Systems Engineer — Linux Isolation & Networking

New
J
JobgetherSystems Engineering
CanadaFull-Time
SalaryCAD $160,000–$240,000 per year
Apply NowOpens the employer's application page

Job Details

Required Skills
KubernetesC++GoRustLinux

Requirements

  • Professional experience developing production-grade systems software using Go, Rust, C, or C++.
  • Strong understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
  • Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
  • Experience building networking infrastructure involving TCP/IP, transparent proxying, TLS termination, or TLS origination.
  • Practical experience with process isolation, privilege separation, protected credential handling, or related operating-system security controls.
  • Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is highly valued.
  • Familiarity with workload identity and attestation frameworks such as SPIFFE or SPIRE is a plus.
  • Experience with cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is desirable.
  • Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container runtimes, or managed container platforms is advantageous.
  • Experience with Temporal or another durable workflow execution platform is a plus.
  • Strong analytical, troubleshooting, and collaboration skills, with the ability to work effectively across infrastructure, security, and backend teams.

Responsibilities

  • Build and operate secure infrastructure for process isolation, sandboxing, workload execution, and network interception across multi-tenant environments.
  • Develop transparent sidecar proxy capabilities that intercept outbound API traffic, enforce credential and compliance policies, and generate tamper-evident audit records.
  • Implement Linux-based process isolation using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and secure credential-handling practices.
  • Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
  • Design mechanisms that reliably enforce workload and customer boundaries across large numbers of isolated execution environments.
  • Evaluate and implement workload identity and attestation technologies, including SPIFFE and SPIRE.
  • Build secure workload startup and initialization flows covering KMS access, token preparation, network-rule configuration, and readiness signaling.
  • Improve the performance, observability, reliability, and failure recovery of execution and isolation infrastructure.
  • Partner with Platform, Security, and Backend Engineering teams to define technical interfaces, troubleshoot production issues, and deploy infrastructure improvements.
View Full Description & ApplyYou'll be redirected to the employer's site
CAD $160,000–$240,000 per year
Apply Now