Senior Systems Engineer - Email Deliverability & Infrastructure
Mission Inbox
| Company | Mission Inbox |
| Category | Engineering |
| Location | Palermo |
| Remote | Remote |
| Employment | Full-time |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 3 Jun 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (workable) |
Description
Location: Fully Remote (Global) Compensation: $24k to $36k USD Yearly Position Type: Full-Time Contract Role Overview We are seeking a highly technical, impact-driven Senior Systems Engineer to own, scale, and protect our core email transmission infrastructure. In this role, your golden rule will be Reputation Above All . You are not just managing email lists or monitoring dashboards; you will architect and maintain the high-availability server infrastructure, Mail Transfer Agents (MTAs), and automated defensive systems that ensure our legitimate traffic hits the inbox while bad actors are ruthlessly contained. The ideal candidate bridges the gap between deep Linux systems administration, network engineering, and advanced email deliverability strategy. You will have a massive impact on the company by safeguarding our global IP/domain reputation, minimizing blast radiuses, and ensuring zero-downtime mail operations across our entire infrastructure network. Core Responsibilities 1. Infrastructure Management & High Availability MTA Optimization: Maintain and configure core MTAs ( Postfix , Postal ) and IMAP/POP3 servers ( Dovecot ), ensuring graceful reloads over restarts to prevent dropping active connections. Traffic Routing & Load Balancing: Utilize HAProxy and network routing protocols (like BGP via FRRouting ) to distribute outbound traffic and architect high-volume failover mechanisms. Redundancy & Failover: Administer backend infrastructure databases ( PostgreSQL replica setups) and maintain dedicated "Block" backup/archive servers to instantly take over the workload of a failed primary "Cube" server. Architectural Segregation: Maintain strict workload isolation across our infrastructure network—separating standard nodes for mail stacks, specialized injection nodes (Postal), and separate archiving/backup systems to prevent high-volume senders from degrading performance. 2. Deliverability Engine & Authentication Protocol Architecture Protocol Enforcement: Act as the absolute technical authority on DNS and authentication setups, maintaining flawless configurations for SPF (navigating the 10-lookup limit), DKIM (key rotation and forwarding protection), DMARC (safely driving policies toward p=reject), and BIMI . Traffic Throttling: Implement automated, MTA-level dynamic throttling to handle 4xx deferrals instantly, preventing a single high-volume sender from triggering global rate limits across our shared IP pools. Warm-up Strategy: Design and guide automated IP/Domain Warm-up Plans for new infrastructure, managing incremental volume scaling over 2–4 week cycles. 3. Edge Security, Anti-Abuse & Incident Response Outbound Spam Filtering: Configure and optimize Rspamd to actively scan, flag, and quarantine highly spammy content before it exits our network. Edge Defense: Deploy automated connection-dropping systems ( Fail2Ban , custom SMTP blocker scripts) to mitigate authenticated attacks, brute-force attempts, and malicious traffic. Blast Radius Mitigation: Program and maintain a dynamic IP pooling engine ("The Penalty Box") to instantly isolate accounts displaying poor metrics (bounces, FBL spikes) away from prime Tier-1 IP pools. Blocklist Remediation: Act as the primary responder to major DNSBL (e.g., Spamhaus ) listings. Leverage log analysis to locate the root cause account, plug the security leak, and submit expert delisting requests. 4. Observability & Monitoring Log Shipping Architecture: Build and manage high-performance log aggregation pipelines using Vector to ship system and MTA data into a centralized repository for real-time auditing and incident response. Network Auditing: Utilize IPAudit and custom tools to continuously scan for bandwidth anomalies, connection spikes, or compromised user credentials. Dashboard Management: Actively monitor ISP infrastructure portals daily ( Google Postmaster Tools ,