Systems Engineer — Linux Isolation & Networking
New
J
JobgetherSystems Engineering
CanadaFull-Time
SalaryCAD $160,000–$240,000 per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- KubernetesC++GoRustLinux
Requirements
- Professional experience developing production-grade systems software using Go, Rust, C, or C++.
- Strong understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
- Experience building networking infrastructure involving TCP/IP, transparent proxying, TLS termination, or TLS origination.
- Practical experience with process isolation, privilege separation, protected credential handling, or related operating-system security controls.
- Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is highly valued.
- Familiarity with workload identity and attestation frameworks such as SPIFFE or SPIRE is a plus.
- Experience with cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is desirable.
- Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container runtimes, or managed container platforms is advantageous.
- Experience with Temporal or another durable workflow execution platform is a plus.
- Strong analytical, troubleshooting, and collaboration skills, with the ability to work effectively across infrastructure, security, and backend teams.
Responsibilities
- Build and operate secure infrastructure for process isolation, sandboxing, workload execution, and network interception across multi-tenant environments.
- Develop transparent sidecar proxy capabilities that intercept outbound API traffic, enforce credential and compliance policies, and generate tamper-evident audit records.
- Implement Linux-based process isolation using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and secure credential-handling practices.
- Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
- Design mechanisms that reliably enforce workload and customer boundaries across large numbers of isolated execution environments.
- Evaluate and implement workload identity and attestation technologies, including SPIFFE and SPIRE.
- Build secure workload startup and initialization flows covering KMS access, token preparation, network-rule configuration, and readiness signaling.
- Improve the performance, observability, reliability, and failure recovery of execution and isolation infrastructure.
- Partner with Platform, Security, and Backend Engineering teams to define technical interfaces, troubleshoot production issues, and deploy infrastructure improvements.
View Full Description & ApplyYou'll be redirected to the employer's site