Canonical Ltd.

Software Engineer - Secure Container Images

Canonical Ltd. · EMEA

About the Role

With more than 10 billion pulls, Canonical's container images are trusted by developers worldwide to build and run software securely and at scale. That trust rests on our commitment to hardened, production-ready images. We are advancing the state of the art with a new generation of Ubuntu-based container images we call "rocks": minimal images engineered for performance and usability and backed by long-term security commitments. As a member of the team, you will own the path from upstream source to published image, turning open source software into tested, signed, and continuously maintained artifacts that developers can deploy with confidence. This is fast-paced, multi-disciplinary software engineering. Because most of the software we package originates from third-party upstreams, you will work across a broad range of container technologies and hundreds of open source projects, often in several programming languages, integrating and maintaining them so they are easy to consume on Ubuntu. Automation is central to the role: you will build the pipelines that package, build, test, and publish images at scale. Your seniority in this role will reflect your software engineering experience and your ability to mentor and guide more junior colleagues. Location: This role is based in the EMEA region This role entails • Build and maintain a growing portfolio of high-quality, hardened container images • Design and operate automated CI/CD pipelines that build, test, scan, sign, publish, promote, and retire images across environments and architectures • Write tooling and tests to assess security compliance and cloud-native compatibility • Work closely with the community and partners to share container expertise and keep our portfolio current with new features, patches, and applications • Collaborate with our product security, platform, infrastructure, and customer-facing teams • Contribute technical input to the team's decision-making • Set the standard for quality, defining image standards that span security, compatibility, performance, size, and developer experience • Grow our knowledge base and write about the work we do • Work in a collaborative, agile, and globally distributed environment • Mentor colleagues and contribute to hiring • Work from home with global travel of up to 15% for internal and external events What we are looking for in you • Proficiency in Bash and Python • Experience working with CI/CD systems (e.g. GitHub Actions, Jenkins) • Experience building container images • Command of at least one container management or orchestration tool (e.g. Docker, Podman, or Kubernetes) • Hands-on experience with Linux systems, package management, build systems, release engineering, or artifact pipelines • Clear communication and end-to-end ownership, spanning design, review, documentation, operation, and cross-team collaboration • A commitment to sharing knowledge and helping those around you grow • A genuine appetite for learning and for working outside your comfort zone • A Bachelor's degree or equivalent in Computer Science, a STEM field, or a similar discipline • An exceptional academic track record from both high school and university • Business level written and spoken English. • Sincere personal motivation aligned with our mission. • International travel 2-4 times a year for company events up to two weeks long. • 0-7 years relevant experience. In addition we expect that you will match our values, by being: • Precise, taking care to deliver correctness and clarity. • Reliable, delivering high quality work that builds trust and confidence. • Accessible, collaborating to build products and systems that are usable. • Adroit, blending enthusiasm, knowledge, adaptability, style and character. Nice-to-have skills • A security-oriented maintenance mindset: you can investigate dependency and vulnerability findings, assess their impact, and deliver a safe fix • An understanding of software supply chain security, with some experience generating and consuming artifacts such as SBOMs, signatures, provenance, or CVE reports • Familiarity with GitOps principles and workflows • Familiarity with additional languages such as Go or Rust • Hands-on experience building minimal and distroless container images • Knowledge of the OCI specifications • Familiarity with security or compliance frameworks such as CIS, NIST, FedRAMP, or DISA STIG • Evidence of contributions to open source projects • A passion for embedding security across all stages of the engineering lifecycle (DevSecOps), and an interest in using AI or agentic development responsibly and safely • Relevant Linux, container, or cloud-native certifications (such as CKS or DCA) are welcome If your experience is close but does not match every requirement, we encourage you to apply. We value transferable experience from Linux packaging, release engineering, build systems, platform engineering, and open-source maintenance. What

💬 Developer Questions

Ask the team a question — answers show up here

🎯

What does the interview process look like?

🤖

What AI/vibe coding tools does the team use daily?

👥

How big is the engineering team?

Is the team fully async or are there required meetings?

🚀

What does onboarding look like for remote hires?

🔧

Can you share more about the tech stack and architecture?

📈

What does career growth look like in this role?

📅

What does a typical day look like?

💰

Is there a salary range you can share?

📊

Is equity or stock options part of the package?

🌍

Are there timezone requirements or preferences?

🛂

Do you sponsor work visas?

🏢 Is this your listing? Claim it to answer questions

Similar Jobs

Helpful resources

Hiring for a similar role? Post your job here — it's free →