Senior Cyber Threat Response Advisor

Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.

Maintainer signals as of 9/25/2026

450 Townsend Street, San Francisco, CA 94107, United States
About TRM Labs

TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.

View jobs by TRM Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will conduct end-to-end cyber threat analysis for critical-infrastructure sectors. You will identify priority organizations, investigate vulnerabilities and threat actors, produce defensible intelligence, and coordinate remediation with infrastructure operators, government partners, ISACs, engineers, and internal stakeholders.

Requirements

  • 5+ years of cyber threat intelligence, incident response, or a related analytical field
  • Experience serving as the primary contact for an external organization during a live incident or remediation
  • Experience independently driving complex analysis to actionable outcomes
  • Experience delivering time-sensitive RFI-style responses
  • Applied AI fluency and experience validating AI-assisted or agentic workflows
  • Experience with open-web, social, forum, attack-surface, exposure, or threat-actor collection
  • Experience producing finished intelligence
  • OSINT and identity, alias, infrastructure, and behavior-resolution skills
  • Strong analytical judgment and written and verbal communication
  • United States residency and U.S. citizenship

Responsibilities

  • Analyze critical-infrastructure sectors and identify priority organizations and exposures
  • Conduct OSINT, attack-surface discovery, and threat-actor collection
  • Build AI-assisted workflows while validating outputs through human quality control
  • Map command-and-control infrastructure, malware, TTPs, and threat actors
  • Triage indicators and exposures into actionable findings
  • Produce exposure notifications, actor profiles, IOC packages, and infrastructure attributions
  • Advise on multiple active threats and support other analysts
  • Partner with infrastructure entities, government partners, ISACs, and engineers

Benefits

  • Equity plan eligibility

Hiring Process

Recruiter intro → Hiring Manager interview → First Round of 1–2 skills-focused interviews → Final panel round → References → Offer → Onboarding