Confidential mandate

Confidential-Computing AI Inference Assurance Expert

Planned Hiring / New

Confidential-Computing AI Inference Assurance Expert mandate in Zurich, Switzerland · Private Wealth Technology

A Zurich private-wealth technology group commissions an eight-week independent assurance of enclave-based AI inference, requiring a reproducible trust chain, adversarial failure evidence and an explicit production release opinion.

The mandate

The group must determine whether one proposed inference pathway keeps portfolio notes, client restrictions and retrieved context protected from cloud operators and unauthorised platform administrators throughout execution. The vendor demonstrates an enclave badge, but the current design does not prove what measured code receives keys, how model artefacts enter memory, whether logs reveal prompts, or what occurs when attestation, capacity or regional services fail.

The named deliverable is a Confidential Inference Assurance Opinion and Release Control Pack. It will define the end-to-end trust boundary, validate hardware and workload attestations, trace key-release policy, test encrypted model loading and data handling, examine observable leakage and downgrade paths, and issue a release, conditional-release or no-release opinion for the specified Zurich-to-Frankfurt deployment.

The eight-week engagement starts 4 January 2027. Milestone one, the signed trust map and falsification plan, is due 11 January; milestone two, the witnessed attestation, image-measurement and key-path evidence, is due 22 January; milestone three, the adversarial, leakage and fallback result book, is due 12 February; milestone four, the final opinion, exception schedule and operating controls, is due 26 February.

Acceptance requires the client cryptography lead to reperform certificate-chain and measurement validation, the CISO’s test team to reproduce one tampered-image denial and one revoked-policy denial, and the data owner to trace sampled plaintext only within approved protected-memory boundaries. Both sponsors must sign each residual exposure, compensating control and retest event; procurement approval, legal interpretation of bank secrecy and assurance of unrelated cloud services are excluded.

The client will provide isolated tenant access, enclave and host images, build provenance, attestation policies, key-management configurations, model-loader code, network and telemetry designs, recovery procedures and vendor engineering access. Security engineers in Zurich and Frankfurt will support witnessed tests, while a Geneva data owner will supply tokenised cases; no production client content may leave the controlled tenant, and destructive testing requires an approved replica.

Why this is external work

The platform team designed the pathway and the cloud provider attests only its own layers, leaving neither party positioned to challenge the full trust chain independently. Internal security has strong infrastructure controls but has not combined measured execution, model loading, retrieval context and inference observability in one assurance case. A fixed external opinion lets the risk owners distinguish cryptographic evidence from contractual promise before confidential workloads are released.

What you will own

  • Draw the complete trust and plaintext map from retrieval and prompt assembly through protected execution, model memory, output handling, telemetry, crash recovery and deletion.
  • Verify endorsement chains, trusted-computing-base measurements, freshness, revocation and attestation-policy evaluation against a separately obtained expected build identity.
  • Trace key release from request through attested claims, workload identity and policy decision, testing replay, stale collateral, altered measurements and administrator substitution.
  • Inspect encrypted model and adapter loading for unprotected staging, mutable dependencies, debug access, swap exposure and artefact substitution before protected execution begins.
  • Exercise capacity exhaustion, attestation outage, regional failover and recovery paths to detect silent downgrade into ordinary compute or uncontrolled logging.
  • Evaluate practical leakage through response metadata, logs, counters, timing and shared resources, stating measured bounds and limitations rather than claiming side-channel elimination.
  • Issue the release opinion and implementable gate checklist linking every approved build, policy, certificate set and exception to mandatory re-attestation or retest.

Candidate qualifications

  • Led confidential-computing assurance for a production workload using hardware-backed trusted execution and remote attestation in a major cloud or comparable environment.
  • Traced a key-release decision through endorsement, measurement, workload identity, policy and revocation evidence, including a witnessed negative test.
  • Assessed machine-learning inference inside protected execution, covering encrypted model loading, accelerator or memory limitations, retrieval context and operational telemetry.
  • Found a fallback, recovery or observability path that defeated an otherwise valid enclave design and drove a documented architecture or release decision.
  • Evaluated realistic side-channel exposure without presenting theoretical protection as complete confidentiality, communicating residual limits to senior risk owners.
  • Delivered an assurance pack whose scripts, captured evidence and acceptance logic an internal security team could reproduce after departure.

Non-negotiables

  • The named expert must attend two Zurich workshops and the Frankfurt observation visit despite the otherwise remote delivery model.
  • No client prompt, portfolio, model or key material may be copied outside the approved tenant or submitted to personal testing infrastructure.
  • Any employment, investment, certification income or commercial relationship involving the chosen cloud, hardware or assurance vendor must be disclosed before access.
  • Will issue a no-release opinion if the client cannot prove measured-code identity, policy-bound key release or fail-closed behaviour under outage.
  1. 49 words maximum. Describe one confidential-computing trust chain you personally falsified, including the negative test and resulting release decision.
  2. 49 words maximum. How would you prove that an attested inference workload cannot obtain keys after image mutation, policy revocation or stale collateral?
  3. 49 words maximum. Confirm eight-week capacity, Zurich and Frankfurt attendance, and all provider or hardware relationships relevant to independent assurance.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.