Systems Engineer — Linux Isolation & Networking in Canada at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Systems Engineer — Linux Isolation & Networking based in Canada.
This is a high-impact systems engineering role focused on building secure infrastructure at the Linux, networking, and process boundaries. You’ll design and operate isolation and sandboxing technologies that enable secure workload execution in multi-tenant environments. The role combines low-level systems programming, networking, workload security, and cloud infrastructure. You’ll work on technologies such as Linux namespaces, cgroups, transparent proxies, workload identity, and sandboxing runtimes. Your work will help protect credentials, enforce customer and workload boundaries, and strengthen platform security. You’ll collaborate closely with Platform, Security, and Backend Engineering teams in a fast-moving, technology-driven environment.
- Build and operate secure infrastructure for process isolation, sandboxing, workload execution, and network interception across multi-tenant environments.
- Develop transparent sidecar proxy capabilities that intercept outbound API traffic, enforce credential and compliance policies, and generate tamper-evident audit records.
- Implement Linux-based process isolation using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and secure credential-handling practices.
- Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
- Design mechanisms that reliably enforce workload and customer boundaries across large numbers of isolated execution environments.
- Evaluate and implement workload identity and attestation technologies, including SPIFFE and SPIRE.
- Build secure workload startup and initialization flows covering KMS access, token preparation, network-rule configuration, and readiness signaling.
- Improve the performance, observability, reliability, and failure recovery of execution and isolation infrastructure.
- Partner with Platform, Security, and Backend Engineering teams to define technical interfaces, troubleshoot production issues, and deploy infrastructure improvements.
- Professional experience developing production-grade systems software using Go, Rust, C, or C++.
- Strong understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
- Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
- Experience building networking infrastructure involving TCP/IP, transparent proxying, TLS termination, or TLS origination.
- Practical experience with process isolation, privilege separation, protected credential handling, or related operating-system security controls.
- Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is highly valued.
- Familiarity with workload identity and attestation frameworks such as SPIFFE or SPIRE is a plus.
- Experience with cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is desirable.
- Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container runtimes, or managed container platforms is advantageous.
- Experience with Temporal or another durable workflow execution platform is a plus.
- Strong analytical, troubleshooting, and collaboration skills, with the ability to work effectively across infrastructure, security, and backend teams.
- Base salary range of CAD $160,000–$240,000 per year for the Toronto position.
- Full-time employment with opportunities to work on advanced Linux, networking, cloud, and security infrastructure.
- Additional benefits and rewards may be available depending on the role and individual impact.
- Potential eligibility for additional incentive compensation, depending on the applicable role and plan.
- Opportunity to work with cutting-edge technologies in a high-growth, high-performance environment.
- Collaboration with multidisciplinary Platform, Security, and Backend Engineering teams.
- Professional growth opportunities in systems engineering, cloud infrastructure, and cybersecurity.
- Inclusive workplace committed to equal employment opportunity and a diverse workforce.