Staff Systems Engineer
About Kaseya
Kaseya is the leading provider of AI-powered IT management and cybersecurity software, serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Our comprehensive platform helps organizations efficiently manage, secure, and automate their IT environments, driving operational efficiency and long-term business success.
Backed by Insight Partners , a leading global software investor, Kaseya has experienced sustained double-digit growth and continues to expand its global footprint. Today, Kaseya supports customers in more than 20 countries and manages over 15 million endpoints worldwide.
Founded in 2000, Kaseya was built by builders - and we're still building. We look for people who create rather than wait, who see a hard problem and lean in, and who treat challenges as raw material. At Kaseya, everyone plays a role in shaping the future of IT: whether you're in engineering, product, sales, marketing, customer support, or operations, your work helps protect, defend, and optimize IT environments across the globe.
We're building teams that grow, perform, and make an impact. If you're driven by the itch to make things better - a product, a process, a career - you'll fit right in.
At Kaseya, we don't just raise the bar. We build it.
Position Summary:
Kaseya is looking for an Intelligence Systems Engineer to design and build the low-level process isolation, sandboxing, and network interception infrastructure that powers secure sidecar architecture at scale. This role focuses on Linux systems, networking, process boundaries, and security infrastructure rather than application-layer development. You role is focused, but not limited to:
You will design and build the process isolation, sandboxing, and network interception infrastructure that makes sidecar architecture work at scale.
This is low-level systems work who will be operating at the OS, networking, and process boundary layer, not the application layer.
Build and maintain the Fleet sidecar: a per-workload transparent authenticating proxy that intercepts all outbound vendor API calls at the TCP layer via iptables, enforces credential management and compliance policy, and writes tamper-evident audit ledger entries: all without any app-level instrumentation
Implement and harden process isolation between the sidecar and automation workload processes: separate UIDs, ptrace restrictions, mlock'd credential memory, explicit zeroing of plaintext after use
Develop and refine language-agnostic sandboxing approaches: evaluate and implement solutions across gVisor, micro VMs, WASM, and Unix domain socket-based isolation patterns; the platform must support automation workloads written in any language
Manage namespace isolation at scale: this platform runs thousands of Temporal namespaces for client orgs; you will work on the infrastructure that keeps those boundaries structurally enforced, not just configured
Evaluate and potentially adopt SPIFFE/SPIRE for workload identity attestation within the sandboxed execution environment
Work on sidecar startup sequencing: KMS credential fetch, OAuth token warming, iptables rule installation, and readiness signaling all before the workload process starts
Required Qualification:
Deep Linux systems experience: iptables/netfilter, process namespaces, cgroups, socket options, Unix domain sockets
Experience with at least one sandboxing or isolation technology: gVisor, Firecracker micro VMs, WASM runtimes, or equivalent
Strong networking fundamentals: TCP/IP stack, transparent proxying, TLS termination and origination
Language-agnostic mindset : you design platforms that other languages run on top of, not systems tied to a single runtime
Comfort working close to the OS: memory management, process lifecycle, privilege separation
Familiarity with SPIFFE/SPIRE or similar workload identity frameworks is a strong plus
Go or Rust strongly preferred; C/C++ experience relevant
Preferred Qualification:
Experience building or operating multi-tenant container or VM isolation infrastructure
Prior work in security tooling, EDR, or zero-trust networking
Familiarity with KMS integrations (AWS KMS, Azure Key Vault) at the infrastructure level
Additional information Kaseya provides equal employment opportunity to all employees and applicants without regard to race, religion, age, ancestry, gender, sex, sexual orientation, national origin, citizenship status, physical or mental disability, veteran status, marital status, or any other characteristic protected by applicable law.