Can you strace the service start? I want to see if it fails on mmap or on clone. Also check /proc/user_beancounters if OpenVZ, failcnt column tells real story. Provider hides limits there.
I saw same on my Wrocław lab box, turned out privvmpages limit was 280MB but kmemsize tiny. Systemd allocates lot of kernel memory for cgroups.