we care more about security instinct and appetite than a checklist of tools.

  • Understanding of CI/CD and build-system internals, container images and image hardening, and OCI registry mechanics.

  • Experience operating production infrastructure: on-call, incident response, SLOs, and the realities of keeping high-traffic services healthy.

  • Comfortable leading a distributed, remote-first team across European and US time zones, with a high degree of autonomy.

  • Strong written and verbal communication, and a habit of staying close to customers.

  • Hands-on familiarity with Go is a plus; it's the team's primary language.

What to expect

First 30 days

Get to know the team, the systems, and the commitments before changing anything. Build relationships with each engineer, understand the roadmap and what the team is building, and get hands-on enough with Build Cloud and the inherited systems to understand the on-call load you're taking on.

First 90 days.

Own the delivery plan with the team and Product. Get the on-call rotation to a healthy, sustainable place. Be the team's point of contact across the wider org.

One year Outlook

The team is delivering against its roadmap and operating its production systems reliably, the on-call and delivery cadence are sustainable, and the team is growing both in capability and in number.

Docker considers visa sponsorship on a case-by-case basis based on business needs.

Perks

  • Freedom & flexibility; fit your work around your life

  • Designated quarterly Whaleness Days plus end of year Whaleness break

  • Home office setup; we want you comfortable while you work

  • 16 weeks of paid Parental leave (after 6 months of employment)

  • Technology stipend equivalent to $100 USD net/month

  • PTO plan that encourages you to take time to do the things you enjoy

  • Training stipend for conferences, courses and classes

  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

  • Docker Swag

  • Medical benefits, retirement and holidays vary by country

  • Remote-first culture, with offices in Seattle and Paris

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

#LI-REMOTE

Discover Other Areas

Understand the scope of work, key skills, and tools used in different career areas.

About Cloud Solutions

The Cloud Solutions area is responsible for designing, implementing, and managing cloud infrastructure and services (AWS, Azure, GCP) for companies. Cloud professionals architect scalable, secure, and cost-optimized solutions, from data center migrations to serverless and multi-cloud architectures.

Key skills include IaC (Terraform, CloudFormation), containers (Docker, Kubernetes), serverless (Lambda, Cloud Functions), managed databases (RDS, DynamoDB, BigQuery), cloud networking (VPC, CDN, load balancer), and security (IAM, WAF, KMS). Knowledge of FinOps, cloud governance, and AWS/Azure/GCP certifications is a differentiator.

Cloud Solutions professionals in technology companies are highly valued, especially those who master multi-cloud architectures, FinOps, and can optimize costs while maintaining performance and security. The field offers opportunities from cloud engineer to cloud solutions architect, head of cloud, and chief cloud architect.

About Design

The Design field, especially UX/UI and Product Design, has experienced significant growth in recent years. With accelerated business digitization, the demand for professionals who can create intuitive and pleasant digital experiences has never been higher.

Key skills include Figma, Sketch, Adobe XD, user research, design thinking, prototyping, and system design. Product designers are increasingly valued for their direct impact on business results.

Remote work has opened doors for Brazilian designers to work for global companies, with competitive salaries in dollars and euros.

About Product Owner

The Product Owner (PO) is the professional responsible for maximizing the value of the product delivered by the development team. They act as the voice of the customer and stakeholders, managing and prioritizing the product backlog, defining clear user stories, and ensuring the team works on the most valuable items for the business.

Key skills include backlog management, user story writing, prioritization (Mascow, RICE), agile methodologies (Scrum, Kanban), and stakeholder communication. Knowledge of tools like Jira, Trello, Azure DevOps, and Miro is essential.

Product Owners are highly sought-after professionals in the technology market, working collaboratively with Scrum Masters, Product Managers, and engineering teams to drive agility and continuous value delivery.

About IT Governance

IT Governance is the area responsible for ensuring that information technology resources are used strategically, efficiently, and in compliance with standards and regulations. IT governance professionals ensure that technology supports business objectives in a secure and reliable manner.

Key skills include IT service management (ITIL), IT audit and compliance, risk management, business continuity, disaster recovery, metrics and indicators (SLAs, KPIs), and strategic alignment between IT and business. Frameworks like COBIT, ITIL, ISO 27001, and compliance standards are essential.

