# Senior Systems Engineer II - Edge Platform & Packaging (On-Prem)

> Dispel · United States (Remote) · Full-time · Posted 2026-08-03

**Salary:** USD 150,000–159,000

**Workplace:** remote

**Department:** Engineering

## Description

Dispel builds secure, private network infrastructure for critical industries. A large share of our product does not run in our cloud — it runs on appliances inside customer plants, substations, water districts, and manufacturing floors, on networks we do not control, behind change-control windows we do not set, sometimes reachable only through a narrow tunnel and sometimes not reachable at all. Every one of those appliances has to be installable by a field technician, patchable without a truck roll, and diagnosable after the fact.

As a Senior Systems Engineer II, you own how Dispel's on-premises software gets built, packaged, shipped, updated, and observed. That covers our Site Control appliance and the Wicket fleet: the OS baseline, the container and package layers, the release artifacts, the signing and provenance chain, the update mechanism, and the local telemetry and edge-processing capability that lets an appliance keep doing useful work when its uplink is degraded or gone.

This is a systems role, not a build-tooling role. You will make consequential calls about the runtime substrate on the edge, how state and configuration are reconciled, how an appliance recovers from a failed update, and how much processing belongs at the edge versus in the cloud. You scope that work into well-defined milestones, estimate it, and follow through — and you write it so other engineers can reason about it and extend it with confidence.

Engineering at Dispel is a collaborative effort and those that show up trying to get things done and help others will receive support from the team. Dispel has high aspirations and we are growing quickly.

## Requirements

### Execution (Primary Focus)

### Packaging and Release Engineering

-   Own the build and packaging pipeline for on-premises deliverables — OS images, packages, container images, and the release bundles field and customer teams actually install.
-   Make on-premises builds reproducible and verifiable: pinned inputs, deterministic outputs, signed artifacts, and an SBOM per release that survives a customer security review.
-   Design a versioning and compatibility model that tells anyone, at a glance, which appliance versions interoperate with which cloud-side and orchestration components.
-   Collapse bespoke, per-project packaging into a small number of supported paths, and make the supported paths good enough that nobody wants to fork them.
-   Turn appliance provisioning from a documented procedure into an automated, idempotent one.

### Updatability

-   Own the update mechanism end to end: delivery, staging, application, verification, and rollback — for appliances on constrained links, in maintenance windows, or fully air-gapped.
-   Design for failure as the normal case. An interrupted or bad update must leave the appliance in a known-good state and recoverable without a site visit.
-   Build fleet-level release control: staged rollouts, cohorts and canaries, version and drift visibility across the fleet, and a mechanism to hold or reverse a rollout in progress.
-   Shrink the interval between a CVE being published and the fleet being patched, and make that interval measurable rather than anecdotal.
-   Keep the update path working across the OS baseline and its kernel lifecycle, not just the application layer on top of it.

### Edge Processing

-   Extend the appliance runtime so workloads can execute locally — telemetry collection and pre-processing, buffering and store-and-forward, local decisioning — and reconcile cleanly when connectivity returns.
-   Define what belongs at the edge versus in the cloud, and hold that line with evidence about bandwidth, latency, and customer data-residency constraints rather than preference.
-   Own resource discipline on the appliance: hardware is fixed, workloads grow, and the network functions on that box must never be starved by anything you add beside them.
-   Design the local observability story so that a support engineer can reconstruct what an appliance was doing without shell access to it.

### Reliability, Security, and Quality

-   Own the integrity of the on-premises supply chain: signing keys, trust roots, artifact provenance, and the assumption that any of it may be audited by a customer or regulator.
-   Build the test substrate this work requires — appliance-in-a-loop testing, upgrade and downgrade paths exercised in CI, hardware and near-hardware validation before a release reaches a customer.
-   Ensure on-premises systems meet performance, scalability, and security requirements, particularly where packaging and runtime choices touch the network data path.
-   Participate in incident response and root cause analysis, especially for field failures where the evidence is thin and the appliance is remote.

