974,315open jobs
58,640companies
159,915added this week
Browse all
Salary
$90k – $150k per year
Location
In office (London)
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 22, 2026.

Overview
Company
Impact
Profile match
SASH builds AI safety research capacity in Asia and policy-relevant governance work from Singapore.

The Team

Some of the most consequential decisions of the AI era will depend on answering one question: can we verify what is happening inside AI datacenters? Answering it could unlock international cooperation, help countries protect their sovereignty, and enable trustworthy adoption of AI in high-stakes industries. Building tools that can earn trust across borders is an urgent technical and political challenge.

SASH’s Verification team builds and tests tools to verify agreements about AI. We prototype new verification mechanisms, lead international research collaborations, and work with policymakers around the world to show what these tools can do and inform how they’re used.

You’d join a small team combining technical expertise with international AI policy experience. Our technical team is led by Pascal Berrang, an Associate Professor at University of Birmingham, and brings experience from the Singapore Government. Our policy team brings experience from Oxford and the Centre for the Governance of AI, while our partners include experts from the Future of Life Institute and the University of Oxford.

The problem

An international agreement on AI is only as broad as what can be verified, and the appetite for verification is growing. In September 2026 Anthropic gave independent third-party evaluators permanent, employee-level access to its systems, and OpenAI said it would match it. Frontier developers now accept that outsiders should be able to check their work.

Between states, the options are cruder: take the operator's word that a datacenter is running a declared, safety-tested model and nothing else, or put inspectors and hardware inside the building. Inspections do not scale, and installing hardware might not be acceptable to every operator.

Zero-knowledge proofs are the one approach that removes both problems at once. The prover can demonstrate a claim - the committed model produced these output tokens - while revealing nothing about the weights, and the verifier's trust rests on mathematics rather than on hardware it has to manufacture, ship and guard. Progress here can be deployed immediately, because there is nothing to fabricate and nothing to install.

The catch has always been cost, and the figures usually quoted for it are badly out of date: the literature still puts proving at four orders of magnitude more expensive than the computation being proved. Our own prototype proves a full conversation with an 8-billion-parameter model in about an hour and a half on a single GPU, and most of what is left is ordinary engineering rather than cryptography. Extrapolated to a 405-billion-parameter model, fifty times larger, that is 16 to 24 hours because cost grows far more slowly than the models do.

Verification is also a much friendlier setting for ZKPs than the applications they were designed for. A verifier needs confidence that, say, 99% of compute is used legitimately - and sampling roughly 300 outputs is enough for 95% confidence in that claim. Better still, the sampling can go inside a single proof: preliminary work suggests blocks within a transcript can be sparsely sub-sampled, so floating-point matrix multiplication only has to be emulated exactly for a small sample of vector products. For some problems that is a 100,000x saving over a complete proof.

Your work

You would own the line from "this works in a paper" to "a policymaker can rely on this."

Concretely, that means driving down proving cost, closing the gap between what our proofs currently explain and what a frontier inference actually does, and making the resulting system one that a sceptical adversary's technical staff would sign off on. You'd work alongside hardware-security and systems colleagues on the team and with external cryptographers, and you'd be expected to publish since the whole approach depends on other people being able to check it.

Representative projects

  • Prove a full inference transcript from a frontier-scale model end to end, and report honestly what it cost.

  • Get an open prototype to parity with the best proprietary systems. The most useful thing anyone can do for this field right now is make the state of the art public and checkable.

  • Close out the data-preparation path that dominates our current proving time, using the reference-implementation check as a correctness oracle for AI-assisted optimisation.

  • Help develop the agenda for where this field goes next, including where AI-assisted research can be pointed at.

  • Design and analyse the sub-sampling scheme: what fraction of blocks must be checked, under what adversary model, to bound the information a dishonest prover can smuggle through.

  • Bring ZKPs closer to what is deployed today, integrating exact emulation of the hardware's floating-point behaviour, including its rounding, scaling and accumulation, or moving production inference to integer arithmetic with batch-invariant kernels.

  • Build proof circuits for low-precision formats such as NVFP4, where "just emulate the hardware" turns into numerical engineering.

  • Investigate compute- and memory-exhaustion schemes such as proof-of-useful-work or proof-of-space.

  • Hide the model architecture itself, perhaps through proof recursion.

  • Red-team our own constraint system.

About you

We are hiring this role at a range of levels, from people early in their research career to people who have shipped proof systems in production. We care more about ability and trajectory than years of experience.

You may be a good fit if you:

  • Have built something real with a modern proof system (Halo2, Plonky3, STARK-based stacks, or comparable) or have deep GPU and ML systems experience and want to learn proof systems on the job. We expect to hire both profiles.

  • Are comfortable reasoning about soundness: what an adversary can do, what your assumption actually buys you, and where the argument is critical.

  • Can write code that other people will attack, and enjoy that prospect.

  • Are willing to do the unglamorous last mile: generalising across model architectures, chasing numerical mismatches, rather than only the interesting part.

