Senior Systems Engineer (Linux Isolation & Networking) in Canada Creek, Nova Scotia at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Systems Engineer (Linux Isolation & Networking) based in Canada.
This is a senior, hands-on systems engineering role focused on building secure infrastructure for automation and agentic AI workloads.
You will work at the Linux, networking, and process boundary rather than primarily at the application layer.
The role involves designing isolation and sandboxing mechanisms that protect workloads in secure, multi-tenant environments.
You will own complex infrastructure components from architecture and development through production operations.
Your work will span process isolation, network interception, workload identity, credential security, observability, and reliability.
You will collaborate closely with Platform, Security, Backend Engineering, and other technical teams to solve challenging infrastructure problems.
This is an opportunity to shape foundational systems that make intelligent workloads more secure, reliable, and scalable.
- Design, build, and operate per-workload sidecar proxy infrastructure that intercepts outbound API traffic and enforces authentication, credential, compliance, and audit controls.
- Implement robust process-isolation mechanisms using Linux namespaces, cgroups, separate user identities, ptrace restrictions, protected memory, and secure credential cleanup.
- Evaluate and implement language-independent sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, micro virtual machines, and Unix domain sockets.
- Build infrastructure that enforces workload and customer boundaries across isolated execution environments and workflow namespaces.
- Integrate workload identity and attestation capabilities using technologies such as SPIFFE, SPIRE, or comparable frameworks.
- Implement secure workload startup and initialization sequences, including KMS access, OAuth token preparation, network-rule installation, and readiness signaling.
- Improve the performance, observability, reliability, and failure-recovery capabilities of execution and isolation layers.
- Design and operate networking infrastructure involving TCP/IP, transparent proxying, TLS termination and origination, and traffic interception.
- Partner with Platform, Security, and Backend Engineering teams on architecture, system design, production troubleshooting, and long-term reliability improvements.
- Take ownership of infrastructure components throughout their lifecycle, from technical design and implementation through deployment, operations, and continuous improvement.
- 5+ years of experience in systems engineering or software engineering, with a track record of building production infrastructure, runtime systems, or platform services.
- Strong production development experience with Go, Rust, C, or C++.
- Solid understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
- Experience developing networking systems involving TCP/IP, transparent proxies, or TLS termination and origination.
- Strong systems-thinking and problem-solving abilities, with a methodical approach to designing, troubleshooting, and improving complex infrastructure.
- Ability to work effectively across engineering and security disciplines and communicate technical concepts clearly with cross-functional teams.
- Experience operating production systems with a focus on reliability, observability, security, and recovery from failures.
- Experience with Go or Rust for systems-level or infrastructure development is highly desirable.
- Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is an advantage.
- Familiarity with SPIFFE, SPIRE, or other workload identity and attestation frameworks is a plus.
- Experience integrating cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is beneficial.
- Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container-runtime internals, or managed container platforms is advantageous.
- Experience with Temporal or another durable workflow execution platform is a plus.
- Professional English fluency may be required for collaboration across a globally distributed engineering environment.
- Candidates must be legally authorized to work in Canada, as visa sponsorship is not available for this position.
- Fully remote work within Canada.
- Opportunity to work with advanced systems, cloud, networking, security, and AI infrastructure technologies.
- Flexible, globally distributed work environment designed around remote collaboration.
- Flexible paid time off.
- Comprehensive healthcare coverage, including coverage available to employees in Canada.
- Company stock options.
- Professional development budget.
- Office equipment budget.
- Wellness budget.
- Internet reimbursement.
- Inclusive parental leave.
- Annual team gatherings and opportunities to connect with colleagues globally.
- Remote work travel program.
- Inclusive and supportive culture that values diverse perspectives, backgrounds, and experiences.
- Opportunities to work on technically challenging infrastructure with significant impact on security, reliability, and scalability.
- Support for accommodations throughout the hiring process where needed.