IT Governance professionals in technology companies are highly valued, especially those who master ITSM, IT audit, and risk management. The field offers opportunities from governance analyst to CIO/CTO, with a focus on efficiency, compliance, security, and business value.

About Product Manager

The Product Manager (PM) is the professional responsible for defining the strategy, vision, and roadmap of a digital product. They work at the intersection of technology, business, and user experience (UX), leading the discovery and delivery of solutions that solve real problems in a viable way for the company.

Key skills include product discovery, data and metrics analysis (AARRR, NPS, LTV), user research, go-to-market strategy, roadmapping, strategic prioritization, and leadership by influence. Tools like Amplitude, Mixpanel, Hotjar, Jira, and Notion are fundamental.

Product Managers play a central role in the growth of startups, scale-ups, and large technology companies, with career progression opportunities to Product Leader, Head of Product, and Chief Product Officer (CPO).

Career Guides

Technology Career Guide

Planning, skills, interviews, and professional growth in IT, Data Science, DevOps, and Product.

Read full guide →

Design Career Guide

UX/UI, Graphic Design, Product Design. Portfolio, tools, interviews, and growth in the Design field.

Read full guide →

Marketing Career Guide

SEO, Paid Media, Growth, Content Marketing. Certifications, tools, and strategies to grow in Digital Marketing.

Read full guide →

Finance Career Guide

Financial market, investments, corporate finance, certifications, and strategies to grow in the financial field.

Read full guide →

Communication Career Guide

Journalism, PR, Corporate Communication, Content Marketing, and Multimedia Production.

Read full guide →

Administration Career Guide

Business Management, HR, Logistics, Consulting, Project Management, and Entrepreneurship.

Read full guide →

Data Career Guide

Data Science, Data Engineering, BI, Machine Learning, and AI. From training to the job market.

Read full guide →

Product Career Guide

Product Management, Product Ownership, Agile, Scrum, and OKRs. From strategy to execution.

Read full guide →

Tech & Remote Glossary

Stop getting lost in interviews and job descriptions

The job market, especially within tech and global companies, has developed its own dialect. Not understanding these acronyms can make you lose valuable opportunities or poorly negotiate your contract. To end this problem, we created the Definitive Glossary for the Remote Professional.

🏢 Work Models & Routine

Async (Asynchronous Work)
A communication model where responses don't need to be immediate. Instead of back-to-back meetings, the team relies on well-structured documents, threads, and messages. It's the gold standard for global companies spanning multiple time zones.
Sync (Synchronous Work)
The opposite of Async. It requires the team to be online and available at the same time for meetings, live chats, and real-time collaboration.
Daily / Stand-up
A quick daily meeting (usually 15 minutes) common in Agile (Scrum) methodologies. The team answers three questions: What did I do yesterday? What will I do today? Are there any blockers?
All-Hands / Town Hall
A company-wide meeting involving all employees. Usually led by the founders (C-Levels) to present results, new goals, and answer team questions.
1:1 (One-on-One)
A recurring individual meeting between a professional and their direct manager. It is used for career alignment, feedback, and problem-solving, not just for project status updates.

💰 Contracts, Benefits & Compensation

PTO (Paid Time Off)
Instead of strict, categorized leave policies, modern US companies usually offer a flexible pool of days (e.g., 20 days of PTO, or even "Unlimited PTO") that you can use for vacations, sick days, or personal matters, while receiving your regular compensation.
Equity / Stock Options
Company ownership. The startup offers you the right to buy shares at a heavily discounted strike price in the future. If the company grows, goes public, or is acquired, these shares can be highly lucrative.
Vesting (Vesting Schedule)
The rule that controls your Equity. It usually lasts 4 years. You don't get all the shares on day one; you "earn" them gradually as you stay with the company. A "1-year Cliff" means you must stay for at least one year to receive your first batch of shares.
RSUs (Restricted Stock Units)
Unlike Stock Options (where you have the right to buy the stock), RSUs are actual shares the company grants you as a bonus or part of your compensation package, following a strict Vesting schedule.
Independent Contractor (1099 / B2B)
The most common international hiring model for global talent working for US companies. You act as a service provider (business-to-business), receiving the gross salary (often six-figure compensation) without standard local payroll tax deductions at the source.

