Docker is not secure enough (it can help but it's not designed to be bulletproof). MAC (GRsecurity...) can be considered the "right" solution.
Or just give up and go QuubeOS ;)
Or just give up and go QuubeOS ;)
Obviously docker, as opposed to Qubes, won't stop more complex malware that exploits the kernel.
Currently, for multi-user systems the only safe option for containers is sadly virtualisation or emulation; nice implementation of rootless chroot is proot, http://proot.me/