Kaseya

Senior Systems Engineer (Linux Isolation & Networking)

Kaseya
Apply
4 hours ago
Toronto, CanadaSenior
H1B Sponsor

Responsibilities

  • Design, build, and operate per-workload sidecar proxies that intercept outbound API traffic and enforce authentication, credential, compliance, and audit controls.
  • Implement Linux process-isolation controls using namespaces, cgroups, separate user identities, ptrace restrictions, protected memory, and secure credential cleanup.
  • Evaluate and implement sandboxing approaches using gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, or Unix domain sockets.
  • Enforce workload and customer boundaries across isolated execution environments and Temporal namespaces.
  • Integrate workload identity and attestation capabilities using SPIFFE, SPIRE, or similar technologies.
  • Implement secure workload startup sequencing, including KMS access, OAuth token preparation, network-rule installation, and readiness signaling.
  • Improve the performance, observability, reliability, and failure recovery of execution and isolation layers.
  • Partner with Platform, Security, and Backend Engineering teams on system design, production troubleshooting, and reliability improvements.

Requirements

  • At least 5 years of systems engineering or software engineering experience building production infrastructure, runtime, or platform services.
  • Production development experience with Go, Rust, C, or C++.
  • Experience with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
  • Experience implementing or operating a sandboxing or workload-isolation technology such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
  • Experience building networking systems involving TCP/IP, transparent proxying, or TLS termination and origination.
  • Preferred experience with Go or Rust for systems-level or infrastructure development.
  • Preferred experience building or operating multi-tenant container, sandbox, or virtual-machine isolation infrastructure.
  • Preferred experience with SPIFFE, SPIRE, or another workload identity and attestation framework.
  • Preferred experience integrating AWS KMS, Azure Key Vault, GCP Cloud KMS, or similar key-management services.
  • Preferred experience with endpoint security, EDR, zero-trust networking, or infrastructure security products.
  • Preferred experience with Kubernetes, container-runtime internals, or managed container platforms.
  • Preferred experience with Temporal or another durable workflow execution platform.

Categories

Kaseya

About Kaseya

5,001-10,000 employees

Kaseya is the leading global provider of AI-powered IT management and cybersecurity software. Kaseya delivers a unified technology platform to manage infrastructure, secure endpoints, back up critical data, and streamline operations for more than 40,000 MSP and SMB customers around the globe. To learn more, visit www.kaseya.com.

Contact me