Назад
Company hidden
7 дней назад

Systems Engineer — Linux Isolation & Networking (Linux)

160 000 - 240 000CAD
Тип работы
fulltime
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Systems Engineer — Linux Isolation & Networking (Linux): Building process-isolation, sandboxing, and network-interception infrastructure for secure workload execution across the Kaseya Intelligence Platform with an accent on Linux internals, workload boundaries, and operating-system security controls. Focus on designing transparent proxying, implementing secure credential handling, integrating sandboxing and workload identity technologies, and improving reliability across multi-tenant execution environments.

Location: Toronto, Ontario, Canada

Salary: CAD 160,000–240,000 per year

Company

hirify.global provides AI-powered IT management and cybersecurity software for managed service providers and internal IT organizations worldwide.

What you will do

  • Build and operate transparent sidecar proxies that intercept vendor API calls, enforce credential and compliance policies, and record tamper-evident audit events.
  • Implement Linux process-isolation controls using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and credential cleanup.
  • Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
  • Design workload and customer boundaries across large numbers of isolated, multi-tenant execution environments.
  • Integrate workload identity and attestation technologies such as SPIFFE and SPIRE, including secure startup sequencing and key-management access.
  • Improve performance, observability, reliability, and failure recovery while partnering with Platform, Security, and Backend Engineering teams.

Requirements

  • Production systems software development experience with Go, Rust, C, or C++.
  • Experience with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
  • Experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
  • Experience building networking infrastructure involving TCP/IP, transparent proxying, or TLS termination and origination.
  • Experience implementing process isolation, privilege separation, protected credential handling, or related operating-system security controls.

Nice to have

  • Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure.
  • Experience with SPIFFE, SPIRE, cloud key-management services, Kubernetes, or container-runtime internals.
  • Experience with endpoint security, EDR, zero-trust networking, infrastructure security, or durable workflow platforms such as Temporal.
  • Experience supporting systems subject to security, privacy, or compliance requirements.

Culture & Benefits

  • Full-time employment at a high-growth software company focused on innovation, accountability, and results.
  • Opportunity to work with advanced technology and collaborate across Platform, Security, and Backend Engineering.
  • Benefits and additional rewards may be available depending on the role and individual impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →