🤫husshhussh
🤫husshhusshOnePuppy
Systems software · H06

Virtualization and Sandboxing Engineer

Let people add useful tools without giving every tool access to their lives. You will build the isolation around models, plugins and remote jobs.

See what is open todayAll roles

Not open yet: Pilot expansion

This work starts when that stage arrives, so there is no application to submit today and we will not pretend otherwise. What is written below is what the role is for and what would make somebody right for it, published early on purpose so you can decide whether it is worth watching.

The work

What this person actually does

Evaluate processes, containers, virtual machines and capability-based restrictions against the actual threat model. Implement filesystem and network boundaries, resource quotas and safe lifecycle management. Work with security researchers to test escapes and confused-deputy behavior.

The milestone

What it looks like when it is working

In your first 90 days, deliver an isolated tool runner with explicit permissions, reproducible attack tests and measured startup and memory costs.

Evidence

What would show us you can do it

Bring experience with kernel isolation, hypervisors or hardened execution environments. Understand the difference between restricting a process and protecting against a compromised host.

Evidence, not credentials. We are describing work you can point at, in whatever form it exists.

The exercise

How we would look at it together

Design a document-conversion sandbox that handles malicious files while preventing credential access and unintended network use.

← All 72 roles in the catalog