Logo for SASH

Research Engineer / Research Scientist, Confidential Computing

Role overview

Qualifications

  • Experience with confidential computing or hardware enclaves (e.g., SGX, TDX, SEV-SNP, Arm CCA, GPU confidential computing)
  • Understanding of attestation chains in security systems
  • Ability to integrate solutions across organizational boundaries
  • Experience in ambiguous, early-stage environments

Responsibilities

  • Establish what attestation on current accelerators proves and does not prove
  • Design a registry for outsiders to check attested claims
  • Build attested logging inside an enclave for privacy-preserving audits
  • Chain attestations across pipelines to ensure claims about final outputs are verifiable

Key facts

Hard skills

Other skills

  • Adaptability
  • Collaboration

About the company

SASH logo

SASH

Computer Software / SaaS

Singapore AI Safety Hub is a co-working, events and community space for people working on or interested in AI safety. SASH’s mission is to strengthen and grow the AI safety community in Singapore through community, building awareness, upskilling talent and facilitating international cooperation. Although only launched in February 2025, SASH already houses established researchers from internationally renowned AI safety organisations such as FAR.AI,Truthful AI, Apart Research, The Future Society and Impact Academy working on technical and governance research. Find out more at www.aisafety.sg

Company details

Company typeTPE
IndustryComputer Software / SaaS
Company size1 - 1

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The team

Some of the most consequential decisions of the AI era will depend on answering one question: can we verify what is happening inside AI datacenters? Answering it could unlock international cooperation, help countries protect their sovereignty, and enable trustworthy adoption of AI in high-stakes industries. Building tools that can earn trust across borders is an urgent technical and political challenge.

SASH’s Verification team builds and tests tools to verify agreements about AI. We prototype new verification mechanisms, lead international research collaborations, and work with policymakers around the world to show what these tools can do and inform how they’re used.

You’d join a small team combining technical expertise with international AI policy experience. Our technical team is led by Pascal Berrang, an Associate Professor at University of Birmingham, and brings experience from the Singapore Government. Our policy team brings experience from Oxford and the Centre for the Governance of AI, while our partners include experts from the Future of Life Institute and the University of Oxford.

The problem

Verifying what happens inside a datacenter running large AI models is the bottleneck on almost every serious agreement about AI — between states, between a regulator and a lab, between a company and the customers it wants to reassure. The obstacle is always the same shape: the party with something to prove cannot hand over its model weights, and the party doing the checking cannot simply take its word.

One solution to this problem puts its trust in hardware: a trusted execution environment isolates a computation and attests to what ran inside it, so a claim about what happened becomes a claim you can check against a chip. Confidential computing exists on current accelerators and runs near production speed.

That unlocks several problems. An audit tells you something about a model, but nothing connects that result to the weights actually being served — attesting the deployed model by weight hash closes the gap between "this model was evaluated" and "you are talking to the model that was evaluated." The most valuable evaluations are built by people who cannot publish their test set, against models whose weights cannot leave the developer; inside an enclave, neither side has to give way. Logs can be attested where they are produced, making usage auditable after the fact without being readable.

Your work

You would own the question of what a chip's word is actually worth, and then build the systems that are worth building on top of it.

Concretely, that means establishing what attestation on current accelerators does and does not prove, designing a registry that lets an outsider check an attested claim without anyone's permission, and making attested pipelines that hold together when someone hostile pulls on them. "It works" and "an adversary cannot make it lie" are different bars, and only the second one counts here. You'd work alongside cryptographers and hardware-security colleagues on the team and with external partners, and you'd be expected to publish since the whole approach depends on other people being able to check it.

Representative projects

  • Establish what a GPU confidential-computing attestation guarantees on current hardware, and publish where it breaks.

  • Design and build the registry: the attested-result format, the submission path for third-party auditors, and a verification client someone outside the trust chain can actually run.

  • Build attested logging inside an enclave, and work out what a privacy-preserving audit over those logs can and cannot establish.

  • Run an evaluation end to end under mutual secrecy, with an attestation recording whose code and whose weights were involved.

  • Chain attestations across a pipeline so a claim about a final output stays checkable back to its inputs, then find where that chain breaks under production load.

  • Get a confidential-computing stack running on accelerators from more than one supply chain.

  • Combine hardware attestation with the team's cryptographic work, so a verifier does not have to trust the chip alone.

  • Red-team our own attestation chain.

About you

We are hiring this role at a range of levels. We care more about ability and trajectory than years of experience.

You may be a good fit if you:

  • Have built something real with confidential computing or hardware enclaves (SGX, TDX, SEV-SNP, Arm CCA, GPU confidential computing) or have strong systems security fundamentals and want to learn them on the job.

  • Understand attestation chains well enough to know where they carry weight and where they are decoration.

  • Are hard to reassure: you read a security claim and look first for what it does not say.

  • Can ship an integration across organisational boundaries, which is as much about people as about code.

  • Thrive in ambiguous, early-stage environments where defining the problem is part of the job.

Strong candidates may also have:

  • ML inference serving experience and the operational scars of production deployment.

  • Background in audit, certification, or PKI: the registry is a certificate authority with unusual requirements.

  • Privacy-preserving computation experience beyond enclaves: secure computation, differential privacy, federated setups.

  • Familiarity with the AI evaluations landscape and what safety institutes actually need.

  • Experience explaining a hardware guarantee to someone who will never read a datasheet.

Role Logistics & Benefits

Location:

  • This is a remote role that can be based in Singapore, the UK, or remotely.

  • For candidates interested in relocating, SASH can provide visa sponsorship in the UK.

  • Our team is globally distributed, so remote team members should be comfortable maintaining some working-hour overlap with colleagues across regions.

Compensation:

Our compensation takes location, experience, and level into account. Salaries above the stated range may be available for exceptional candidates.

 

Benefits:

  • Competitive benefits and leave policies.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Research Engineer Related jobs

Other jobs at SASH

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.