Engineering Tech Lead (vNode)
AI summary of the role
This Engineering Tech Lead owns the technical direction and execution for vNode, a container runtime that provides VM-grade tenant isolation using Linux user namespaces and seccomp.
No longer in the current catalog. Last included 2026-09-09. Check the employer’s posting for availability.
What you’ll do
- Own the vNode technical execution: drive architecture for how vNode wraps containerd, integrates with the kubelet, and exposes safe isolation primitives.
- Go deep on container runtimes and isolation: lead work where vNode meets containerd, Kata Containers, gVisor, runc, and the kernel.
- Ship the kubelet integration surface: own CRI, kubelet device plugins, cgroups v2, eviction, and node lifecycle integration.
- Raise the engineering bar: run technical design reviews, set testing patterns for isolation guarantees, and mentor engineers.
What you’ll bring
- Deep container runtime experience: shipped production work against containerd directly.
- Kubernetes node-level depth: worked inside the kubelet, CRI layer, or a node-resident agent.
- Go systems programming chops: write production Go for systems-level code (syscalls, namespaces, file descriptors, process lifecycle).
- Linux isolation fluency: user namespaces, seccomp-bpf, capabilities, and Landlock.
Technologies
containerd · kubelet · CRI · cgroups v2 · Kata Containers · gVisor · runc · seccomp · user namespaces · Go
About vcluster
Kubernetes virtualization platform that runs isolated virtual clusters inside one real cluster, used by enterprises and AI neoclouds for multi-tenancy and cost reduction.
Series A · 50–100 people
Source and classification
Internal deployment & tooling · Evidence for this classification:
As an Engineering Tech Lead at vCluster Labs, you aren't just shipping container runtime features; you are defining how Kubernetes operators get VM-grade tenant isolation without the VM tax. vNode replaces virtual kubelets and microVMs with a runtime built on Linux user namespaces and seccomp, and the person in this seat owns where that runtime goes next. You will partner directly with the vNode founding engineers, run the technical bar for the team, and ship the work that decides whether AI Clouds and regulated enterprises can adopt vNode as their default isolation layer. As an Engineering Tech Lead, your role will include: Owning the vNode technical execution: Drive the architecture for how vNode wraps containerd, integrates with the kubelet, and exposes safe isolation primitives. You will set the bar for what ships, what gets deferred, and what gets redesigned. Going deep on
More from the job description
As an Engineering Tech Lead at vCluster Labs, you aren't just shipping container runtime features; you are defining how Kubernetes operators get VM-grade tenant isolation without the VM tax. vNode replaces virtual kubelets and microVMs with a runtime built on Linux user namespaces and seccomp, and the person in this seat owns where that runtime goes next. You will partner directly with the vNode founding engineers, run the technical bar for the team, and ship the work that decides whether AI Clouds and regulated enterprises can adopt vNode as their default isolation layer. As an Engineering Tech Lead, your role will include: Owning the vNode technical execution: Drive the architecture for how vNode wraps containerd, integrates with the kubelet, and exposes safe isolation primitives. You will set the bar for what ships, what gets deferred, and what gets redesigned. Going deep on container runtimes and isolation: Lead the work where vNode meets containerd, Kata Containers, gVisor, runc, and the kernel. You will be the person who can explain (and improve) exactly what happens between a Pod spec and a process running under a constrained user namespace with a tight seccomp profile. Shipping the kubelet integration surface: Own how vNode plugs into the node lifecycle: CRI, kubelet device plugins, cgroups v2, eviction, and the rough edges between Kubernetes' node model and a runti [... source excerpt omitted ...] , set the pattern for testing isolation guarantees, and mentor the engineers shipping alongside you. You are not a people manager, but you are the engineer the team copies. Being Customer Zero for vNode: Run vNode against vCluster Platform tenant clusters internally before customers see it. You will close the loop between what AI Cloud operators need and what vNode actually does in production. Representing vNode externally: Contribute upstream where it matters (containerd, runc, Kubernetes SIG-Node), write the technical posts that explain why namespace-based isolation is the right answer, and represent vCluster Labs at KubeCon-class venues when the timing is right. This role c [... source excerpt omitted ...] the kubelet, the CRI layer, or a node-resident agent. You know what cgroups v2, OCI hooks, and the kubelet's PLEG do and where they break. Go systems programming chops: You write production Go for systems-level code (syscalls, namespaces, file descriptors, process lifecycle), not just service handlers. Linux isolation fluency: User namespaces, seccomp-bpf, capabilities, and Landlock are not abstract concepts; you have shipped against them and can reason about their failure modes. Tech Lead instincts: You set technical direction by writing the design doc, prototyping the hard part, and then bringing the team along. You raise the bar without becoming the bottleneck. Bonus points
Employer postings · Data from · Sources