Senior Confidential Computing Infrastructure Engineer
Job Summary
About the Opportunity
Personal Connect is recruiting a Senior Confidential Computing Infrastructure Engineer on behalf of an innovative technology company in Beijing.
This is a highly specialized infrastructure engineering position focused on building secure environments for large-scale AI model training and inference. The successful candidate will work with heterogeneous confidential computing environments and help develop infrastructure capable of providing end-to-end verifiable security.
The role combines low-level systems engineering confidential computing virtualization GPU security remote attestation and AI infrastructure.
The position is open to both Chinese and international candidates. International candidates should have a strong academic and professional background and must be able to meet the applicable requirements for obtaining a Chinese work permit.
Key Responsibilities
- Design build deploy and maintain confidential computing infrastructure for large-scale AI model training and inference.
- Deploy and manage Confidential Virtual Machine (CVM) lifecycle infrastructure Key Management Systems (KMS) gateways and related services.
- Work with open-source confidential computing technology stacks such as dstack and similar platforms.
- Build confidential computing environments based on GPU Trusted Execution Environments (GPU-TEE).
- Work with technologies including NVIDIA Confidential Computing Intel TDX and AMD SEV-SNP.
- Develop and implement end-to-end remote attestation mechanisms for large-model training and inference workloads.
- Support measured launch/boot certificate infrastructure key management TLS and related security mechanisms.
- Participate in integration and adaptation for China-developed computing platforms Xinchuang ecosystems and Chinese commercial cryptography standards.
- Support technologies including Hygon CSV Kunpeng Ascend and related attestation environments.
- Work with Hardware Security Modules (HSMs) and cryptographic trust roots.
- Optimize infrastructure for performance reliability stability and security.
- Develop highly reliable low-level system components for production environments.
- Work closely with senior technical leadership including the Technical VP and/or Chief Scientist.
职位介绍
Personal Connect 现受一家位于北京的创新科技企业委托招聘一名高级机密计算基础设施工程师Senior Confidential Computing Infrastructure Engineer
这是一个高度专业化的基础设施工程岗位主要负责为大规模人工智能模型的训练与推理构建安全计算环境成功候选人将参与异构机密计算环境的建设并协助开发能够实现端到端可验证安全的基础设施
该职位涉及底层系统工程机密计算虚拟化GPU 安全远程证明以及 AI 基础设施等多个技术领域
本职位面向中国籍及外籍候选人开放外籍候选人应具备良好的教育及专业背景并需符合在中国申请外国人工作许可的相关条件
主要职责
- 设计搭建部署和维护用于大规模 AI 模型训练与推理的机密计算基础设施
- 部署和管理**机密虚拟机Confidential Virtual MachineCVM**生命周期基础设施密钥管理系统KMS网关及相关服务
- 使用 dstack 等开源机密计算技术栈及类似平台开展基础设施建设
- 构建基于 GPU 可信执行环境GPU-TEE 的机密计算环境
- 使用包括 NVIDIA Confidential ComputingIntel TDXAMD SEV-SNP 在内的相关技术
- 为大模型训练和推理工作负载开发并实现**端到端远程证明Remote Attestation**机制
- 支持度量启动证书基础设施密钥管理TLS 及相关安全机制
- 参与国产计算平台信创生态以及中国商用密码标准的集成与适配
- 支持海光 CSV鲲鹏昇腾及相关远程证明环境
- 使用**硬件安全模块HSM**及密码学信任根相关技术
- 对基础设施进行性能可靠性稳定性和安全性优化
- 为生产环境开发高可靠性的底层系统组件
- 与公司高级技术管理人员紧密合作包括技术 VP 和/或首席科学家
Requirements
Candidates should have:
- 38 years of professional experience in systems engineering infrastructure engineering low-level software development or a closely related field.
- Strong programming skills in Rust and/or C/Go.
- Strong knowledge of Linux systems and low-level Linux architecture.
- Practical experience with areas such as:
- Linux kernel
- Virtualization
- KVM/QEMU
- Drivers
- System calls
- Experience with at least one major TEE or confidential computing technology such as:
- Intel TDX
- AMD SEV-SNP
- NVIDIA Confidential Computing
- Intel SGX
- Confidential Virtual Machines
- Understanding of remote attestation and trusted execution concepts.
- Understanding of measured boot/launch and platform integrity verification.
- Knowledge of key management certificates PKI and TLS.
- Experience developing reliable systems or infrastructure components where performance stability and security are critical.
Preferred Qualifications
The following experience will be considered a strong advantage:
- Previous experience with a major cloud providers confidential computing or trusted computing team.
- Experience in TEE hardware security chip security or confidential computing infrastructure.
- Experience with CUDA GPU drivers or GPU kernel-level development.
- Knowledge of cryptography and applied security engineering.
