SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kaseya is seeking a Staff Systems Engineer to design and build low-level process isolation, sandboxing, and network interception infrastructure that powers secure sidecar architecture at scale. This is deep systems work operating at the OS, networking, and process boundary layers rather than application development.
Key responsibilities include:
- Design and implement process isolation, sandboxing, and network interception infrastructure for sidecar architecture serving thousands of workloads
- Build and maintain the Fleet sidecar: a per-workload transparent authenticating proxy that intercepts outbound vendor API calls at the TCP layer via iptables, enforces credential management and compliance policy, and maintains tamper-evident audit ledgers without application-level instrumentation
- Implement and harden process isolation between sidecars and automation workloads using separate UIDs, ptrace restrictions, mlock'd credential memory, and explicit plaintext zeroing
- Develop language-agnostic sandboxing approaches across gVisor, micro VMs, WASM, and Unix domain socket patterns to support automation workloads in any language
- Manage namespace isolation at scale across thousands of Temporal namespaces for client organizations, ensuring structural enforcement of boundaries
- Evaluate and potentially adopt SPIFFE/SPIRE for workload identity attestation within sandboxed execution environments
- Work on sidecar startup sequencing including KMS credential fetch, OAuth token warming, iptables rule installation, and readiness signaling
Required qualifications:
- Deep Linux systems experience with iptables/netfilter, process namespaces, cgroups, socket options, and Unix domain sockets
- Experience with sandboxing or isolation technologies (gVisor, Firecracker, WASM runtimes, or equivalent)
- Strong networking fundamentals including TCP/IP stack, transparent proxying, TLS termination and origination
- Language-agnostic platform design mindset
- Comfort working close to the OS: memory management, process lifecycle, privilege separation
- Go or Rust strongly preferred; C/C++ experience relevant
- Familiarity with SPIFFE/SPIRE or similar workload identity frameworks is a strong plus
Preferred experience includes building or operating multi-tenant container or VM isolation infrastructure, prior work in security tooling/EDR/zero-trust networking, and KMS integrations at the infrastructure level.
Kaseya is the leading provider of AI-powered IT management and cybersecurity software serving MSPs and internal IT organizations worldwide. Backed by Insight Partners, the company supports customers in 20+ countries and manages over 15 million endpoints.