Docker logoDO

About

Docker's attack surface is the software supply chain itself. Founded in 2013, the company standardized containerization - packaging applications with all dependencies into units that run consistently across any infrastructure. That standardization is now the backbone of modern deployment, which means Docker's security posture matters at planetary scale: over 20 million monthly users and 20 billion image pulls flowing through its ecosystem. The threat model is clear. Container images are executable artifacts sourced from thousands of contributors; compromised dependencies, malicious packages, and misconfigurations propagate at the speed of a docker pull.

The product stack reflects that reality. Docker Desktop handles local development environments where vulnerabilities often originate. Docker Hub, the registry layer, is where image integrity, access controls, and vulnerability scanning intersect. A broader suite of security and developer tools wraps around these, targeting the full lifecycle from build to runtime. The security team operates across this surface - supply chain integrity, registry hardening, secrets management, and the kind of infrastructure-level concerns that come with being a distribution point for a significant portion of the world's containerized workloads.

For security engineers, the draw is specificity: not abstract threat models but the concrete challenge of securing a platform that other organizations trust to deliver their production code. The company's stated aim - reducing complexity and eliminating friction in the software development lifecycle - means security can't be bolted on as overhead. It has to be integrated into workflows developers actually use, which is a harder and more interesting problem than perimeter defense.

Similar companies

ReversingLabs logoRE

ReversingLabs

ReversingLabs provides software supply chain security and threat intelligence solutions, analyzing billions of files daily to identify hidden malware and risks in software binaries.

2 jobs
Defense Unicorns logoDU

Defense Unicorns

Defense Unicorns delivers containerized software to air-gapped military systems, satellites, and submarines using tools like Zarf and UDS.

2 jobs
GitLab logoGI

GitLab

GitLab is the most comprehensive AI-powered DevSecOps platform, enabling teams and their AI agents to ship secure software faster from planning to production.

1 job
SUSE logoSU

SUSE

SUSE is an enterprise open source technology company founded in 1992, providing secure Linux-based infrastructure and platform solutions built on a philosophy of transparency and no vendor lock-in.

1 job
Databricks logoDA

Databricks

Databricks is the data and AI company, providing a unified Data Intelligence Platform that combines data engineering, data science, and machine learning for enterprise organizations.

1 job
Canonical logoCA

Canonical

Canonical publishes Ubuntu and enterprise open source software, with security, compliance, and systems management tooling spanning cloud, IoT, and AI infrastructure globally.

1 job