Life At TrustSphere
We are a practitioner company. The people who have run GRC programmes, argued cyber budgets in front of boards and cleaned up after incidents are the same people designing and building 4sight — because a product built at one remove from the work always shows it.
How we work
TrustSphere is small enough that the distance between an idea and a shipped change is short. Engineers talk to customers. Practitioners write specifications. Nobody is protected from the consequences of their own design decisions, which turns out to be the most reliable quality control there is.
We are deliberate about scope. The product does a few hard things properly — quantification that survives audit, GRC that reflects live control state, operations that reconcile to one model — rather than a long feature list that is shallow everywhere.
The work is remote-friendly and outcome-measured. We care what shipped and whether it was any good, not how many hours it sat open on someone's screen.
What we look for
Judgement over credentials
Certifications tell us what you studied. We are more interested in a decision you made under uncertainty and what you learned when it went sideways.
Writing that thinks
Most of our disagreements are resolved in writing. Being able to make a clear argument in a paragraph matters more here than it does in most engineering roles.
Comfort with ambiguity
Cyber risk is a field where the honest answer is usually a range. People who need certainty before acting find the work frustrating.
Directness with care
We would rather have the awkward conversation early. That works only if it is done without ego, which is the part we actually screen for.
What you can expect
Real ownership from week one
You will own something that ships and carries your name on it. There is no queue to wait in for interesting work, because there is no bench.
Practitioners around you
Our team and advisory board bring decades of GRC, cyber and platform experience. Access to that is the fastest part of the learning curve here.
Learning as part of the job
Certification and conference support, and time to go deep on FAIR, regulation or engineering craft rather than doing it entirely on weekends.
Flexibility with accountability
Where and when you work is largely yours to arrange. What you committed to and whether it landed is not.
Frequently asked questions
Where are you based, and is the work remote?
TrustSphere is an India-based company working with enterprise clients across sectors. Most roles are remote-friendly with periodic time together; some client-facing roles involve travel.
Do I need a cyber security background to apply?
For advisory and practitioner roles, yes. For engineering, design and product roles, no — we have hired strong people with no security background before and taught them the domain. Curiosity about the domain is non-negotiable; prior expertise in it is not.
What does the hiring process look like?
A conversation about your work, a practical exercise close to something you would actually do here, and a discussion with the people you would work alongside. We give feedback either way.
There is no role listed that fits me. Should I still write?
Yes. We are small and hire opportunistically. Tell us what you are good at and what you would want to own, and we will tell you honestly whether there is something worth talking about.
Related
If this sounds like the way you want to work, tell us.
We hire opportunistically rather than to a fixed headcount plan, so a good person with no matching role open is still worth a conversation. Tell us what you are good at and what you would want to own.