Logo for Kaseya

Systems Engineer — Linux Isolation & Networking

Role overview

Qualifications

  • Experience developing production systems software using Go, Rust, C, or C++
  • Experience working with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management
  • Experience implementing or operating at least one sandboxing or workload-isolation technology, such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines
  • Experience building networking infrastructure involving TCP/IP, transparent proxying, or TLS termination and origination

Responsibilities

  • Build and operate a transparent sidecar proxy that intercepts outbound vendor API calls, enforces credential and compliance policies, and records tamper-evident audit events
  • Implement process-isolation controls using Linux users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and explicit credential cleanup
  • Evaluate and implement sandboxing approaches using technologies such as gVisor, Firecracker, WebAssembly runtimes, or Unix-domain-socket isolation
  • Design infrastructure that enforces workload and customer boundaries across large numbers of isolated execution environments

About the company

Kaseya logo

Kaseya

Computer Software / SaaS

Kaseya is a premier provider of unified IT management and security software for managed service providers (MSPs) and small to medium-sized businesses (SMBS). Through its customer-centric approach, Kaseya delivers best-in-breed technologies that allow organizations to efficiently manage, secure and backup IT. Kaseya offers a broad array of IT management solutions, including well-known names: Kaseya, Datto, IT Glue, RapidFire Tools, Spanning Cloud Apps, ID Agent, Vonahi, audIT, Graphus, RocketCyber, TruMethods and Unitrends. These solutions empower businesses to command all of IT centrally, easily manage remote and distributed environments, simplify backup and disaster recovery, safeguard against cybersecurity attacks, effectively manage compliance and network assets, streamline IT documentation and automate across IT management functions. Headquartered in Miami, Florida, Kaseya is privately held with a presence in over 20 countries.

Company details

Company typeXLarge
IndustryComputer Software / SaaS
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Kaseya

Kaseya is the leading provider of AI-powered IT management and cybersecurity software, serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Our comprehensive platform helps organizations efficiently manage, secure, and automate their IT environments, driving operational efficiency and long-term business success.

Backed by Insight Partners, a leading global software investor, Kaseya has experienced sustained double-digit growth and continues to expand its global footprint. Today, Kaseya supports customers in more than 20 countries and manages over 15 million endpoints worldwide.

Founded in 2000, Kaseya has built a culture centered around innovation, accountability, and results. We are a high-growth, high-performance organization that values individuals who are driven, adaptable, and committed to delivering exceptional outcomes for our customers and teammates alike.

At Kaseya, success comes from embracing challenges, moving with urgency, and continuously raising the bar. 

Systems Engineer — Linux Isolation & Networking

Locations: Toronto, ON — 2 openings
Employment Type: Full-time

Why Kaseya?

Join a fast-growing company that’s transforming the IT industry. At Kaseya, you’ll have the opportunity to work with cutting-edge technology, collaborate with a dynamic team, and develop your career in a high impact role.

Join the Kaseya growth rocket ship and see how we are #ChangingLives!

Job Summary

We’re hiring Systems Engineers to build the process-isolation, sandboxing, and network-interception infrastructure that enables secure workload execution across the Kaseya Intelligence Platform. This is low-level engineering at the Linux, networking, and process boundary rather than application-layer development. You’ll build language-independent infrastructure that isolates workloads, protects credentials, and enforces security controls across multi-tenant environments.

Roles & Responsibilities

  • Build and operate a transparent sidecar proxy that intercepts outbound vendor API calls, enforces credential and compliance policies, and records tamper-evident audit events

  • Implement process-isolation controls using Linux users and permissions, namespaces, cgroups, ptrace restrictions, protected memory, and explicit credential cleanup

  • Evaluate and implement sandboxing approaches using technologies such as gVisor, Firecracker, WebAssembly runtimes, or Unix-domain-socket isolation

  • Design infrastructure that enforces workload and customer boundaries across large numbers of isolated execution environments

  • Evaluate and integrate workload identity and attestation technologies such as SPIFFE and SPIRE

  • Implement secure workload startup sequencing, including KMS access, token preparation, network-rule installation, and readiness signalling

  • Improve the performance, observability, reliability, and failure recovery of the execution and isolation layers

  • Partner with Platform, Security, and Backend Engineering teams to define interfaces, investigate production issues, and deploy platform improvements

Required Qualifications

  • Experience developing production systems software using Go, Rust, C, or C++

  • Experience working with Linux internals, including namespaces, cgroups, netfilter or iptables, sockets, and process lifecycle management

  • Experience implementing or operating at least one sandboxing or workload-isolation technology, such as gVisor, Firecracker, WebAssembly, containers, or micro virtual machines

  • Experience building networking infrastructure involving TCP/IP, transparent proxying, or TLS termination and origination

  • Experience implementing process isolation, privilege separation, protected credential handling, or related operating-system security controls

Preferred Qualifications

  • Experience building or operating multi-tenant container, sandbox, or virtual-machine isolation infrastructure

  • Experience with SPIFFE, SPIRE, or another workload identity and attestation framework

  • Experience integrating AWS KMS, Azure Key Vault, GCP Cloud KMS, or similar key-management services

  • Experience working on endpoint security, EDR, zero-trust networking, or infrastructure security products

  • Experience with Kubernetes, container-runtime internals, or managed container platforms

  • Experience with Temporal or another durable workflow execution platform

  • Experience supporting systems subject to security, privacy, or compliance requirements

Compensation Range — Toronto Posting Only

The base salary range for this job is CAD $160,000 – $240,000 / year.

An individual’s base pay depends on various factors including geographical location and review of experience, knowledge, skills, and abilities of the applicant. At Kaseya, certain roles are eligible for benefits and additional rewards. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee’s role.

Additional Information

Kaseya provides equal employment opportunity to all employees and applicants without regard to race, religion, age, ancestry, gender, sex, sexual orientation, national origin, citizenship status, physical or mental disability, veteran status, marital status, or any other characteristic protected by applicable law.

Additional information
Kaseya provides equal employment opportunity to all employees and applicants without regard to race, religion, age, ancestry, gender, sex, sexual orientation, national origin, citizenship status, physical or mental disability, veteran status, marital status, or any other characteristic protected by applicable law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

System Engineer Related jobs

Other jobs at Kaseya

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.