### Enabling Others (Secondary Focus)

### Cross-Functional Communication

-   Participate in an on-call rotation to support system reliability, including responding to incidents and performing after-hours troubleshooting as needed.
-   Partner with the field, support, and customer-facing engineering teams — they encounter your work first, and their friction is your backlog.
-   Work with security and compliance to make on-premises releases evidence-producing by default, so customer and regulatory reviews draw on artifacts you already generate.
-   Give product and engineering leadership a straight read on what the edge can and cannot support, early enough to change a plan.
-   Write the runbooks, upgrade notes, and architecture documentation that other engineers and field teams operate from.
-   Informally mentor IC1 and IC2 engineers on your team — through code review, pairing, and sharing technical context.
-   Participate in evaluation portions of interview loops to help Dispel hire well.

### Qualifications

-   5+ years of professional engineering experience with a demonstrated track record of shipping software that runs on infrastructure you do not operate.
-   You have owned a release and update mechanism for deployed systems — edge, appliance, embedded, or on-premises enterprise — and dealt with the consequences when one went wrong in the field.
-   Deep Linux systems fluency: systemd, the boot and init path, filesystem and partition layout, kernel and package lifecycle, and how a distribution actually gets assembled.
-   Strong packaging and distribution experience — Debian/apt packaging, OCI images, image-based or A/B update schemes, or equivalent — including artifact signing and repository operation.
-   Proficiency in at least one systems-capable language (Go, Rust, Python, or C) and comfort reading code across the layers you package.
-   Comfortable using coding agents (e.g., GitHub Copilot, Claude Code) as part of your daily workflow
-   Proficiency with Infrastructure as code, with primary focus using Ansible and Terraform.
-   Container runtime and orchestration experience, with real opinions about what is appropriate on a single constrained node versus in a datacenter.
-   Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions, or similar), including building pipelines that produce release artifacts rather than just deploying them.
-   Solid network fundamentals — routing, DNS, firewalls, VPN concepts — enough to package and operate networking software without breaking its data path.
-   Demonstrated ability to work with cross-team stakeholders to define requirements and deliver results with minimal oversight.
-   A willingness to accept failure and feedback, learn and try again.
-   A passion for learning new disciplines and gaining a deep understanding of how others on the team do their work.
-   An ability to communicate clearly and succinctly both in-person and over team chat.

### Bonus Points

-   Experience shipping into OT, ICS, or industrial environments, and familiarity with the change-control and segmentation realities of those networks.
-   Experience with air-gapped or intermittently connected deployments, including offline mirrors and sneakernet update paths.
-   Background in security-focused products where reliability and regulatory compliance matter — IEC 62443, NERC CIP, FIPS-validated cryptography, or FedRAMP-adjacent work.
-   Supply-chain security depth: SLSA, in-toto, Sigstore, SBOM generation and consumption, reproducible builds.
-   Lightweight Kubernetes distributions or single-node orchestration at the edge (K3s, MicroShift, Talos), and honest experience with their operational costs.
-   Image-based Linux and atomic update systems: OSTree, Mender, RAUC, SWUpdate, or similar.
-   On-premises virtualization, hardware bring-up, or hardware qualification experience.
-   Telemetry pipeline experience at the edge — agent-based collection, buffering, and forwarding into customer SIEMs.
-   Experience building or operating commercial VPN, ZTNA, or secure remote access products.

## Benefits

**We Offer:**

-   $150,000-159,000 salary range
-   401(k) w/ company match
-   Unlimited paid time off
-   Parental leave
-   Full medical, dental, vision insurance
-   Performance bonus and equity eligible
-   Remote work (15-20% travel for on-prem purposes)

## Apply

[Apply at Dispel](https://apply.workable.com/dispel/j/85FC6E958E/apply)

---
Powered by [Workable](https://www.workable.com)
