Posted 30 August, 2026
Staff Systems Engineer
Kaseya Careers
Pune, India
Full Time
Reference: 102_699653_6146948004
Position Summary:
Kaseya is looking for an Intelligence Systems Engineer to design and build the low-level process isolation, sandboxing, and network interception infrastructure that powers secure sidecar architecture at scale. This role focuses on Linux systems, networking, process boundaries, and security infrastructure rather than application-layer development. You role is focused, but not limited to:
- You will design and build the process isolation, sandboxing, and network interception infrastructure that makes sidecar architecture work at scale.
- This is low-level systems work who will be operating at the OS, networking, and process boundary layer, not the application layer.
- Build and maintain the Fleet sidecar: a per-workload transparent authenticating proxy that intercepts all outbound vendor API calls at the TCP layer via iptables, enforces credential management and compliance policy, and writes tamper-evident audit ledger entries: all without any app-level instrumentation
- Implement and harden process isolation between the sidecar and automation workload processes: separate UIDs, ptrace restrictions, mlock'd credential memory, explicit zeroing of plaintext after use
- Develop and refine language-agnostic sandboxing approaches: evaluate and implement solutions across gVisor, micro VMs, WASM, and Unix domain socket-based isolation patterns; the platform must support automation workloads written in any language
- Manage namespace isolation at scale: this platform runs thousands of Temporal namespaces for client orgs; you will work on the infrastructure that keeps those boundaries structurally enforced, not just configured
- Evaluate and potentially adopt SPIFFE/SPIRE for workload identity attestation within the sandboxed execution environment
- Work on sidecar startup sequencing: KMS credential fetch, OAuth token warming, iptables rule installation, and readiness signaling all before the workload process starts
Required Qualification:
- Deep Linux systems experience: iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets
- Experience with at least one sandboxing or isolation technology: gVisor, Firecracker micro VMs, WASM runtimes, or equivalent
- Strong networking fundamentals: TCP/IP stack, transparent proxying, TLS termination and origination
- Language-agnostic mindset : you design platforms that other languages run on top of, not systems tied to a single runtime
- Comfort working close to the OS: memory management, process lifecycle, privilege separation
- Familiarity with SPIFFE/SPIRE or similar workload identity frameworks is a strong plus
- Go or Rust strongly preferred; C/C++ experience relevant
Preferred Qualification:
- Experience building or operating multi-tenant container or VM isolation infrastructure
- Prior work in security tooling, EDR, or zero-trust networking
- Familiarity with KMS integrations (AWS KMS, Azure Key Vault) at the infrastructure level