CareerPlanGet AI match score →

Senior Software Engineer (Isolation/Sandboxing)

💼 Full-time🗓 2026-06-24

Core

Designing and implementing secure workload isolation and sandboxing mechanisms for user-generated and AI-generated code execution across the Linux system stack.

Role type

Senior IC systems software engineer (sandboxing/isolation)

Builds

Secure execution environments, sandboxing platforms, and system-level services

Domain

Operating systems, systems programming, security, and distributed infrastructure

Deliverable

production ML models | product features | infrastructure

Required skills

Linux internals, systems programming, networking fundamentals (L2/L3/L4), TCP/IP, HTTP and service communication, debugging complex distributed systems, performance analysis and optimization, design and implementation of production-grade software

Preferred skills

C, Go, Rust, eBPF, network traffic optimization, congestion control, cryptography, security architecture, Kubernetes internals, protocol design

Technologies

gVisor, KVM, container runtimes, virtualization technologies, containerd, CRI-O, Linux security frameworks

Responsibilities

Building and improving secure workload isolation systems, designing and implementing sandboxing mechanisms, investigating and optimizing system performance, profiling large distributed systems, improving networking performance and traffic management, designing and evolving internal protocols, contributing to and debugging system-level services, driving technical projects from architecture to production rollout

Rewrite
## About the role Who We Are Looking For We are looking for a Senior / Staff Software Engineer with a strong background in systems programming, Linux internals, performance optimization, and workload isolation. This is not a typical backend, DevOps, SRE, or infrastructure engineering role. We need someone who can work across multiple layers of the system stack, from Linux kernel mechanisms and networking to application-level services and security controls. The ideal candidate has experience designing, implementing, and optimizing complex systems where security, isolation, and performance are equally important. ## What You'll Work On - Building and improving secure workload isolation systems - Designing and implementing sandboxing mechanisms for user-generated and AI-generated code execution - Working with Linux security primitives such as: namespaces cgroups seccomp permissions and access controls - Investigating and optimizing system performance across multiple layers of the stack - Profiling large distributed systems and identifying bottlenecks - Improving networking performance and traffic management - Designing and evolving internal protocols and service communication mechanisms - Contributing to and debugging system-level services and infrastructure components - Evaluating and integrating technologies such as: gVisor KVM container runtimes virtualization technologies - Driving technical projects from architecture and requirements gathering through implementation and production rollout ## Ideal Background We are looking for engineers who have worked on one or more of: - Linux kernel-adjacent systems - Sandboxing and isolation platforms - Container runtimes - Hypervisors and virtualization - Cloud infrastructure internals - Performance engineering - Operating systems - Networking infrastructure - Security-focused systems programming Examples include engineers who have contributed to: - gVisor - Kata Containers - Firecracker - containerd - CRI-O - KVM-based platforms - Linux security frameworks - Large-scale distributed infrastructure ## Required Skills Strong expertise in - Linux internals - Systems programming - Networking fundamentals (L2/L3/L4) - TCP/IP - HTTP and service communication - Debugging complex distributed systems - Performance analysis and optimization - Designing and implementing production-grade software - Programming Languages ## Preferred - C - Go - Rust - Other languages are acceptable if the candidate has strong systems engineering experience. ## Nice to Have - eBPF - Network traffic optimization - Congestion control - Cryptography - Security architecture - Kubernetes internals - Cloud infrastructure - Protocol design - Open-source contributions ## What We Are Not Looking For This role is generally not a fit for: - Traditional DevOps engineers - Infrastructure engineers focused primarily on operations - Backend engineers without low-level systems experience - Security specialists who have only worked on security and not on broader system architecture - Engineers whose experience is limited to application-level development ## Seniority
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