← All Descrial roles
DESCRIAL

CYBER SECURITY LEAD

at Descrial, part of TresVista

London Full time Reports to Head of Engineering
£115,000 – £135,000
Screened by CHOOSETO

What you would
actually do.

We're hiring a Cyber Security Lead to secure Descrial's product and cloud platform, and to show enterprise buyers that those protections hold up. We handle confidential investment data and our AI agents act on users' behalf, so it matters a great deal who and what can access each piece of data and what each agent is allowed to do.

You'll own security end to end, from decisions in the code to reassuring clients. The role is roughly 60% hands-on product and cloud security and 40% assurance and client-facing work.

About Descrial

Descrial is a startup inside a twenty-year-old company

TresVista has run the analytical work behind private capital since 2006. 2,000 people, 400+ clients including some of the biggest names in the industry, no outside capital and no outside board. That was the first chapter. And we enjoyed getting here!

The next chapter is harder and more interesting

We are moving from services to software, from one firm's workflows to an industry's, and from executing investment decisions to shaping how they get made. Thirty of us in King's Cross, small and senior, with day one founder intensity. At its fullest expression, Descrial changes how every serious investment firm decides.

The role

You report to the Head of Engineering, work with the Cloud Architect on AWS security and partner with TresVista's compliance organisation on certification readiness. You make security practical for engineers and credible in client reviews.

Your remit

The product and cloud

You own secure development practices: threat modelling, secure code review, dependency and secrets hygiene, and CI/CD security gates. With the Cloud Architect, you set AWS patterns for IAM, network segmentation, encryption, logging and detection.

The agent boundaries

You set defences against prompt injection and data leakage, tool-use guardrails and model-provider risk assessment. You define what an agent may do for a user, how authorisation is scoped by tenant and how actions are attributed and audited. You own AI supply-chain risk, including model and weights provenance, third-party assessments and detecting provider changes or deprecations.

The evidence

With TresVista, you drive SOC 2 and ISO 27001 readiness and prepare for ISO 42001 and EU AI Act obligations, owning the technical evidence. You run penetration testing and vulnerability management through scoping, remediation, verification and reporting. Alongside Compliance, you handle client questionnaires, due diligence and security terms in enterprise contracts.

The operating standard

You establish security monitoring and incident-response runbooks sized for a scale-up. You help engineers adopt secure practices and keep access and joiner/leaver discipline consistent across London and Bengaluru.

Your experience

  • You have 7+ years in security engineering, including 3+ years securing cloud-native SaaS. AWS experience is strongly preferred.
  • You have hands-on secure development and application-security depth, including threat modelling, code-level findings and OWASP.
  • You have implemented SOC 2 or ISO 27001 certification programmes and can explain the evidence behind the controls.
  • You have worked directly on client security questionnaires, audits or enterprise due diligence.
  • You have a degree in engineering, computer science or a related field, or equivalent experience.

Useful to have, none required

  • CISSP, OSCP, CCSP or comparable certifications
  • Financial-services security or another regulated industry
  • AI/LLM security, including prompt injection, model risk, data boundaries, ISO 42001 or the EU AI Act
  • Experience as an early security hire

The reality

This will be difficult.

It demands pace and accuracy. We are building autonomous systems inside high-stakes live businesses, where decisions carry real consequences and impact and waiting for everyone to agree is not always an option.

The systems will sometimes get things wrong. In this phase the London team needs to create the evaluations, visibilities and safeguards that catch mistakes early, reducing them over time and stopping the same failures happening again.

If you want to build the foundations of an enterprise grade technology platform to service a multi-billion $ serviceable market opportunity, and share in that growth, this is your chance to join us.

In our conversations

Come ready to discuss three pieces of work:

  • A security boundary you designed: the threat, implementation and evidence that it held.
  • A certification or client review you supported: the gaps and how you closed them.
  • A vulnerability or incident-response improvement you carried through to verification.

Compensation

The all-inclusive package is typically £115,000–£135,000 a year, depending on experience.

Practical details

  • King's Cross, London. In office (3 to 5 days a week), with colleagues in London and Bengaluru.
  • Visa sponsorship is not available for this role.
  • We aim to finish the process within three weeks. Tell us if you need an adjustment to the interviews.
  • Descrial is an equal opportunity employer.

Apply

You do not need to meet every qualification to apply. Strong candidates bring different combinations of experience, judgement and potential, and we know that some people are more likely than others to underestimate what they could contribute. If the work interests you and you believe you could make an impact, we encourage you to apply.

The systems we are building will influence how important investment decisions are made. That makes a range of experiences and perspectives essential to building them responsibly. We want a team where different viewpoints are heard, respected and reflected in the work.

HOW HIRING WORKS

We screen first.
Descrial sees you second.

Descrial does not receive a stack of CVs. We interview you ourselves, and only put you forward with our own assessment attached.

FIRST: CHOOSETO
  1. 1 Application received We have your CV and details.
  2. 2 Initial review We assess your application against the role.
  3. 3 Video introduction We ask you to record a short video introducing yourself.
  4. 4 Shortlisting We review your CV and video together.
THEN: DESCRIAL

Once we introduce you, Descrial runs its own process.

  1. Technical assessment A take-home or live exercise relevant to the role
  2. Interview with a senior member of the team Deeper dive into your experience and how we can work together
  3. Final interview with a member of the Executive Committee Cultural fit, motivation and the offer conversation

They aim to complete the process within three weeks.

Are you a match?

We read every application properly. You will always be able to see where yours has got to.

Apply for Cyber Security Lead

REF JDR-DES-0003