Senior / Staff Cyber Threat Response Advisor
What security roles in crypto pay
81 salaries · our own dataMost security roles in crypto pay between $141k and $269k, with a median of $200k.
As a Senior or Staff Cyber Threat Response Advisor at TRM Labs, you will lead end-to-end analysis focused on cyber resilience for critical infrastructure. You join the Cybercrime team within Primary Intelligence to identify the organizations most important to protect, surface vulnerabilities and exposures affecting them, and deliver actionable intelligence to critical-infrastructure entities, government partners, and ISACs. This is a senior individual-contributor role where you run all-source analysis on consequential targets, fusing OSINT, external exposure discovery, and threat-actor collection into defensible findings.
What you'll do
- Drive end-to-end remediation for critical-infrastructure sectors by analyzing organizations most important to protect and surfacing vulnerabilities and exposures they face, from first signal through to actionable notification.
- Run cyber threat collection by combining OSINT, external attack-surface and exposure discovery, and direct threat-actor collection to find and validate exposures and the actors positioned to exploit them across fragmented sources.
- Build with AI to create tools and workflows necessary to achieve your mission with speed and scale, ensuring human quality control over every output, and feed learnings back into TRM's tooling and methods.
- Build the network picture around cyber threats by mapping C2 infrastructure, malware families, TTPs, and the actors operating them so findings reflect how threats against a sector actually operate.
- Triage at scale by working through large indicator and exposure sets, clustering infrastructure, and turning fragmented signals into clear, defensible findings stakeholders can act on immediately.
- Produce finished intelligence including exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions that hold up when tested by defenders, government partners, or ISACs.
- Act as a senior advisor across multiple active threats, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution.
- Partner directly with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on the specific exposures, actors, and referrals in front of you.
What you bring
- 5-8+ years in cyber threat intelligence, incident response, or a closely related analytical field, including experience as the primary point of contact for an outside organization during a live incident or remediation.
- A track record of driving complex analysis independently, taking fragmented information and driving it to a real, actionable outcome rather than just producing a report.
- Comfort working to someone else's clock, delivering real answers under RFI-style pressure when partners need something in hours or days, with examples to demonstrate this capability.
- Applied AI fluency with experience already building AI-assisted or agentic workflows in daily analytical work, ability to show how you validate outputs and where they fail, and treatment of AI as a force multiplier for remediation at scale.
- Real collection capability, whether hands-on experience building or adapting tools to pull signal from open web, social, and forum sources, external attack-surface and exposure discovery, or direct threat-actor collection.
- Demonstrated experience producing finished intelligence such as actor profiles, campaign reporting, attribution assessments, exposure notifications, or infrastructure mapping.
- Strong OSINT instincts and the ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources.
- Excellent judgment about analytical confidence and evidentiary strength, understanding what can and cannot be defended in a report, referral, or operational setting.
- Excellent written and verbal communication, able to package findings for both technical analysts and non-technical partners.
- U.S. citizenship required. Must be based in the United States.
- Travel up to 50% within the United States, regularly onsite with critical-infrastructure operators, government partners, and ISACs.
Nice to have
- Direct familiarity with one or more critical-infrastructure sectors and their operating environments such as ICS/OT/SCADA, healthcare, energy, or financial-sector security.
- Experience working with or delivering intelligence to government partners, ISACs, or sector coordinating bodies.
- Working proficiency in a language heavily used by cyber actors, particularly if used operationally rather than academically.
- A public presence such as conference talks, published research, or invite-only sharing circles.
About TRM Labs
TRM Labs is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. TRM provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime, enabling investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
Context for this role
From the live jobs we track on CryptoJobsHQ, updated daily.
TRM Labs has 68 open roles on CryptoJobsHQ: 25 in Engineering, 16 in Design and 8 in Research. 94% are fully remote, most of the rest in the UK and the UAE. 18 were posted in the last 7 days. The median advertised base salary is $195k, from 21 listings that publish pay.
All 68 TRM Labs roles →1,282 Infrastructure roles are open across crypto right now.
Browse Infrastructure Jobs →- AI Blockchain Security Engineer at ByLabs · On-site
- Digital Assets Structuring & Tokenization Associate at Traderpal Token · On-site
- Internal Auditor - Crypto Payments at Axiom Recruit · Remote
- Director, Ecosystem & Product Security at Stellar Development Foundation · Remote
