← All jobs
TL

Senior Cyber Threat Response Advisor

TRM LabsUnited States
Type
Full-time
Work setup
Remote
Experience
Senior
Posted
Today
🌍 Fully remote

What security roles in crypto pay

77 salaries · our own data
median $200k$145k$268k

Most security roles in crypto pay between $145k and $268k, with a median of $200k.

As a Senior Cyber Threat Response Advisor at TRM Labs, you focus on cyber resilience for critical infrastructure. You analyze critical-infrastructure sectors to identify the organizations most important to protect, surface vulnerabilities and exposures affecting them, and deliver that intelligence to critical-infrastructure entities, government partners, and ISACs who can act on it. This is a senior individual-contributor role where you run all-source analysis end to end on consequential targets, fusing OSINT, external exposure discovery, and threat-actor collection into defensible findings.

What you'll do

  • Drive end-to-end remediation for your sectors by analyzing critical-infrastructure sectors to identify the organizations most important to protect and surface the vulnerabilities and exposures affecting them, from first signal through to actionable notification.
  • Run cyber threat collection by combining OSINT, external attack-surface and exposure discovery, and direct threat-actor collection to find and validate exposures and the actors positioned to exploit them across fragmented sources.
  • Leverage AI to build the tools and workflows necessary to achieve your mission with speed and scale, ensuring human quality control over every output, and feed what works back into TRM's tooling and methods so defense scales beyond your own caseload.
  • Build the network picture around cyber threats by mapping C2 infrastructure, malware families, TTPs, and the actors operating them so findings reflect how a threat against a sector actually operates.
  • Triage at scale by working through large indicator and exposure sets, clustering infrastructure, and turning fragmented signals into clear, defensible findings that stakeholders can act on immediately.
  • Produce finished intelligence including exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions that hold up when tested by critical-infrastructure defenders, government partners, or ISACs.
  • Act as a senior advisor across multiple active threats at once, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution.
  • Partner across the ecosystem by working directly with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on specific exposures, actors, and referrals.

What you bring

  • 5+ years in cyber threat intelligence, incident response, or a closely related analytical field, including experience as the primary point of contact for an outside organization during a live incident or remediation.
  • A track record of driving complex analysis independently, taking fragmented information and driving it to a real, actionable outcome rather than just writing a report about it.
  • Comfort working to someone else's clock and delivering real answers under RFI-style pressure, where a partner needs something in hours or days rather than on a self-paced research timeline.
  • Applied AI fluency: you are already building AI-assisted or agentic workflows in your daily analytical work, can show how you validate their outputs and where they fail, and treat AI as a force multiplier for remediation at scale with strong human quality control over resulting output.
  • Real collection capability, whether hands-on experience building or adapting tools to pull signal from open web and social sources, external attack-surface and exposure discovery, or direct threat-actor collection.
  • Demonstrated experience producing finished intelligence such as actor profiles, campaign reporting, attribution assessments, exposure notifications, or infrastructure mapping.
  • Strong OSINT instincts and the ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources.
  • Excellent judgment about analytical confidence and evidentiary strength, understanding what can and cannot be defended in a report, referral, or operational setting.
  • Excellent written and verbal communication: you can package a finding for a technical analyst and for a non-technical partner alike.
  • Comfort operating in an environment where priorities can change quickly and ambiguity is normal.
  • U.S. citizenship and ability to be based in the United States.
  • Willingness to travel up to 50% within the United States, regularly working onsite with critical-infrastructure operators, government partners, and ISACs.

Nice to have

  • Direct familiarity with one or more critical-infrastructure sectors and their operating environments such as ICS/OT/SCADA, healthcare, energy, or financial-sector security.
  • Experience working with or delivering intelligence to government partners, ISACs, or sector coordinating bodies.
  • Working proficiency in a language heavily used by cyber actors, particularly if used operationally rather than academically.
  • A public presence such as conference talks, published research, or invite-only sharing circles.

About TRM Labs

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. A Series C company with $220M in total funding backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others, TRM is headquartered in San Francisco and operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.

Senior Cyber Threat Response Advisor | CryptoJobsHQ