Staff Systems Engineer

Kaseya Limited

Pune District

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Kaseya is seeking an Intelligence Systems Engineer to design and build low-level process isolation, sandboxing, and network interception infrastructure powering secure sidecar architecture at scale. The role focuses on Linux systems, networking, and security, not application-layer development.

You will design, implement and harden the Fleet sidecar, manage namespace isolation for thousands of Temporal namespaces, and evaluate workload-identity frameworks like SPIFFE/SPIRE.

Qualifications

  • Deep Linux systems experience including iptables/netfilter and namespaces.
  • Experience with sandboxing or isolation tech such as gVisor, Firecracker, WASM, or equivalent.
  • Strong networking knowledge: TCP/IP, TLS, proxying.
  • Language-agnostic platform design rather than a single runtime.

Responsibilities

  • Design and build the process isolation, sandboxing, and network interception infrastructure at scale for sidecar architecture.
  • Operate at the OS, networking and process boundary layer, not the application layer.
  • Build and maintain Fleet sidecar: a per-workload proxy intercepting outbound API calls at TCP layer.
  • Enforce credential management, compliance policy, and tamper-evident audit entries.
  • Hardening: separate UIDs, ptrace restrictions, memory zeroing after use.
  • Develop sandboxing approaches with gVisor, micro VM, WASM, or similar patterns.
  • Manage namespace isolation; thousands of Temporal namespaces to enforce boundaries.
  • Evaluate SPIFFE/SPIRE for workload identity in sandboxed execution.
  • Address sidecar startup sequencing: KMS fetch, OAuth warmup, iptables, readiness signaling.

Skills

Linux systems
Networking fundamentals
Go
Rust
C/C++
Security tooling
Memory management
Process isolation

Tools

iptables
netfilter
SPIFFE/SPIRE
KMS integrations
Unix domain sockets

Job description

About Kaseya

Kaseya is the leading provider of AI-powered IT management and cybersecurity software, serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Our comprehensive platform helps organizations efficiently manage, secure, and automate their IT environments, driving operational efficiency and long-term business success.

Backed by Insight Partners, a leading global software investor, Kaseya has experienced sustained double-digit growth and continues to expand its global footprint. Today, Kaseya supports customers in more than 20 countries and manages over 15 million endpoints worldwide.

Founded in 2000, Kaseya has built a culture centered around innovation, accountability, and results. We are a high-growth, high-performance organization that values individuals who are driven, adaptable, and committed to delivering exceptional outcomes for our customers and teammates alike.

At Kaseya, success comes from embracing challenges, moving with urgency, and continuously raising the bar.

Position Summary:

Kaseya is looking for an Intelligence Systems Engineer to design and build the low-level process isolation, sandboxing, and network interception infrastructure that powers secure sidecar architecture at scale. This role focuses on Linux systems, networking, process boundaries, and security infrastructure rather than application-layer development. You role is focused, but not limited to:

  • You will design and build the process isolation, sandboxing, and network interception infrastructure that makes sidecar architecture work at scale.
  • This is low-level systems work who will be operating at the OS, networking, and process boundary layer, not the application layer.
  • Build and maintain the Fleet sidecar: a per-workload transparent authenticating proxy that intercepts all outbound vendor API calls at the TCP layer via iptables, enforces credential management and compliance policy, and writes tamper-evident audit ledger entries: all without any app-level instrumentation
  • Implement and harden process isolation between the sidecar and automation workload processes: separate UIDs, ptrace restrictions, mlock'd credential memory, explicit zeroing of plaintext after use
  • Develop and refine language-agnostic sandboxing approaches: evaluate and implement solutions across gVisor, micro VMs, WASM, and Unix domain socket-based isolation patterns; the platform must support automation workloads written in any language
  • Manage namespace isolation at scale: this platform runs thousands of Temporal namespaces for client orgs; you will work on the infrastructure that keeps those boundaries structurally enforced, not just configured
  • Evaluate and potentially adopt SPIFFE/SPIRE for workload identity attestation within the sandboxed execution environment
  • Work on sidecar startup sequencing: KMS credential fetch, OAuth token warming, iptables rule installation, and readiness signaling all before the workload process starts

Required Qualification:

  • Deep Linux systems experience: iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets
  • Experience with at least one sandboxing or isolation technology: gVisor, Firecracker micro VMs, WASM runtimes, or equivalent
  • Strong networking fundamentals: TCP/IP stack, transparent proxying, TLS termination and origination
  • Language-agnostic mindset : you design platforms that other languages run on top of, not systems tied to a single runtime
  • Comfort working close to the OS: memory management, process lifecycle, privilege separation
  • Familiarity with SPIFFE/SPIRE or similar workload identity frameworks is a strong plus
  • Go or Rust strongly preferred; C/C++ experience relevant

Preferred Qualification:

  • Experience building or operating multi-tenant container or VM isolation infrastructure
  • Prior work in security tooling, EDR, or zero-trust networking
  • Familiarity with KMS integrations (AWS KMS, Azure Key Vault) at the infrastructure level

Additional information
Kaseya provides equal employment opportunity to all employees and applicants without regard to race, religion, age, ancestry, gender, sex, sexual orientation, national origin, citizenship status, physical or mental disability, veteran status, marital status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Systems Engineer
Staff Systems Engineer

Kaseya • Maharashtra

On-site
INR 420,000 - 660,000
Kubernetes Systems Engineer
Kubernetes Systems Engineer

Kaseya Limited • Pune District

On-site
INR 3,500,000 - 5,500,000
Senior Staff Software Engineer - 260421-5
Senior Staff Software Engineer - 260421-5

Kaseya Limited • Pune District

On-site
INR 3,000,000 - 5,500,000
Staff Software Engineer - 260421-4
Staff Software Engineer - 260421-4

kaseya • Pune District

On-site
INR 4,000,000 - 7,000,000
Senior Staff Software Engineer - 260421-5
Senior Staff Software Engineer - 260421-5

kaseya • Pune District

On-site
INR 3,500,000 - 6,000,000
Senior Staff Software Engineer - 260421-5
Senior Staff Software Engineer - 260421-5

Kaseya • Maharashtra

On-site
INR 5,000,000 - 9,000,000
Senior Software Engineer
Senior Software Engineer

Kaseya • Pune District

On-site
INR 1,500,000 - 2,000,000
Principal Software Engineer
Principal Software Engineer

Kaseya • Maharashtra

On-site
INR 2,500,000 - 3,500,000
Staff Software Engineer
Staff Software Engineer

Kaseya • Maharashtra

On-site
INR 4,000,000 - 6,500,000
Staff Software Engineer (Golang)
Staff Software Engineer (Golang)

Kaseya • Maharashtra

On-site
INR 3,500,000 - 5,500,000
Competitive salary and benefits