write a service unit for systemd and put it into system slice (/etc/systemd/system). as long as you execute it under a user (even root), you will be restricted.