  • Thrive in ambiguous, early-stage environments where defining the problem is part of the job.

Strong candidates may also have:

  • Published work in applied cryptography, verifiable computation, or succinct proofs.

  • Low-precision numerics experience: rounding modes, accumulation order, and why two GPUs disagree.

  • Formal verification experience, especially of a verifier codebase or a protocol.

  • Familiarity with lookup arguments, recursion, or folding schemes.

  • Experience explaining a cryptographic guarantee to someone who will never read the proof.

  • Experience using AI systems as research collaborators on problems where correctness is checkable, and a view on where that works and where it does not.

Role Logistics & Benefits

Location:

  • This is a remote role that can be based in Singapore, the UK, or remotely.

  • For candidates interested in relocating, SASH can provide visa sponsorship in the UK.

  • Our team is globally distributed, so remote team members should be comfortable maintaining some working-hour overlap with colleagues across regions.

Compensation:

Our compensation takes location, experience, and level into account. Our compensation takes location, experience, and level into account. Salaries above the stated range may be available for exceptional candidates.

Benefits:

  • Competitive benefits and leave policies.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
974,315 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

AI/ML
Similar stack
Same company
London
Research Scientist 22 days ago
$60k – $77k per year • Hybrid • Full-Time • PhD • Luton
MATLAB
MATLAB
Simulink
Apply
≈ $106k – $212k per year (Estimated) • Equity • In office • Full-Time • London
SQL
AI/ML
AI Agents
Analytics
Microsoft Excel
Management
Google Sheets
Apply
≈ $104k – $206k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Edinburgh • Southampton
AI/ML
Fine-tuning
Embeddings
Prompt Engineering
AI Agents
TensorFlow
PyTorch
LLM
RAG
Agentic Workflows
Machine Learning
Management
Agile
Apply
≈ $94k – $256k per year (Estimated) • In office • PhD • Cambridge
Python
MATLAB
Apply
≈ $118k – $238k per year (Estimated) • In office • Full-Time • 6+ years exp • Master's Degree • London
Python
SQL
Python
bandit
AI/ML
Spark
Fine-tuning
Scikit-learn
TensorFlow
NumPy
PyTorch
ClearML
Feature Store
Machine Learning
DevOps
CI/CD
Analytics
A/B Testing
Apply
≈ $85k – $196k per year (Estimated) • In office • Bachelor's Degree • El Segundo
AI/ML
Fine-tuning
Prompt Engineering
Multimodal AI
RAG
OpenAI
Anthropic
Edge AI
Apply
≈ $113k – $219k per year (Estimated) • In office • 3+ years exp • El Segundo
AI/ML
Prompt Engineering
LLM
OpenAI
Anthropic
Edge AI
Apply
Hybrid • Full-Time • 3+ years exp • Rotterdam
JavaScript
TypeScript
Node JS
Databases
PostgreSQL
Supabase
AI/ML
LLM
OpenAI
Anthropic
Frontend
Next.js
React.js
Vite
Mobile
Firebase
DevOps
CI/CD
Docker
Cybersecurity
Okta
Apply
≈ $19k – $53k per year (Estimated) • Remote (EAEU) • Moscow
Python
Databases
Microsoft Fabric
AI/ML
LLM
OpenAI
DevOps
Azure
Apply
$266k – $370k per year • Hybrid • TS/SCI • Full-Time • 10+ years exp • Washington
AI/ML
OpenAI
Apply
$90k – $150k per year • In office • Full-Time • London
AI/ML
CUDA Toolkit
LLM
CUDA
Post-training
KV Cache
Apply
$90k – $150k per year • In office • Full-Time • London
Cybersecurity
PKI
Apply
$90k – $150k per year • Remote (United Kingdom, Singapore) • Full-Time • London • San Francisco
Apply
$200k – $250k per year • Remote (Singapore) • Full-Time • PhD
AI/ML
AI Agents
EU AI Act
NIST AI RMF
Machine Learning
Apply
$120k – $180k per year • Remote (Singapore) • Full-Time
Python
AI/ML
AI Agents
Tool Use
DevOps
Docker
Kubernetes
Apply
Growth Project Lead 5 hours ago
≈ $92k – $187k per year (Estimated) • Hybrid • Full-Time • London
Apply
Hybrid • Full-Time • Master's Degree • London • Amsterdam • Berlin • Cambridge
AI/ML
Model Context Protocol
AI Agents
Apply
≈ $77k – $143k per year (Estimated) • In office • Full-Time • London
Apply
$120k – $203k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • London • Austin
Python
Java
PowerShell
C#
DevOps
Terraform
Ansible
GCP
Azure
CI/CD
Jenkins
AWS
Platform Engineering
Cybersecurity
PKI
Apply
≈ $63k – $146k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Edinburgh • London
SQL
Apply
See all jobs
This is one of many
974,315 more open roles from verified company boards, updated every day.