Kaseya

Senior Systems Engineer (Linux Isolation & Networking)

Kaseya$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in systems or software engineering for production infrastructure
  • Proficient in Go, Rust, C, or C++ for system development
  • Deep knowledge of Linux internals including namespaces and cgroups
  • Hands-on experience with sandboxing or workload isolation tools like gVisor or Firecracker
  • Solid understanding of networking systems including TCP/IP and TLS

Responsibilities

  • Design and operate a per-workload sidecar proxy for API traffic management
  • Implement robust process-isolation controls leveraging Linux features
  • Evaluate and apply multiple sandboxing technologies to enhance security
  • Create infrastructure that maintains workload and customer isolation
  • Integrate workload identity capabilities with technologies like SPIFFE
  • Establish secure startup sequences for workloads with necessary controls
  • Enhance the execution layer's performance and reliability
  • Collaborate across teams for system design and troubleshooting

Benefits

  • Comprehensive health, dental, and vision insurance
  • 401(k) retirement plan with company match
  • Flexible work hours and remote work options
  • Professional development and training opportunities
  • Generous paid time off and holiday schedule
Full Job Description
Senior Systems Engineer (Linux Isolation & Networking)
Job Summary

We're hiring a Senior Systems Engineer to build the process-isolation, sandboxing, and network-interception infrastructure supporting the Kaseya Intelligence Platform. This is a hands-on systems role operating at the Linux, networking, and process boundary rather than the application layer. You'll own complex platform components from design through production, helping ensure automation and agentic AI workloads remain isolated, secure, observable, and reliable in multi-tenant environments.
Roles & Responsibilities
  • Design, build, and operate a per-workload sidecar proxy that intercepts outbound API traffic and applies authentication, credential, compliance, and audit controls
  • Implement process-isolation controls using Linux namespaces, cgroups, separate user identities, ptrace restrictions, protected memory, and secure credential cleanup
  • Evaluate and implement language-independent sandboxing approaches using gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, or Unix domain sockets
  • Build infrastructure that enforces workload and customer boundaries across isolated execution environments and Temporal namespaces
  • Integrate workload identity and attestation capabilities using SPIFFE, SPIRE, or similar technologies
  • Implement secure workload startup sequencing, including KMS access, OAuth token preparation, network-rule installation, and readiness signalling
  • Improve the performance, observability, reliability, and failure recovery of the execution and isolation layers
  • Partner with Platform, Security, and Backend Engineering teams on system design, production troubleshooting, and long-term reliability improvements
Required Qualifications
  • 5+ years of systems engineering or software engineering experience building production infrastructure, runtime, or platform services
  • Experience developing production systems using Go, Rust, C, or C++
  • Experience working with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management
  • Experience implementing or operating at least one sandboxing or workload-isolation technology, such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines
  • Experience building networking systems involving TCP/IP, transparent proxying, or TLS termination and origination
Preferred Qualifications
  • Experience using Go or Rust for systems-level or infrastructure development
  • Experience building or operating multi-tenant container, sandbox, or virtual-machine isolation infrastructure
  • Experience with SPIFFE, SPIRE, or another workload identity and attestation framework
  • Experience integrating AWS KMS, Azure Key Vault, GCP Cloud KMS, or similar key-management services
  • Experience working on endpoint security, EDR, zero-trust networking, or infrastructure security products
  • Experience with Kubernetes, container-runtime internals, or managed container platforms
  • Experience with Temporal or another durable workflow execution platform

About Kaseya

Industry
Founded
2000

Similar Jobs

More Jobs at Kaseya

More Information Technology Jobs

Find similar Senior Systems Engineer (Linux Isolation & Networking) jobs: