Senior Systems Engineer (Linux Isolation & Networking) (Canada)

Senior Systems Engineer (Linux Isolation & Networking) (Canada)

29 Aug
|
Jobgether
|
Canada

29 Aug

Jobgether

Canada

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Systems Engineer (Linux Isolation & Networking) based in Canada.

This is a senior, hands-on systems engineering role focused on building secure infrastructure for automation and agentic AI workloads.

You will work at the Linux, networking, and process boundary rather than primarily at the application layer.

The role involves designing isolation and sandboxing mechanisms that protect workloads in secure, multi-tenant environments.

You will own complex infrastructure components from architecture and development through production operations.

Your work will span process isolation, network interception, workload identity, credential security, observability, and reliability.

You will collaborate closely with Platform, Security, Backend Engineering, and other technical teams to solve challenging infrastructure problems.

This is an opportunity to shape foundational systems that make intelligent workloads more secure, reliable, and scalable.

n

Accountabilities:

- Design, build, and operate per-workload sidecar proxy infrastructure that intercepts outbound API traffic and enforces authentication, credential, compliance, and audit controls.
- Implement robust process-isolation mechanisms using Linux namespaces, cgroups, separate user identities, ptrace restrictions, protected memory, and secure credential cleanup.
- Evaluate and implement language-independent sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, and Unix domain sockets.
- Build infrastructure that enforces workload and customer boundaries across isolated execution environments and workflow namespaces.

- Integrate workload identity and attestation capabilities using technologies such as SPIFFE, SPIRE, or comparable frameworks.
- Implement secure workload startup and initialization sequences, including KMS access, OAuth token preparation, network-rule installation, and readiness signaling.
- Improve the performance, observability, reliability, and failure-recovery capabilities of execution and isolation layers.

- Design and operate networking infrastructure involving TCP/IP, transparent proxying, TLS termination and origination, and traffic interception.




- Partner with Platform, Security, and Backend Engineering teams on architecture, system design, production troubleshooting, and long-term reliability improvements.
- Take ownership of infrastructure components throughout their lifecycle, from technical design and implementation through deployment, operations, and continuous improvement.

Requirements

- 5+ years of experience in systems engineering or software engineering, with a track record of building production infrastructure, runtime systems, or platform services.
- Strong production development experience with Go, Rust, C, or C++.
- Solid understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.

- Experience developing networking systems involving TCP/IP, transparent proxies, or TLS termination and origination.
- Strong systems-thinking and problem-solving abilities, with a methodical approach to designing, troubleshooting, and improving complex infrastructure.
- Ability to work effectively across engineering and security disciplines and communicate technical concepts clearly with cross-functional teams.

- Experience operating production systems with a focus on reliability, observability, security, and recovery from failures.
- Experience with Go or Rust for systems-level or infrastructure development is highly desirable.
- Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is an advantage.

- Familiarity with SPIFFE, SPIRE, or other workload identity and attestation frameworks is a plus.
- Experience integrating cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is beneficial.
- Background in endpoint security, EDR, zero-trust networking,



infrastructure security, Kubernetes, container-runtime internals, or managed container platforms is advantageous.

- Experience with Temporal or another durable workflow execution platform is a plus.
- Professional English fluency may be required for collaboration across a globally distributed engineering environment.
- Candidates must be legally authorized to work in Canada, as visa sponsorship is not available for this position.

Benefits

- Fully remote work within Canada.
- Opportunity to work with advanced systems, cloud, networking, security, and AI infrastructure technologies.
- Flexible, globally distributed work environment designed around remote collaboration.
- Flexible paid time off.
- Comprehensive healthcare coverage, including coverage available to employees in Canada.
- Company stock options.
- Career development budget.

- Office equipment budget.
- Wellness budget.
- Internet reimbursement.
- Inclusive parental leave.
- Annual team gatherings and opportunities to connect with colleagues globally.

- Remote work travel program.
- Inclusive and supportive culture that values diverse perspectives, backgrounds, and experiences.
- Opportunities to work on technically challenging infrastructure with significant impact on security, reliability, and scalability.

- Support for accommodations throughout the hiring process where needed.

nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

📌 Senior Systems Engineer (Linux Isolation & Networking) (Canada)
🏢 Jobgether
📍 Canada

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior systems engineer (linux isolation & networking) (canada) / canada