Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Novavirt Inc.

Rust Systems & Security Engineer

Job Description

Company :
Novavirt Inc.
Product:
BaseHV Location:
Michigan only — remote/hybrid within Michigan, with periodic on-site hardware/lab work in the Sterling Heights area
Employment:
Full-time, W-2
Compensation:
$130,000-$145,000 annual base salary, depending on experience Work authorization: Must have legal authorization to work for Novavirt in the United States Out-of-state remote work: Not available. Candidates currently outside Michigan may apply but must relocate to Michigan before beginning employment. About Novavirt and BaseHV Novavirt is a Michigan-headquartered enterprise infrastructure company developing cloud, managed-services, and virtualization technology. BaseHV is Novavirt's Rust-based Type 1 bare-metal hypervisor and virtualization-management platform. The existing implementation already includes bare-metal boot, Intel VT-x/VMX initialization, Extended Page Table construction, an initial VM-exit path, installer components, management APIs and CLI functionality, and the BHV-FS datastore foundation. Novavirt is preparing a Phase I research program focused on determining whether BaseHV can progress from this technical foundation to secure guest execution with enforceable per-VM memory isolation, constrained privileged unsafe-code boundaries, predictable fault containment, and practical performance. We are seeking a Rust Systems & Security Engineer to help rigorously test those claims rather than assume them. The Role The Rust Systems & Security Engineer will work closely with the Principal Hypervisor Engineer / Principal Investigator to design, implement, and execute the security, correctness, fault-injection, and performance-validation portions of the BaseHV Phase I research program. This is not primarily an application-security or web-security role. The position focuses on privileged systems software: low-level Rust, unsafe-code boundaries, virtual-memory isolation, hypervisor state transitions, adversarial guest behavior, resource exhaustion, failure containment, and reproducible systems experimentation. The engineer will help establish whether BaseHV's memory-safety-oriented architecture actually provides measurable security and reliability benefits under controlled testing. If Phase I validates the architecture, this role is expected to continue as a foundational member of the BaseHV engineering organization as the platform expands into networking, storage, hardware compatibility, clustering, high availability, and production security. Responsibilities Work with the Principal Hypervisor Engineer / PI to define measurable Phase I security, isolation, reliability, and performance criteria. Identify and characterize unsafe Rust within security-critical BaseHV components. Help concentrate unavoidable unsafe operations behind narrow, documented, auditable interfaces. Review low-level code for memory-safety hazards, incorrect assumptions, state corruption, and unsafe hardware interactions. Develop tests for guest-to-host and VM-to-VM memory-isolation boundaries. Design adversarial guest workloads intended to exercise EPT violations, invalid accesses, malformed state transitions, and unexpected VM-exit conditions. Develop resource-exhaustion tests involving CPU, memory, storage, and related constrained-resource conditions. Build fault-injection test harnesses for crash recovery, lifecycle failures, invalid state transitions, and partial operations. Validate VM create, boot, run, reset, stop, and failure-state transitions. Test whether faults affecting one workload remain contained from unrelated workloads and privileged BaseHV state. Develop reproducible benchmarks for guest-execution overhead, VM-exit behavior, memory overhead, lifecycle timing, and recovery behavior. Help define and measure the privileged unsafe-code surface of BaseHV. Document test methodology, expected invariants, observed failures, and research results suitable for NSF technical reporting. Assist with Phase II planning for virtual-network isolation, management security, expanded hardware support, and broader workload testing. Participate in code review and help establish long-term systems-security engineering practices for the BaseHV team. Required Qualifications Strong candidates should demonstrate meaningful experience in several of the following areas: Rust systems programming Low-level or performance-sensitive software development Memory safety and unsafe Rust Operating-system, kernel, hypervisor, firmware, embedded, or systems-runtime development Virtual memory, page tables, memory ownership, and protection boundaries Systems security and isolation mechanisms Fault injection, fuzzing, adversarial testing, or negative testing State-machine and lifecycle correctness testing Concurrency, race-condition analysis, and resource-exhaustion behavior QEMU, GDB, tracing, serial-console debugging, or comparable low-level diagnostic tools Reproducible performance benchmarking and experimental methodology Experience with x86 virtualization, KVM, Xen, Firecracker, Cloud Hypervisor, QEMU, Linux kernel internals, or similar low-level platforms is strongly preferred but not required if the candidate has deep Rust and systems-security expertise. A Ph.D. is not required. Demonstrated systems-engineering ability, careful security reasoning, and experience working close to hardware or privileged software are more important than a particular academic credential. Preferred Experience Additional valuable experience includes: Intel VT-x, VMCS, EPT, or
AMD-V/NPT
Security review of unsafe Rust Fuzzing privileged or systems-level software Property-based testing Crash-consistency or storage-correctness testing Security boundary modeling and threat modeling Formal methods or model checking Performance-counter analysis Hardware-assisted virtualization testing Open-source systems software contributions Research Responsibilities The Phase I program will not treat the use of Rust as proof of security. The Rust Systems & Security Engineer will help answer questions such as: Which privileged operations still require unsafe Rust? Can those operations be constrained to small and auditable interfaces? Can one VM access memory owned by another VM? Can a malformed or hostile guest corrupt privileged BaseHV state? What happens when a VM exhausts memory or CPU resources? Does BaseHV return to a defined state after injected failures? Are test results reproducible across repeated executions? What measurable performance cost results from the proposed safety architecture? The engineer will work with the PI to turn these questions into repeatable tests and quantitative Phase I success criteria. Work Location This position must be performed physically from Michigan. Novavirt may support remote or hybrid work within Michigan. Periodic access to physical BaseHV test infrastructure in the Sterling Heights area will be required for bare-metal testing, failure injection, and hardware-dependent validation. Candidates currently residing outside Michigan may apply if they are willing to establish their work location in Michigan before employment begins. Novavirt is not offering permanent out-of-state remote work for this position. Why This Role Matters BaseHV's Phase I research is intended to determine whether a predominantly memory-safe Rust hypervisor architecture can provide meaningful isolation and reliability advantages without unacceptable performance tradeoffs. The Rust Systems & Security Engineer will be responsible for helping Novavirt prove—or disprove—those claims through rigorous testing. If the architecture succeeds, this engineer will have helped establish the security engineering practices, test methodology, and reliability standards that guide BaseHV as it develops from an R D platform into a production enterprise virtualization product.
Pay:
$130,000.00 - $145,000.00 per year
Benefits:
Dental insurance Flexible schedule Health insurance Paid time off Professional development assistance Vision insurance People with a criminal record are encouraged to apply
Work Location:
Hybrid remote in Sterling Heights, MI 48313

Benefits

  • Paid Time Off (PTO)
  • Professional Development
  • Health Insurance
  • Dental Insurance
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
75
out of 100
Average of individual scores

Were these scores useful?