





Metro location and generic engineer title increase competition, but niche low-level sandboxing skills reduce applicant density.
Highly specialized Linux kernel, sandboxing, and security skills reduce cross-industry transferability.
Many mandatory low-level systems, sandboxing technologies, and language preferences create high filtering for candidates.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Design and build low-level process isolation, sandboxing, and network interception infrastructure for secure sidecar architectures at scale, operating at OS, networking, and process boundary layers.
Develop and maintain the Fleet sidecar proxy to intercept outbound vendor API calls at the TCP layer, enforce credential and compliance policies, and create tamper-evident audit logs without application-level instrumentation.
Manage namespace and workload isolation at scale, including startup processes involving KMS credential fetch, OAuth token warming, iptables installation, and readiness signaling before workload start.
Deep expertise in Linux systems including iptables/netfilter, process namespaces, cgroups, socket options, and Unix domain sockets.
Experience with at least one sandboxing or isolation technology such as gVisor, Firecracker micro VMs, or WASM runtimes.
Strong networking fundamentals covering TCP/IP stack, transparent proxying, TLS termination and origination.
Work Experience Required: Not explicitly mentioned in the JD.
Experienced in building and operating multi-tenant container or VM isolation infrastructures for secure environments.
Skilled in low-level systems programming with proficiency in Go or Rust; familiarity with C/C++ is a plus.
Knowledgeable about security tooling domains such as EDR, zero-trust networking, and infrastructure-level KMS integrations (AWS KMS, Azure Key Vault).