JobTarget Logo

Systems Engineer — Linux Isolation & Networking in Canada at Jobgether

NewJob Function: Engineering
Jobgether
Canada, M5V 3L9, Canada
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Systems Engineer Linux Isolation & Networking

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Systems Engineer — Linux Isolation & Networking based in Canada.

This is a high-impact systems engineering role focused on building secure infrastructure at the Linux, networking, and process boundaries. You’ll design and operate isolation and sandboxing technologies that enable secure workload execution in multi-tenant environments. The role combines low-level systems programming, networking, workload security, and cloud infrastructure. You’ll work on technologies such as Linux namespaces, cgroups, transparent proxies, workload identity, and sandboxing runtimes. Your work will help protect credentials, enforce customer and workload boundaries, and strengthen platform security. You’ll collaborate closely with Platform, Security, and Backend Engineering teams in a fast-moving, technology-driven environment.

Accountabilities:
  • Build and operate secure infrastructure for process isolation, sandboxing, workload execution, and network interception across multi-tenant environments.
  • Develop transparent sidecar proxy capabilities that intercept outbound API traffic, enforce credential and compliance policies, and generate tamper-evident audit records.
  • Implement Linux-based process isolation using users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and secure credential-handling practices.
  • Evaluate and integrate sandboxing technologies such as gVisor, Firecracker, WebAssembly runtimes, and Unix-domain-socket isolation.
  • Design mechanisms that reliably enforce workload and customer boundaries across large numbers of isolated execution environments.
  • Evaluate and implement workload identity and attestation technologies, including SPIFFE and SPIRE.
  • Build secure workload startup and initialization flows covering KMS access, token preparation, network-rule configuration, and readiness signaling.
  • Improve the performance, observability, reliability, and failure recovery of execution and isolation infrastructure.
  • Partner with Platform, Security, and Backend Engineering teams to define technical interfaces, troubleshoot production issues, and deploy infrastructure improvements.
Requirements:
  • Professional experience developing production-grade systems software using Go, Rust, C, or C++.
  • Strong understanding of Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management.
  • Hands-on experience implementing or operating sandboxing or workload-isolation technologies such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines.
  • Experience building networking infrastructure involving TCP/IP, transparent proxying, TLS termination, or TLS origination.
  • Practical experience with process isolation, privilege separation, protected credential handling, or related operating-system security controls.
  • Experience with multi-tenant container, sandbox, or virtual-machine isolation infrastructure is highly valued.
  • Familiarity with workload identity and attestation frameworks such as SPIFFE or SPIRE is a plus.
  • Experience with cloud key-management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS is desirable.
  • Background in endpoint security, EDR, zero-trust networking, infrastructure security, Kubernetes, container runtimes, or managed container platforms is advantageous.
  • Experience with Temporal or another durable workflow execution platform is a plus.
  • Strong analytical, troubleshooting, and collaboration skills, with the ability to work effectively across infrastructure, security, and backend teams.
Benefits:
  • Base salary range of CAD $160,000–$240,000 per year for the Toronto position.
  • Full-time employment with opportunities to work on advanced Linux, networking, cloud, and security infrastructure.
  • Additional benefits and rewards may be available depending on the role and individual impact.
  • Potential eligibility for additional incentive compensation, depending on the applicable role and plan.
  • Opportunity to work with cutting-edge technologies in a high-growth, high-performance environment.
  • Collaboration with multidisciplinary Platform, Security, and Backend Engineering teams.
  • Professional growth opportunities in systems engineering, cloud infrastructure, and cybersecurity.
  • Inclusive workplace committed to equal employment opportunity and a diverse workforce.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Canada, M5V 3L9, Canada

Frequently asked questions about this position

Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.