> Markdown version of [/jobs/ext/1919314-senior-systems-security-architect-sandboxing-runtime-virtualization](https://www.wearedevelopers.com/jobs/ext/1919314-senior-systems-security-architect-sandboxing-runtime-virtualization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Systems Security Architect - Sandboxing & Runtime Virtualization - **Company:** Shimhalal Fiscal Governance, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $156,000.0 - $176,800.0 - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Bash Shell, Compilers, Computer Engineering, Linux, Github, Python (Programming Language), Kernel-Based Virtual Machine, Message Broker, Quick EMUlator (QEMU), RabbitMQ, Redis, Message Oriented Middleware, Software Engineering, Data Streaming, Virtualization Technology, Information Technology, Integration Frameworks, Apache Kafka - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f478dffb3a2704ad ## About the Role * Bachelor's or Master's degree in Computer Engineering, Computer Science, or Systems Software. * 4+ years of professional experience in low-level Linux systems programming, kernel isolation, or security virtualization. * Verifiable hands-on mastery with AWS Firecracker micro-VMs, KVM, QEMU, or writing custom secure containers via Rust/C primitives. * Complete comfort managing secure asynchronous messaging queues (Kafka, RabbitMQ) handling telemetry streams., * Question 1 (Yes/No): Do you have 3+ years of low-level Linux systems programming experience, specifically working with kernel isolation primitives such as namespaces, cgroups, chroot, or KVM hypervisors?Question 2 (Yes/No): Have you explicitly engineered or orchestrated highly secure, ephemeral sandboxing containment environments utilizing AWS Firecracker micro-VMs?Question 3 (Free Text - Limit 250 characters): Which asynchronous message broker or streaming platform (e.g., Kafka, RabbitMQ, Redis) have you scaled to process high-volume, real-time application log or telemetry queues?Question 4 (Yes/No): Did you include your functional shell/Python isolation automation script for the mandatory 48-Hour Sandboxing challenge?, * Master's (Preferred) ## Description Because the Autonomous Security Architect (ASA) ingests, compiles, and tests untrusted, potentially malicious third-party open-source dependencies at global scale, we require a low-level Linux systems engineer to build our "containment arena." As our Senior Systems Security Architect, you will own the runtime virtualization layers, ensuring that all automated code execution, compilation trials, and symbolic analysis are securely trapped inside ultra-fast, isolated sandbox architectures., * Design, orchestrate, and optimize high-speed, ephemeral compilation environments using micro-hypervisors. * Implement kernel-level security isolation profiles, memory separation constraints, cgroups, and network namespaces. * Build high-throughput webhook integration frameworks to capture repository package dependency updates (GitHub, Crates.io, npm). * Optimize multi-tenant multi-processing pipelines to ensure sandbox creation and teardown cycles execute at sub-second speeds. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Challenges of Breaking A Monolith](https://www.wearedevelopers.com/videos/362-security-challenges-of-breaking-a-monolith) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges)