Senior Systems Security Architect - Sandboxing & Runtime Virtualization

Shimhalal Fiscal Governance, LLC
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$156,000.0 - $176,800.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Bash Shell Compilers Computer Engineering Linux Github Python (Programming Language) Kernel-Based Virtual Machine Message Broker Quick EMUlator (QEMU) RabbitMQ Redis
+7 more
Message Oriented Middleware Software Engineering Data Streaming Virtualization Technology Information Technology Integration Frameworks Apache Kafka

Job description

Because the Autonomous Security Architect (ASA) ingests, compiles, and tests untrusted, potentially malicious third-party open-source dependencies at global scale, we require a low-level Linux systems engineer to build our “containment arena.” As our Senior Systems Security Architect, you will own the runtime virtualization layers, ensuring that all automated code execution, compilation trials, and symbolic analysis are securely trapped inside ultra-fast, isolated sandbox architectures., * Design, orchestrate, and optimize high-speed, ephemeral compilation environments using micro-hypervisors.

  • Implement kernel-level security isolation profiles, memory separation constraints, cgroups, and network namespaces.
  • Build high-throughput webhook integration frameworks to capture repository package dependency updates (GitHub, Crates.io, npm).
  • Optimize multi-tenant multi-processing pipelines to ensure sandbox creation and teardown cycles execute at sub-second speeds.

Requirements

  • Bachelor’s or Master’s degree in Computer Engineering, Computer Science, or Systems Software.
  • 4+ years of professional experience in low-level Linux systems programming, kernel isolation, or security virtualization.
  • Verifiable hands-on mastery with AWS Firecracker micro-VMs, KVM, QEMU, or writing custom secure containers via Rust/C primitives.
  • Complete comfort managing secure asynchronous messaging queues (Kafka, RabbitMQ) handling telemetry streams., * Question 1 (Yes/No): Do you have 3+ years of low-level Linux systems programming experience, specifically working with kernel isolation primitives such as namespaces, cgroups, chroot, or KVM hypervisors?Question 2 (Yes/No): Have you explicitly engineered or orchestrated highly secure, ephemeral sandboxing containment environments utilizing AWS Firecracker micro-VMs?Question 3 (Free Text - Limit 250 characters): Which asynchronous message broker or streaming platform (e.g., Kafka, RabbitMQ, Redis) have you scaled to process high-volume, real-time application log or telemetry queues?Question 4 (Yes/No): Did you include your functional shell/Python isolation automation script for the mandatory 48-Hour Sandboxing challenge?, * Master’s (Preferred)

Benefits & conditions

Please submit your technical solution to the following prompt alongside your application:

  • Provide a clean Python or Bash automation script demonstrating how to securely isolate an untrusted code compilation shell using standard Linux primitives (namespaces, chroot, or cgroups) or define an optimized configuration profile managing CPU/Memory constraints for an ephemeral micro-VM.
  • Ensure your script includes explicit error catching parameters to safely tear down the temporary containment volume if the compilation loop freezes or attempts an illegal memory access.

Pay: $75.00 - $85.00 per hour

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Resolving questions on module splitting and supply chain security

Stefan Schöberl · World Congress 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:55 min

Demonstrating semantic routing thresholds with the Redis vector library

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all