SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kaseya is seeking a Senior Systems Engineer to design and build process-isolation, sandboxing, and network-interception infrastructure for the Kaseya Intelligence Platform. This hands-on systems role operates at the Linux, networking, and process boundary, supporting secure execution of automation and agentic AI workloads in multi-tenant environments.
Key responsibilities include:
- Design and operate per-workload sidecar proxies that intercept outbound API traffic and enforce authentication, credential, compliance, and audit controls
- Implement process-isolation controls using Linux namespaces, cgroups, separate user identities, ptrace restrictions, and secure credential cleanup
- Evaluate and implement language-independent sandboxing approaches using gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, or Unix domain sockets
- Build infrastructure enforcing workload and customer boundaries across isolated execution environments and Temporal namespaces
- Integrate workload identity and attestation capabilities using SPIFFE, SPIRE, or similar technologies
- Implement secure workload startup sequencing, including KMS access, OAuth token preparation, network-rule installation, and readiness signalling
- Improve performance, observability, reliability, and failure recovery of execution and isolation layers
- Partner with Platform, Security, and Backend Engineering teams on system design, production troubleshooting, and long-term reliability improvements
Required qualifications: 5+ years of systems or software engineering experience building production infrastructure, runtime, or platform services; production systems development in Go, Rust, C, or C++; deep Linux internals knowledge (namespaces, cgroups, netfilter/iptables, sockets, process lifecycle); hands-on experience with sandboxing or workload-isolation technologies (gVisor, Firecracker, WebAssembly, containers, micro VMs); networking systems experience (TCP/IP, transparent proxying, TLS termination/origination).
Preferred: Go or Rust for systems-level development; multi-tenant container/sandbox/VM isolation infrastructure; SPIFFE/SPIRE or workload identity frameworks; cloud KMS integration (AWS, Azure, GCP); endpoint security, EDR, zero-trust, or infrastructure security product experience; Kubernetes or container-runtime internals; Temporal or durable workflow platforms.