TRM Labs

Senior / Staff Cyber Threat Response Advisor

United States

As of 2026-10-06, ChainJobs confirms TRM Labs is hiring a Senior / Staff Cyber Threat Response Advisor in United States, paying $168k–228k (employer-published); posted 2026-09-29, apply on trmlabs.com.

categoryOperations
salary$168k–228k
typeRemote
posted2026-09-29
sourcetrmlabs.com/careers
confirmed opentoday (2026-10-06)
Apply on trmlabs.com → Applications happen on the company's own careers site — we never gate them.
similar roles at other companies

Still open on TRM Labs’s own careers page when we last checked, today (2026-10-06). We re-check every listing daily and remove roles the moment they disappear at the source — how this works.

role description

Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Role

Critical infrastructure — energy, water, healthcare, financial services, telecommunications, transportation, and the government systems that depend on them — is under sustained pressure from the full spectrum of cyber threat actors, from financially motivated criminals through to nation-state operators. The organizations most important to protect are often the ones with the least visibility into their own exposure.

TRM's Cybercrime team, part of the Primary Intelligence organization, works to close that gap. As a Senior / Staff Cyber Threat Response Advisor focused on cyber resilience for critical infrastructure, your job is to analyze critical-infrastructure sectors, identify the organizations that matter most to protect, surface the vulnerabilities and exposures affecting them, and get that intelligence into the hands of the people who can act on it — the critical-infrastructure entities themselves as consumers, working alongside government and ISAC partners.

This is a senior individual-contributor role for someone who wants to do the work directly. You will run all-source analysis end to end on some of the most consequential targets in the cyber mission, fusing OSINT, external exposure discovery, and threat-actor collection into defensible findings that partners can act on immediately.

The impact you will have

  • Drive end-to-end remediation for your sectors. Analyze critical-infrastructure sectors to identify the organizations most important to protect, and surface the vulnerabilities and exposures affecting them — from a first signal through to an actionable notification a defender can use.

  • Run cyber threat collection. Combine OSINT, external attack-surface and exposure discovery, and direct threat-actor collection to find and validate exposures — and the actors positioned to exploit them — across fragmented sources.

  • Build with AI, not just use it. Leverage AI to build the tools and workflows necessary to achieve your mission with speed and scale, ensuring human quality control over every output. Feed what works back into TRM's tooling and methods so defense and remediation against cyber threats scale beyond your own caseload.

  • Build the network picture around cyber threats. Map C2 infrastructure, malware families, TTPs, and the actors operating them, so a finding reflects how a threat against a sector actually operates rather than a catalogue of isolated indicators.

  • Triage at scale. Work through large indicator and exposure sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings that stakeholders can act on immediately.

  • Produce finished intelligence. Deliver exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions that hold up when tested by a critical-infrastructure defender, a government partner, or an ISAC.

  • Act as a senior advisor across multiple active threats at once, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution.

  • Partner across the ecosystem. Work directly with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on the specific exposures, actors, and referrals in front of you.

What we're looking for

  • 5-8+ years in cyber threat intelligence, incident response, or a closely related analytical field, including experience as the primary point of contact for an outside organization during a live incident or remediation.

  • A track record of driving complex analysis independently — taking a body of fragmented information and driving it to a real, actionable outcome, not just writing a report about it.

  • You are comfortable working to someone else's clock. You have delivered real answers under RFI-style pressure — a partner needing something in hours or days, not on a self-paced research timeline — and can point to examples.

  • Applied AI fluency is required. We expect you to already be building AI-assisted or agentic workflows in your daily analytical work, to be able to show how you validate their outputs and where they fail, and to treat AI as a force multiplier for remediation at scale rather. AI tools should be a meaningful part of your research, synthesis, and workflow acceleration toolkit, with strong human quality control over the resulting output.

  • Real collection capability, whether that's hands-on experience building or adapting tools to pull signal from open web, social, and forum sources, external attack-surface and exposure discovery, or direct threat-actor collection. Real strength in one is enough; some of both is ideal.

  • Demonstrated experience producing finished intelligence such as actor profiles, campaign reporting, attribution assessments, exposure notifications, or infrastructure mapping.

  • Strong OSINT instincts and the ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources.

  • Excellent judgment about analytical confidence and evidentiary strength — what can and cannot be defended in a report, a referral, or an operational setting.

  • Excellent written and verbal communication — you can package a finding for a technical analyst and for a non-technical partner alike.

  • Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.

  • Travel: Up to 50%, within the United States. You will regularly be onsite with critical-infrastructure operators, government partners, and ISACs.

  • Must be based in the United States. U.S. citizenship is required.

Nice-to-have

  • Direct familiarity with one or more critical-infrastructure sectors and their operating environments (e.g., ICS/OT/SCADA, healthcare, energy, or financial-sector security).

  • Experience working with or delivering intelligence to government partners, ISACs, or sector coordinating bodies.

  • Working proficiency in a language heavily used by cyber actors, particularly if used operationally rather than academically.

  • A public presence: conference talks, published research, or invite-only sharing circles.

About the Team

  • TRM's Cybercrime team sits within the Primary Intelligence organization, alongside the other threat categories, and combines expert tradecraft and boundary-pushing innovation with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.

  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment.

  • High autonomy, high standards, low bureaucracy — you work directly with analysts, engineers, and the partners and customers who depend on your output.

Team Operating Rhythms

  • Weekly team syncs to align targeting priorities and review disruption opportunities.

  • Daily async standups via Slack on active work, returns, and target packages in flight.

  • Primary time zone overlap: US Eastern / Central.

  • All output documented in Notion and TRM's investigative tools.

  • Surge availability. There is no formal on-call rotation. During active disruption windows, typically when a partner needs an answer in hours rather than days, the team flexes hours to meet the moment.

Learn about TRM Speed in this position

  • Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.

  • Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.

  • Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.

Application Instructions

If you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.

Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.

If you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.

What to Expect From Our Interview Process

Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.

  • Recruiter Intro: Explore your experience, motivations, and alignment with the role.

  • Hiring Manager: Dive deeper into your relevant experience, skills, and impact.

  • First Round: Typically 1–2 interviews focused on the skills most critical to the role.

  • Final Round: Meet some of the people you'd be working with. This is usually a panel-style session where we go deeper on your craft, problem-solving, and alignment with TRM.

  • References: We’ll speak with former colleagues who can provide perspective on your work and impact.

  • Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.

  • Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.

Your recruiter will share your specific interview plan and preparation guidance along the way.

Learn more about interviewing at TRM

Life at TRM

We are building a safer world. That promise shows up in how we work every day.

TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

At TRM, you should expect:

  • Priorities and targets to change quickly as we experiment and iterate

  • Work that often requires operating with a high degree of ambiguity

  • A high level of personal ownership and accountability

  • Close collaboration across teams and functions

  • Frequent, high-touch communication

  • Creative problem solving and out-of-the-box thinking

  • A pace that rewards urgency, adaptability, and outcomes

This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information em

Sourced from TRM Labs's official listing — full details and how to apply at the link above.

Apply on trmlabs.com →

Get an alert when new remote crypto operations roles post

We check 210 employers daily. Join now and we'll email when the first alert goes out, then max once a week. Unsubscribe in one click.

Listing ID a7e1d95438e0 · sourced from TRM Labs's official careers page · Report this listing via the contact form (quote the listing ID)

chainjobs.io — refreshed daily from official careers pages.← back to the board
$168k–228kposted rangeApply on trmlabs.com →