Staff Systems Engineer
Core
Design and build low-level process isolation, sandboxing, and network interception infrastructure for secure sidecar architecture at scale.
Role type
Staff Systems Engineer (Linux/Networking/Security Infrastructure)
Builds
Fleet sidecar (transparent TCP proxy), process isolation mechanisms, language-agnostic sandboxing platform, namespace isolation infrastructure
Domain
Cybersecurity, Cloud Infrastructure, Systems Programming
Deliverable
production ML models | product features | infrastructure
Required skills
Linux systems programming, iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets, TCP/IP stack, TLS termination, memory management, privilege separation
Preferred skills
gVisor, Firecracker micro VMs, WASM runtimes, SPIFFE/SPIRE, KMS integrations, multi-tenant container/VM isolation, security tooling (EDR/zero-trust)
Technologies
gVisor, Firecracker, WASM, Temporal, iptables, Rust, Go, C/C++, AWS KMS, Azure Key Vault
Responsibilities
Design and build process isolation and sandboxing infrastructure; implement transparent TCP proxying for credential management; develop language-agnostic sandboxing solutions; manage namespace isolation at scale; implement sidecar startup sequencing
Seniority
Staff, hands-on IC
