4 hours ago
Responsibilities
- Build and operate a transparent sidecar proxy for outbound API interception, credential and compliance enforcement, and tamper-evident audit logging.
- Implement Linux process-isolation controls using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and credential cleanup.
- Evaluate and implement sandboxing with gVisor, Firecracker, WebAssembly runtimes, or Unix-domain-socket isolation.
- Design infrastructure that enforces workload and customer boundaries across many isolated execution environments.
- Evaluate and integrate workload identity and attestation technologies such as SPIFFE and SPIRE.
- Implement secure workload startup sequencing involving KMS access, token preparation, network-rule installation, and readiness signaling.
- Improve execution-layer performance, observability, reliability, and failure recovery.
- Partner with Platform, Security, and Backend Engineering teams to define interfaces, investigate production issues, and deploy improvements.
Requirements
- Production systems software development experience with Go, Rust, C, or C++.
- Experience with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
- Experience building networking infrastructure involving TCP/IP, transparent proxying, or TLS termination and origination.
- Experience implementing process isolation, privilege separation, protected credential handling, or related operating-system security controls.
- Preferred experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure.
- Preferred experience with SPIFFE, SPIRE, or another workload identity and attestation framework.
- Preferred experience integrating AWS KMS, Azure Key Vault, GCP Cloud KMS, or similar key-management services.
- Preferred experience with endpoint security, EDR, zero-trust networking, or infrastructure security products.
- Preferred experience with Kubernetes, container-runtime internals, or managed container platforms.
- Preferred experience with Temporal or another durable workflow execution platform.
- Preferred experience supporting systems subject to security, privacy, or compliance requirements.
Benefits
- Full-time employment in Toronto, Ontario, with two openings.
- Eligible roles may receive benefits and additional rewards based on individual impact.
- Certain roles may be eligible for sales incentives according to the applicable plan and role.
About Kaseya
Kaseya is the leading global provider of AI-powered IT management and cybersecurity software. Kaseya delivers a unified technology platform to manage infrastructure, secure endpoints, back up critical data, and streamline operations for more than 40,000 MSP and SMB customers around the globe. To learn more, visit www.kaseya.com.