SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Systems Engineer (Linux Isolation & Networking)

Kaseya - Toronto, ON, Canada - In-office - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Kaseya is seeking a Senior Systems Engineer to design and build process-isolation, sandboxing, and network-interception infrastructure for the Kaseya Intelligence Platform. This hands-on systems role operates at the Linux, networking, and process boundary, supporting secure execution of automation and agentic AI workloads in multi-tenant environments. Key responsibilities include: - Design and operate per-workload sidecar proxies that intercept outbound API traffic and enforce authentication, credential, compliance, and audit controls - Implement process-isolation controls using Linux namespaces, cgroups, separate user identities, ptrace restrictions, and secure credential cleanup - Evaluate and implement language-independent sandboxing approaches using gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, or Unix domain sockets - Build infrastructure enforcing workload and customer boundaries across isolated execution environments and Temporal namespaces - Integrate workload identity and attestation capabilities using SPIFFE, SPIRE, or similar technologies - Implement secure workload startup sequencing, including KMS access, OAuth token preparation, network-rule installation, and readiness signalling - Improve performance, observability, reliability, and failure recovery of execution and isolation layers - Partner with Platform, Security, and Backend Engineering teams on system design, production troubleshooting, and long-term reliability improvements Required qualifications: 5+ years of systems or software engineering experience building production infrastructure, runtime, or platform services; production systems development in Go, Rust, C, or C++; deep Linux internals knowledge (namespaces, cgroups, netfilter/iptables, sockets, process lifecycle); hands-on experience with sandboxing or workload-isolation technologies (gVisor, Firecracker, WebAssembly, containers, micro VMs); networking systems experience (TCP/IP, transparent proxying, TLS termination/origination). Preferred: Go or Rust for systems-level development; multi-tenant container/sandbox/VM isolation infrastructure; SPIFFE/SPIRE or workload identity frameworks; cloud KMS integration (AWS, Azure, GCP); endpoint security, EDR, zero-trust, or infrastructure security product experience; Kubernetes or container-runtime internals; Temporal or durable workflow platforms.

Similar roles