Systems Engineer - Linux Isolation & NetworkingLocations: Toronto, ON - 2 openings
Employment Type: Full-time
Job SummaryWe're hiring Systems Engineers to build the process-isolation, sandboxing, and network-interception infrastructure that enables secure workload execution across the Kaseya Intelligence Platform. This is low-level engineering at the Linux, networking, and process boundary rather than application-layer development. You'll build language-independent infrastructure that isolates workloads, protects credentials, and enforces security controls across multi-tenant environments.
Roles & Responsibilities- Build and operate a transparent sidecar proxy that intercepts outbound vendor API calls, enforces credential and compliance policies, and records tamper-evident audit events
- Implement process-isolation controls using Linux users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and explicit credential cleanup
- Evaluate and implement sandboxing approaches using technologies such as gVisor, Firecracker, WebAssembly runtimes, or Unix-domain-socket isolation
- Design infrastructure that enforces workload and customer boundaries across large numbers of isolated execution environments
- Evaluate and integrate workload identity and attestation technologies such as SPIFFE and SPIRE
- Implement secure workload startup sequencing, including KMS access, token preparation, network-rule installation, and readiness signalling
- Improve the performance, observability, reliability, and failure recovery of the execution and isolation layers
- Partner with Platform, Security, and Backend Engineering teams to define interfaces, investigate production issues, and deploy platform improvements
Required Qualifications- Experience developing production systems software using Go, Rust, C, or C++
- Experience working with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management
- Experience implementing or operating at least one sandboxing or workload-isolation technology, such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines
- Experience building networking infrastructure involving TCP/IP, transparent proxying, or TLS termination and origination
- Experience implementing process isolation, privilege separation, protected credential handling, or related operating-system security controls
Preferred Qualifications- Experience building or operating multi-tenant container, sandbox, or virtual-machine isolation infrastructure
- Experience with SPIFFE, SPIRE, or another workload identity and attestation framework
- Experience integrating AWS KMS, Azure Key Vault, GCP Cloud KMS, or similar key-management services
- Experience working on endpoint security, EDR, zero-trust networking, or infrastructure security products
- Experience with Kubernetes, container-runtime internals, or managed container platforms
- Experience with Temporal or another durable workflow execution platform
- Experience supporting systems subject to security, privacy, or compliance requirements
Compensation Range - Toronto Posting OnlyThe base salary range for this job is CAD $160,000 - $240,000 / year.
An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, and abilities of the applicant. At Kaseya, certain roles are eligible for benefits and additional rewards. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.