Jobgether
Jobgether

Senior Systems Engineer (Linux Isolation & Networking)

engineeringfull-timeCanada
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Design, build, and operate per-workload sidecar proxy infrastructure that intercepts outbound API traffic and enforces authentication, credential, compliance, and audit controls.
    • Implement robust process-isolation mechanisms using Linux namespaces, cgroups, separate user identities, ptrace restrictions, protected memory, and secure credential cleanup.
    • Evaluate and implement language-independent sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, and Unix domain sockets.
    • Build infrastructure that enforces workload and customer boundaries across isolated execution environments and workflow namespaces.
    • Integrate workload identity and attestation capabilities using technologies such as SPIFFE, SPIRE, or comparable frameworks.
    • Implement secure workload startup and initialization sequences, including KMS access, OAuth token preparation, network-rule installation, and readiness signaling.
    • Improve the performance, observability, reliability, and failure-recovery capabilities of execution and isolation layers.
    • Design and operate networking infrastructure involving TCP/IP, transparent proxying, TLS termination and origination, and traffic interception.
    • Partner with Platform, Security, and Backend Engineering teams on architecture, system design, production troubleshooting, and long-term reliability improvements.
    • Take ownership of infrastructure components throughout their lifecycle, from technical design and implementation through deployment, operations, and continuous improvement.
    • Requirements

      • 5+ years of experience in systems engineering or software engineering, with a track record of building production infrastructure, runtime systems, or platform services.
      • Strong production development experience with Go, Rust, C, or C++.
      • Solid understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
      • Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
      • Experience developing networking systems involving TCP/IP, transparent proxies, or TLS termination and origination.
      • Strong systems-thinking and problem-solving abilities, with a methodical approach to designing, troubleshooting, and improving complex infrastructure.
      • Ability to work effectively across engineering and security disciplines and communicate technical concepts clearly with cross-functional teams.
      • Experience operating production systems with a focus on reliability, observability, security, and recovery from failures.
      • Experience with Go or Rust for systems-level or infrastructure development is highly desirable.
      • Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is an advantage.
      • Familiarity with SPIFFE, SPIRE, or other workload identity and attestation frameworks is a plus.
      • Experience integrating cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is beneficial.
      • Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container-runtime internals, or managed container platforms is advantageous.
      • Experience with Temporal or another durable workflow execution platform is a plus.
      • Professional English fluency may be required for collaboration across a globally distributed engineering environment.
      • Candidates must be legally authorized to work in Canada, as visa sponsorship is not available for this position.
      • Benefits

        • Fully remote work within Canada.
        • Opportunity to work with advanced systems, cloud, networking, security, and AI infrastructure technologies.
        • Flexible, globally distributed work environment designed around remote collaboration.
        • Flexible paid time off.
        • Comprehensive healthcare coverage, including coverage available to employees in Canada.
        • Company stock options.
        • Professional development budget.
        • Office equipment budget.
        • Wellness budget.
        • Internet reimbursement.
        • Inclusive parental leave.
        • Annual team gatherings and opportunities to connect with colleagues globally.
        • Remote work travel program.
        • Inclusive and supportive culture that values diverse perspectives, backgrounds, and experiences.
        • Opportunities to work on technically challenging infrastructure with significant impact on security, reliability, and scalability.
        • Support for accommodations throughout the hiring process where needed.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now