Jobgether
Systems Engineer — Linux Isolation & Networking
engineeringfull-timeCanada
SALARY
$160k – $240k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities:
- Build and operate secure infrastructure for process isolation, sandboxing, workload execution, and network interception across multi-tenant environments.
- Develop transparent sidecar proxy capabilities that intercept outbound API traffic, enforce credential and compliance policies, and generate tamper-evident audit records.
- Implement Linux-based process isolation using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and secure credential-handling practices.
- Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
- Design mechanisms that reliably enforce workload and customer boundaries across large numbers of isolated execution environments.
- Evaluate and implement workload identity and attestation technologies, including SPIFFE and SPIRE.
- Build secure workload startup and initialization flows covering KMS access, token preparation, network-rule configuration, and readiness signaling.
- Improve the performance, observability, reliability, and failure recovery of execution and isolation infrastructure.
- Partner with Platform, Security, and Backend Engineering teams to define technical interfaces, troubleshoot production issues, and deploy infrastructure improvements.
- Professional experience developing production-grade systems software using Go, Rust, C, or C++.
- Strong understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
- Experience building networking infrastructure involving TCP/IP, transparent proxying, TLS termination, or TLS origination.
- Practical experience with process isolation, privilege separation, protected credential handling, or related operating-system security controls.
- Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is highly valued.
- Familiarity with workload identity and attestation frameworks such as SPIFFE or SPIRE is a plus.
- Experience with cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is desirable.
- Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container runtimes, or managed container platforms is advantageous.
- Experience with Temporal or another durable workflow execution platform is a plus.
- Strong analytical, troubleshooting, and collaboration skills, with the ability to work effectively across infrastructure, security, and backend teams.
- Base salary range of CAD $160,000–$240,000 per year for the Toronto position.
- Full-time employment with opportunities to work on advanced Linux, networking, cloud, and security infrastructure.
- Additional benefits and rewards may be available depending on the role and individual impact.
- Potential eligibility for additional incentive compensation, depending on the applicable role and plan.
- Opportunity to work with cutting-edge technologies in a high-growth, high-performance environment.
- Collaboration with multidisciplinary Platform, Security, and Backend Engineering teams.
- Professional growth opportunities in systems engineering, cloud infrastructure, and cybersecurity.
- Inclusive workplace committed to equal employment opportunity and a diverse workforce.
Requirements:
Benefits:
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply