Skip to main content
Posted 30 August, 2026

Staff Systems Engineer

Kaseya Careers
Pune, India Full Time
Reference: 102_699653_6146948004

Position Summary:

Kaseya is looking for an Intelligence Systems Engineer to design and build the low-level process isolation, sandboxing, and network interception infrastructure that powers secure sidecar architecture at scale. This role focuses on Linux systems, networking, process boundaries, and security infrastructure rather than application-layer development. You role is focused, but not limited to:

  • You will design and build the process isolation, sandboxing, and network interception infrastructure that makes sidecar architecture work at scale.
  • This is low-level systems work who will be operating at the OS, networking, and process boundary layer, not the application layer.
  • Build and maintain the Fleet sidecar: a per-workload transparent authenticating proxy that intercepts all outbound vendor API calls at the TCP layer via iptables, enforces credential management and compliance policy, and writes tamper-evident audit ledger entries: all without any app-level instrumentation
  • Implement and harden process isolation between the sidecar and automation workload processes: separate UIDs, ptrace restrictions, mlock'd credential memory, explicit zeroing of plaintext after use
  • Develop and refine language-agnostic sandboxing approaches: evaluate and implement solutions across gVisor, micro VMs, WASM, and Unix domain socket-based isolation patterns; the platform must support automation workloads written in any language
  • Manage namespace isolation at scale: this platform runs thousands of Temporal namespaces for client orgs; you will work on the infrastructure that keeps those boundaries structurally enforced, not just configured
  • Evaluate and potentially adopt SPIFFE/SPIRE for workload identity attestation within the sandboxed execution environment
  • Work on sidecar startup sequencing: KMS credential fetch, OAuth token warming, iptables rule installation, and readiness signaling all before the workload process starts

Required Qualification:

  • Deep Linux systems experience: iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets
  • Experience with at least one sandboxing or isolation technology: gVisor, Firecracker micro VMs, WASM runtimes, or equivalent
  • Strong networking fundamentals: TCP/IP stack, transparent proxying, TLS termination and origination
  • Language-agnostic mindset : you design platforms that other languages run on top of, not systems tied to a single runtime
  • Comfort working close to the OS: memory management, process lifecycle, privilege separation
  • Familiarity with SPIFFE/SPIRE or similar workload identity frameworks is a strong plus
  • Go or Rust strongly preferred; C/C++ experience relevant

Preferred Qualification:

  • Experience building or operating multi-tenant container or VM isolation infrastructure
  • Prior work in security tooling, EDR, or zero-trust networking
  • Familiarity with KMS integrations (AWS KMS, Azure Key Vault) at the infrastructure level

Sign up for Job Alerts