🤖 Recruitment & Hiring Process

ATS (Applicant Tracking System)
The "robot" that reads your resume. Software like Greenhouse, Ashby, and Workday are used to filter candidates by keywords before a human even looks at the document. (Pro tip: this is why your resume must be clean, semantic, and have the right keywords).
JD (Job Description)
The document that lists the responsibilities, technical requirements, and benefits of the open position.
Cultural Fit
The interview stage that evaluates if your core values, communication style, and worldview align with the company's culture. This is the ultimate test of your Soft Skills.
Onboarding
The integration process. It's the period of your first few weeks at the company, where you get your access credentials, learn about the culture, study the internal documentation, and understand how the product works.

🚀 How to use this to your advantage?

The secret isn't just knowing what these acronyms mean, but using them actively. If during an interview for a premium tech role you ask, "How does your PTO policy and Vesting schedule work?", the recruiter will immediately perceive you as a high-level professional, familiar with the global market standards.

The remote job market requires preparation. And having the right vocabulary is the first big step to securing six-figure proposals and standing out among thousands of applicants.

Expert Tip

How n8n and Automation Open Doors to Premium Jobs

The Paradigm Shift in Web Development

The web development market has matured. A few years ago, mastering a traditional stack (like MERN or LAMP) was enough to secure a highly sought-after role. Today, the corporate landscape — especially in US startups hiring globally and offering six-figure compensation — demands speed and operational efficiency. It's no longer just about building from scratch, but knowing how to integrate complex ecosystems rapidly.

According to Gartner, hyperautomation is one of the top strategic technology trends of the decade. The modern developer must be an integration architect, capable of connecting CRMs, databases, AI APIs, and payment gateways in a matter of hours, not weeks. This is exactly where n8n becomes an indispensable tool in your portfolio.

Why n8n? The Power of "Fair-Code"

n8n is a node-based workflow automation tool. Unlike competitors aimed at non-technical users (such as Zapier or Make), n8n was designed with the developer in mind first. It allows raw JavaScript injection for complex data manipulation, custom HTTP requests, and, most importantly, features a fair-code licensing model that allows it to be self-hosted on a company's own infrastructure.

For technical recruiters and CTOs, a candidate who masters n8n demonstrates maturity. It proves that you understand SaaS cost reduction and value the security and sovereignty of the company's data.

Practical Tips to Land Your Next Role

If you want your resume to pass rigorous ATS (Applicant Tracking System) screening — like Greenhouse or Ashby — and reach the hands of Tech Leads, here are the core skills you should highlight when associating Web Development with n8n:

  • Mastery of Webhooks and RESTful APIs: The foundation of automation is system communication. Demonstrate your ability to create n8n workflows that listen to native Webhooks from your application (e.g., a checkout event in a Next.js e-commerce app) and trigger subsequent actions with low latency.
  • Hosting and Docker: n8n's biggest differentiator is self-hosting. In your resume, mention your ability to package and orchestrate n8n instances using Docker and Docker Compose. Familiarity with Cloud providers (AWS, GCP, or DigitalOcean) to deploy these instances is a massive bonus.
  • Advanced JSON and JavaScript Manipulation: Show that you don't rely solely on pre-built integrations. Using the "Code" node in n8n to transform large JSON payloads using raw JavaScript or TypeScript is what separates a regular user from an automation engineer.
  • Error Handling and Resilience: Systems fail. APIs go down. An amateur automation will break a company's process. In your portfolio, document how you use Error Trigger nodes to build automated retries and send alerts to Slack/Discord when an integration fails.

Your Portfolio is the Ultimate Proof

Just listing "n8n" in the skills section of your resume isn't enough. Create a repository on GitHub containing a real-world use case. For example: export the JSON file of an n8n workflow that reads new leads from a PostgreSQL database, enriches the data using the OpenAI API, and sends them to a CRM. Add a detailed README.md explaining the architecture. This is the ultimate bait for Senior roles.

References and Further Reading