Senior Systems Security Architect - Sandboxing & Runtime Virtualization
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
Because the Autonomous Security Architect (ASA) ingests, compiles, and tests untrusted, potentially malicious third-party open-source dependencies at global scale, we require a low-level Linux systems engineer to build our “containment arena.” As our Senior Systems Security Architect, you will own the runtime virtualization layers, ensuring that all automated code execution, compilation trials, and symbolic analysis are securely trapped inside ultra-fast, isolated sandbox architectures., * Design, orchestrate, and optimize high-speed, ephemeral compilation environments using micro-hypervisors.
- Implement kernel-level security isolation profiles, memory separation constraints, cgroups, and network namespaces.
- Build high-throughput webhook integration frameworks to capture repository package dependency updates (GitHub, Crates.io, npm).
- Optimize multi-tenant multi-processing pipelines to ensure sandbox creation and teardown cycles execute at sub-second speeds.
Requirements
- Bachelor’s or Master’s degree in Computer Engineering, Computer Science, or Systems Software.
- 4+ years of professional experience in low-level Linux systems programming, kernel isolation, or security virtualization.
- Verifiable hands-on mastery with AWS Firecracker micro-VMs, KVM, QEMU, or writing custom secure containers via Rust/C primitives.
- Complete comfort managing secure asynchronous messaging queues (Kafka, RabbitMQ) handling telemetry streams., * Question 1 (Yes/No): Do you have 3+ years of low-level Linux systems programming experience, specifically working with kernel isolation primitives such as namespaces, cgroups, chroot, or KVM hypervisors?Question 2 (Yes/No): Have you explicitly engineered or orchestrated highly secure, ephemeral sandboxing containment environments utilizing AWS Firecracker micro-VMs?Question 3 (Free Text - Limit 250 characters): Which asynchronous message broker or streaming platform (e.g., Kafka, RabbitMQ, Redis) have you scaled to process high-volume, real-time application log or telemetry queues?Question 4 (Yes/No): Did you include your functional shell/Python isolation automation script for the mandatory 48-Hour Sandboxing challenge?, * Master’s (Preferred)
Benefits & conditions
Please submit your technical solution to the following prompt alongside your application:
- Provide a clean Python or Bash automation script demonstrating how to securely isolate an untrusted code compilation shell using standard Linux primitives (namespaces, chroot, or cgroups) or define an optimized configuration profile managing CPU/Memory constraints for an ephemeral micro-VM.
- Ensure your script includes explicit error catching parameters to safely tear down the temporary containment volume if the compilation loop freezes or attempts an illegal memory access.
Pay: $75.00 - $85.00 per hour
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 138 - Are you secure about this?
Dev Digest 121 - AI goes offline
Dev Digest 131 - AI'm not sure about OSS