Staff Systems Engineer
Core
Design and build process isolation, sandboxing, and network interception infrastructure for a secure sidecar architecture and fleet authentication proxy.
Role type
Staff Systems Engineer (Security Infrastructure)
Builds
Secure sidecar architecture, Fleet transparent authenticating proxy, and multi-tenant namespace isolation.
Domain
Cloud Security / Systems Engineering
Deliverable
production ML models | product features | infrastructure
Required skills
Deep Linux systems experience, iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets, TCP/IP, transparent proxying, TLS termination, memory management, process lifecycle, privilege separation
Preferred skills
Go or Rust, C or C++, gVisor, Firecracker micro VMs, WebAssembly runtimes, SPIFFE/SPIRE, multi-tenant container or VM isolation infrastructure, security tooling, EDR, zero-trust networking, infrastructure-level KMS integrations
Technologies
gVisor, Firecracker, WebAssembly, SPIFFE, SPIRE, AWS KMS, Azure Key Vault, iptables, netfilter, cgroups
Responsibilities
Design and build process isolation, sandboxing, and network interception infrastructure; Build and maintain the Fleet transparent authenticating proxy; Harden isolation between sidecars and automation workloads; Evaluate and implement sandboxing approaches; Maintain structural namespace isolation; Implement sidecar startup sequencing for credential retrieval and readiness signaling
Seniority
Staff, hands-on IC
