SlipstreamJobsFresh Startup & VC-Backed Jobs

Systems Engineer — Linux Isolation & Networking

Kaseya - Toronto, ON, Canada - In-office - posted 2026-08-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Kaseya is hiring Systems Engineers to build the process-isolation, sandboxing, and network-interception infrastructure that enables secure workload execution across the Kaseya Intelligence Platform. This is low-level systems engineering focused on Linux, networking, and process boundaries rather than application-layer development. You will build language-independent infrastructure that isolates workloads, protects credentials, and enforces security controls across multi-tenant environments. Key responsibilities include: • Build and operate a transparent sidecar proxy that intercepts outbound vendor API calls, enforces credential and compliance policies, and records tamper-evident audit events • Implement process-isolation controls using Linux users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and explicit credential cleanup • Evaluate and implement sandboxing approaches using technologies such as gVisor, Firecracker, WebAssembly runtimes, or Unix-domain-socket isolation • Design infrastructure that enforces workload and customer boundaries across large numbers of isolated execution environments • Evaluate and integrate workload identity and attestation technologies such as SPIFFE and SPIRE • Implement secure workload startup sequencing, including KMS access, token preparation, network-rule installation, and readiness signalling • Improve the performance, observability, reliability, and failure recovery of the execution and isolation layers • Partner with Platform, Security, and Backend Engineering teams to define interfaces, investigate production issues, and deploy platform improvements Required qualifications include production systems software development experience using Go, Rust, C, or C++; deep knowledge of Linux internals (namespaces, cgroups, netfilter/iptables, sockets, process lifecycle); hands-on experience with sandboxing or workload-isolation technologies (gVisor, Firecracker, WebAssembly, containers, micro VMs); networking infrastructure experience (TCP/IP, transparent proxying, TLS); and experience implementing process isolation, privilege separation, and OS-level security controls. Preferred experience includes multi-tenant container/sandbox/VM isolation infrastructure, SPIFFE/SPIRE, cloud KMS integration (AWS/Azure/GCP), endpoint security or EDR products, and Kubernetes or container-runtime internals.

Similar roles