Systems Engineer — Linux Isolation & Networking
Job Summary
About Kaseya
Kaseya is the leading provider of AI-powered IT management and cybersecurity software serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Our comprehensive platform helps organizations efficiently manage secure and automate their IT environments driving operational efficiency and long-term business success.
Founded in 2000 Kaseya has built a culture centered around innovation accountability and results. We are a high-growth high-performance organization that values individuals who are driven adaptable and committed to delivering exceptional outcomes for our customers and teammates alike.
At Kaseya success comes from embracing challenges moving with urgency and continuously raising the bar.
Locations: Toronto ON 2 openings
Employment Type: Full-time
Join a fast-growing company thats transforming the IT industry. At Kaseya youll have the opportunity to work with cutting-edge technology collaborate with a dynamic team and develop your career in a high impact role.
Join the Kaseya growth rocket ship and see how we are #ChangingLives!
Were hiring Systems Engineers to build the process-isolation sandboxing and network-interception infrastructure that enables secure workload execution across the Kaseya Intelligence Platform. This is low-level engineering at the Linux networking and process boundary rather than application-layer development. Youll build language-independent infrastructure that isolates workloads protects credentials and enforces security controls across multi-tenant environments.
Build and operate a transparent sidecar proxy that intercepts outbound vendor API calls enforces credential and compliance policies and records tamper-evident audit events
Implement process-isolation controls using Linux users and permissions namespaces cgroups ptrace restrictions protected memory and explicit credential cleanup
Evaluate and implement sandboxing approaches using technologies such as gVisor Firecracker WebAssembly runtimes or Unix-domain-socket isolation
Design infrastructure that enforces workload and customer boundaries across large numbers of isolated execution environments
Evaluate and integrate workload identity and attestation technologies such as SPIFFE and SPIRE
Implement secure workload startup sequencing including KMS access token preparation network-rule installation and readiness signalling
Improve the performance observability reliability and failure recovery of the execution and isolation layers
Partner with Platform Security and Backend Engineering teams to define interfaces investigate production issues and deploy platform improvements
Experience developing production systems software using Go Rust C or C
Experience working with Linux internals including namespaces cgroups netfilter or iptables sockets and process lifecycle management
Experience implementing or operating at least one sandboxing or workload-isolation technology such as gVisor Firecracker WebAssembly containers or micro virtual machines
Experience building networking infrastructure involving TCP/IP transparent proxying or TLS termination and origination
Experience implementing process isolation privilege separation protected credential handling or related operating-system security controls
Experience building or operating multi-tenant container sandbox or virtual-machine isolation infrastructure
Experience with SPIFFE SPIRE or another workload identity and attestation framework
Experience integrating AWS KMS Azure Key Vault GCP Cloud KMS or similar key-management services
Experience working on endpoint security EDR zero-trust networking or infrastructure security products
Experience with Kubernetes container-runtime internals or managed container platforms
Experience with Temporal or another durable workflow execution platform
Experience supporting systems subject to security privacy or compliance requirements
The base salary range for this job is CAD $160000 $240000 / year.
An individuals base pay depends on various factors including geographical location and review of experience knowledge skills and abilities of the applicant. At Kaseya certain roles are eligible for benefits and additional rewards. These rewards are allocated based on individual impact in addition certain roles also have the opportunity to earn sales incentives based on revenue or utilization depending on the terms of the plan and the employees role.
Kaseya provides equal employment opportunity to all employees and applicants without regard to race religion age ancestry gender sex sexual orientation national origin citizenship status physical or mental disability veteran status marital status or any other characteristic protected by applicable law.
Additional information
Kaseya provides equal employment opportunity to all employees and applicants without regard to race religion age ancestry gender sex sexual orientation national origin citizenship status physical or mental disability veteran status marital status or any other characteristic protected by applicable law.
Required Experience:
IC
About Company
Additional information Kaseya provides equal employment opportunity to all employees and applicants without regard to race, religion, age, ancestry, gender, sex, sexual orientation, national origin, citizenship status, physical or mental disability, veteran status, marital status, or ... View more