How to apply for Research Engineer/Scientist, Confidential Computing
SASH
About SASH
SASH is a Singapore-based nonprofit focused on building AI safety research capacity and governance expertise across Asia, uniquely positioning it at the intersection of technical AI safety and international policy. Working here means contributing to global AI governance infrastructure, with a mission to enable trustworthy international agreements through verifiable technology. The remote UK role offers flexibility while being part of a diverse, mission-driven team spanning Asia and beyond.
About the role
As a Research Engineer/Scientist in Confidential Computing, you will design and build verification tools that use hardware attestation and cryptography to make AI datacenters trustworthy for international agreements. Your work will directly address critical questions about what GPU confidential-computing attestation guarantees, and you'll create a registry for verifying attested claims and secure logging pipelines. This role is pivotal in translating cutting-edge hardware security into practical governance mechanisms, with opportunities to publish findings and collaborate with cryptographers and hardware-security experts.
A typical day
A typical day might involve prototyping an attestation verification module, debugging a secure logging pipeline, and collaborating with cryptographers on integrating zero-knowledge proofs. You could also spend time analyzing attestation reports from different GPU vendors to document their guarantees, or writing up findings for a publication. Regular syncs with the distributed team across Asia and the UK keep the work aligned with SASH's mission.
Who SASH is looking for
- Hands-on experience with confidential computing technologies such as Intel SGX, TDX, AMD SEV-SNP, Arm CCA, or GPU enclaves (e.g., NVIDIA H100 confidential computing).
- Strong systems security fundamentals, including threat modeling, secure boot, attestation protocols, and adversarial thinking.
- Familiarity with ML inference serving, audit/PKI systems, or privacy-preserving computation (e.g., homomorphic encryption, secure multi-party computation).
- Ability to thrive in ambiguous, early-stage environments, with a track record of building prototypes and publishing research for external verification.
Tips for this application
- Highlight specific projects where you implemented or analyzed hardware attestation (e.g., SGX enclaves, SEV-SNP attestation reports) and describe the security guarantees you verified or challenged.
- Demonstrate understanding of the limitations of current GPU confidential computing (e.g., side channels, attestation scope) and propose how you would investigate them.
- Emphasize any experience with building registries, logging systems, or pipelines that must remain secure under adversarial conditions, as this is central to the role.
- Show awareness of SASH's mission to enable international AI agreements; connect your technical work to governance and trust-building outcomes.
- Include links to publications, code repositories, or detailed project write-ups that showcase your ability to produce verifiable, reproducible research.
What to cover in your cover letter
['Your hands-on experience with confidential computing hardware (SGX, TDX, SEV-SNP, Arm CCA, or GPU enclaves) and what you learned about its guarantees and gaps.', 'How you would approach building a registry for attested claims, including design considerations for scalability, trust, and adversarial resilience.', "Your ability to collaborate with cryptographers and hardware-security experts, and examples of cross-disciplinary work you've done.", "Why SASH's nonprofit, Asia-focused mission resonates with you and how you can contribute to trustworthy international AI agreements."]
Draft a cover letterResearch before applying
- Explore SASH's website and published reports to understand their AI safety and governance initiatives, especially any work on verification and international agreements.
- Read up on the latest developments in GPU confidential computing, such as NVIDIA H100 confidential computing, AMD SEV-SNP for GPUs, and Intel TDX with GPUs.
- Familiarize yourself with key cryptographic primitives used in attestation and privacy-preserving computation, like remote attestation protocols, zero-knowledge proofs, and secure multi-party computation.
- Investigate existing efforts to create attestation registries or transparency logs (e.g., Certificate Transparency, binary transparency) and consider how they might apply to AI datacenters.
Likely interview topics
Based on the job description, expect questions about:
- Explain the attestation process for a specific confidential computing technology (e.g., SEV-SNP) and discuss what an attestation report actually proves and does not prove.
- How would you design a registry to verify attested claims from multiple GPU vendors, ensuring consistency and preventing forgery?
- Describe how you would build an attested logging pipeline that remains secure even if the host OS is compromised.
- What are the current limitations of GPU confidential computing for AI workloads, and how might they affect international agreements?
- Discuss a time you worked in an ambiguous, early-stage project: how did you scope the problem, and what was the outcome?
Common mistakes to avoid
- Focusing only on theoretical knowledge without demonstrating practical implementation experience in confidential computing or systems security.
- Ignoring the governance and international agreement context—this role is not just about building tools but enabling trust across borders.
- Underestimating the ambiguity of an early-stage nonprofit environment; candidates should show adaptability and self-direction rather than expecting well-defined tasks.
Deadline
No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.