- Familiarity with privacy-preserving or secure computation technologies such as:
- Homomorphic Encryption (HE)
- Multi-Party Computation (MPC)
- Experience deploying or contributing to open-source confidential computing projects such as:
- dstack
- Occlum
- Gramine
- Experience with Hygon CSV Kunpeng Ascend Chinese HSM environments or related China-developed trusted computing technologies.
候选人应具备
- 38 年相关工作经验包括系统工程基础设施工程底层软件开发或其他高度相关领域
- 熟练掌握 Rust 和/或 CGo
- 深入了解 Linux 系统及 Linux 底层架构
- 具备以下一个或多个领域的实际经验
- Linux 内核
- 虚拟化
- KVM/QEMU
- 驱动程序
- 系统调用
- 熟悉至少一种主要的 TEE 或机密计算技术例如
- Intel TDX
- AMD SEV-SNP
- NVIDIA Confidential Computing
- Intel SGX
- Confidential Virtual Machine机密虚拟机
- 理解**远程证明Remote Attestation**及可信执行相关概念
- 理解度量启动及平台完整性验证机制
- 熟悉密钥管理证书PKI 及 TLS体系
- 具有开发高可靠系统或基础设施组件的经验并能够在实际工作中兼顾性能稳定性及安全性
优先考虑条件
具备以下经验者将被优先考虑
- 曾在大型云服务商的机密计算或可信计算团队工作
- 具备 TEE硬件安全芯片安全或机密计算基础设施相关经验
- 熟悉 CUDAGPU 驱动或 GPU 内核级开发
- 具备密码学及应用安全工程相关知识
- 熟悉以下隐私保护或安全计算技术
- 同态加密Homomorphic EncryptionHE
- 多方安全计算Multi-Party ComputationMPC
- 具有以下开源机密计算项目的部署或贡献经验
- dstack
- Occlum
- Gramine
- 具有海光 CSV鲲鹏昇腾中国商用密码 HSM 环境或其他国产可信计算技术相关经验
RMB per month
Final compensation will depend on the candidates technical expertise professional experience academic background and overall suitability for the position.
人民币 元/月
最终薪资将根据候选人的技术能力专业经验教育背景及与职位的整体匹配程度确定
Required Skills:
Requirements Candidates should have: 38 years of professional experience in systems engineering infrastructure engineering low-level software development or a closely related field. Strong programming skills in Rust and/or C/Go. Strong knowledge of Linux systems and low-level Linux architecture. Practical experience with areas such as: Linux kernel Virtualization KVM/QEMU Drivers System calls Experience with at least one major TEE or confidential computing technology such as: Intel TDX AMD SEV-SNP NVIDIA Confidential Computing Intel SGX Confidential Virtual Machines Understanding of remote attestation and trusted execution concepts. Understanding of measured boot/launch and platform integrity verification. Knowledge of key management certificates PKI and TLS. Experience developing reliable systems or infrastructure components where performance stability and security are critical. Preferred Qualifications The following experience will be considered a strong advantage: Previous experience with a major cloud providers confidential computing or trusted computing team. Experience in TEE hardware security chip security or confidential computing infrastructure. Experience with CUDA GPU drivers or GPU kernel-level development. Knowledge of cryptography and applied security engineering. Familiarity with privacy-preserving or secure computation technologies such as: Homomorphic Encryption (HE) Multi-Party Computation (MPC) Experience deploying or contributing to open-source confidential computing projects such as: dstack Occlum Gramine Experience with Hygon CSV Kunpeng Ascend Chinese HSM environments or related China-developed trusted computing technologies. 候选人应具备 38 年相关工作经验包括系统工程基础设施工程底层软件开发或其他高度相关领域 熟练掌握 Rust 和/或 CGo 深入了解 Linux 系统及 Linux 底层架构 具备以下一个或多个领域的实际经验 Linux 内核 虚拟化 KVM/QEMU 驱动程序 系统调用 熟悉至少一种主要的 TEE 或机密计算技术例如 Intel TDX AMD SEV-SNP NVIDIA Confidential Computing Intel SGX Confidential Virtual Machine机密虚拟机 理解**远程证明Remote Attestation**及可信执行相关概念 理解度量启动及平台完整性验证机制 熟悉密钥管理证书PKI 及 TLS体系 具有开发高可靠系统或基础设施组件的经验并能够在实际工作中兼顾性能稳定性及安全性 优先考虑条件 具备以下经验者将被优先考虑 曾在大型云服务商的机密计算或可信计算团队工作 具备 TEE硬件安全芯片安全或机密计算基础设施相关经验 熟悉 CUDAGPU 驱动或 GPU 内核级开发 具备密码学及应用安全工程相关知识 熟悉以下隐私保护或安全计算技术 同态加密Homomorphic EncryptionHE 多方安全计算Multi-Party ComputationMPC 具有以下开源机密计算项目的部署或贡献经验 dstack Occlum Gramine 具有海光 CSV鲲鹏昇腾中国商用密码 HSM 环境或其他国产可信计算技术相关经验
Required Education:
Relavent education bachelors and above.