You find ways to learn from useful signals without casually exposing the people behind them, and you test privacy methods against explicit adversaries rather than against good intentions. The premise you will spend a lot of time correcting: keeping raw data on a device does not by itself make a learning system private.
Open for applications. Starts at: Research program.
We are taking applications for this role now and building the pipeline for it. The stage above is when the work itself is expected to begin, which is something you deserve to know before you apply rather than after. It is context, not a gate.
Where
In the office together five days a week, in one of our garages, and remote-friendly around your family, arranged one person at a time. We hire across the United States 🇺🇸, India 🇮🇳 and the UAE 🇦🇪.
The work
Research differential privacy, federated learning, secure aggregation or related techniques where they fit the problem. Measure privacy-utility tradeoffs and leakage from updates or outputs. Work with cryptography and product teams on deployable guarantees and understandable consent.
The milestone
In your first 90 days, deliver a threat model, a reproduced baseline and a privacy evaluation with clearly stated assumptions.
Required
Nice to have
Evidence
Bring rigorous privacy or ML research expertise. Explain why keeping raw data on a device does not by itself make a learning system private.
Evidence, not credentials. We are describing work you can point at, in whatever form it exists.
The exercise
Evaluate a proposed federated training scheme for update leakage, malicious clients and withdrawal after participation.
The package
Indicative pay ranges by market and level are on the compensation page. Plan numbers are confirmed in your offer letter.
Apply
One short form. A person reads every application and you hear back either way. You will get your own link to check where things stand, and you can withdraw or delete your application from it at any time, without an account.