You'll own security end to end, from decisions in the code to reassuring clients. The role is roughly 60% hands-on product and cloud security and 40% assurance and client-facing work.
TresVista has run the analytical work behind private capital since 2006. 2,000 people, 400+ clients including some of the biggest names in the industry, no outside capital and no outside board. That was the first chapter. And we enjoyed getting here!
We are moving from services to software, from one firm's workflows to an industry's, and from executing investment decisions to shaping how they get made. Thirty of us in King's Cross, small and senior, with day one founder intensity. At its fullest expression, Descrial changes how every serious investment firm decides.
You report to the Head of Engineering, work with the Cloud Architect on AWS security and partner with TresVista's compliance organisation on certification readiness. You make security practical for engineers and credible in client reviews.
You own secure development practices: threat modelling, secure code review, dependency and secrets hygiene, and CI/CD security gates. With the Cloud Architect, you set AWS patterns for IAM, network segmentation, encryption, logging and detection.
You set defences against prompt injection and data leakage, tool-use guardrails and model-provider risk assessment. You define what an agent may do for a user, how authorisation is scoped by tenant and how actions are attributed and audited. You own AI supply-chain risk, including model and weights provenance, third-party assessments and detecting provider changes or deprecations.
With TresVista, you drive SOC 2 and ISO 27001 readiness and prepare for ISO 42001 and EU AI Act obligations, owning the technical evidence. You run penetration testing and vulnerability management through scoping, remediation, verification and reporting. Alongside Compliance, you handle client questionnaires, due diligence and security terms in enterprise contracts.
You establish security monitoring and incident-response runbooks sized for a scale-up. You help engineers adopt secure practices and keep access and joiner/leaver discipline consistent across London and Bengaluru.
This will be difficult.
It demands pace and accuracy. We are building autonomous systems inside high-stakes live businesses, where decisions carry real consequences and impact and waiting for everyone to agree is not always an option.
The systems will sometimes get things wrong. In this phase the London team needs to create the evaluations, visibilities and safeguards that catch mistakes early, reducing them over time and stopping the same failures happening again.
If you want to build the foundations of an enterprise grade technology platform to service a multi-billion $ serviceable market opportunity, and share in that growth, this is your chance to join us.
Come ready to discuss three pieces of work:
The all-inclusive package is typically £115,000–£135,000 a year, depending on experience.
You do not need to meet every qualification to apply. Strong candidates bring different combinations of experience, judgement and potential, and we know that some people are more likely than others to underestimate what they could contribute. If the work interests you and you believe you could make an impact, we encourage you to apply.
The systems we are building will influence how important investment decisions are made. That makes a range of experiences and perspectives essential to building them responsibly. We want a team where different viewpoints are heard, respected and reflected in the work.
Descrial does not receive a stack of CVs. We interview you ourselves, and only put you forward with our own assessment attached.
Once we introduce you, Descrial runs its own process.
They aim to complete the process within three weeks.
We read every application properly. You will always be able to see where yours has got to.
Apply for Cyber Security LeadREF JDR-DES-0003
One a week, never sold on, and one click to stop.
We use a few cookies to keep the site running. Necessary ones are always on. Analytics + marketing are off until you say otherwise.
Read our cookie policy · privacy.