Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Subscriptions

Senior Cyber Threat Response Advisor

Full-time

TRM Labs

BUILD A SAFER WORLD.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

ABOUT THE ROLE

Critical infrastructure — energy, water, healthcare, financial services, telecommunications, transportation, and the government systems that depend on them — is under sustained pressure from the full spectrum of cyber threat actors, from financially motivated criminals through to nation-state operators. The organizations most important to protect are often the ones with the least visibility into their own exposure.

TRM’s Cybercrime team, part of the Primary Intelligence organization, works to close that gap. As a Senior Cyber Threat Response Advisor focused on cyber resilience for critical infrastructure, your job is to analyze critical-infrastructure sectors, identify the organizations that matter most to protect, surface the vulnerabilities and exposures affecting them, and get that intelligence into the hands of the people who can act on it — the critical-infrastructure entities themselves as consumers, working alongside government and ISAC partners.

This is a senior individual-contributor role for someone who wants to do the work directly. You will run all-source analysis end to end on some of the most consequential targets in the cyber mission, fusing OSINT, external exposure discovery, and threat-actor collection into defensible findings that partners can act on immediately.

THE IMPACT YOU WILL HAVE

– Drive end-to-end remediation for your sectors. Analyze critical-infrastructure sectors to identify the organizations most important to protect, and surface the vulnerabilities and exposures affecting them — from a first signal through to an actionable notification a defender can use.

– Run cyber threat collection. Combine OSINT, external attack-surface and exposure discovery, and direct threat-actor collection to find and validate exposures — and the actors positioned to exploit them — across fragmented sources.

– Build with AI, not just use it. Leverage AI to build the tools and workflows necessary to achieve your mission with speed and scale, ensuring human quality control over every output. Feed what works back into TRM’s tooling and methods so defense and remediation against cyber threats scale beyond your own caseload.

– Build the network picture around cyber threats. Map C2 infrastructure, malware families, TTPs, and the actors operating them, so a finding reflects how a threat against a sector actually operates rather than a catalogue of isolated indicators.

– Triage at scale. Work through large indicator and exposure sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings that stakeholders can act on immediately.

– Produce finished intelligence. Deliver exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions that hold up when tested by a critical-infrastructure defender, a government partner, or an ISAC.

– Act as a senior advisor across multiple active threats at once, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution.

– Partner across the ecosystem. Work directly with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on the specific exposures, actors, and referrals in front of you.

WHAT WE’RE LOOKING FOR

– 5+ years in cyber threat intelligence, incident response, or a closely related analytical field, including experience as the primary point of contact for an outside organization during a live incident or remediation.

– A track record of driving complex analysis independently — taking a body of fragmented information and driving it to a real, actionable outcome, not just writing a report about it.

– You are comfortable working to someone else’s clock. You have delivered real answers under RFI-style pressure — a partner needing something in hours or days, not on a self-paced research timeline — and can point to examples.

– Applied AI fluency is required. We expect you to already be building AI-assisted or agentic workflows in your daily analytical work, to be able to show how you validate their outputs and where they fail, and to treat AI as a force multiplier for remediation at scale rather. AI tools should be a meaningful part of your research, synthesis, and workflow acceleration toolkit, with strong human quality control over the resulting output.

– Real collection capability, whether that’s hands-on experience building or adapting tools to pull signal from open web, social, and forum sources, external attack-surface and exposure discovery, or direct threat-actor collection. Real strength in one is enough; some of both is ideal.

– Demonstrated experience producing finished intelligence such as actor profiles, campaign reporting, attribution assessments, exposure notifications, or infrastructure mapping.

– Strong OSINT instincts and the ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources.

– Excellent judgment about analytical confidence and evidentiary strength — what can and cannot be defended in a report, a referral, or an operational setting.

– Excellent written and verbal communication — you can package a finding for a technical analyst and for a non-technical partner alike.

– Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.

– Travel: Up to 50%, within the United States. You will regularly be onsite with critical-infrastructure operators, government partners, and ISACs.

– Must be based in the United States. U.S. citizenship is required.

NICE-TO-HAVE

– Direct familiarity with one or more critical-infrastructure sectors and their operating environments (e.g., ICS/OT/SCADA, healthcare, energy, or financial-sector security).

– Experience working with or delivering intelligence to government partners, ISACs, or sector coordinating bodies.

– Working proficiency in a language heavily used by cyber actors, particularly if used operationally rather than academically.

– A public presence: conference talks, published research, or invite-only sharing circles.

ABOUT THE TEAM

– TRM’s Cybercrime team sits within the Primary Intelligence organization, alongside the other threat categories, and combines expert tradecraft and boundary-pushing innovation with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.

– Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment.

– High autonomy, high standards, low bureaucracy — you work directly with analysts, engineers, and the partners and customers who depend on your output.

TEAM OPERATING RHYTHMS

– Weekly team syncs to align targeting priorities and review disruption opportunities.

– Daily async standups via Slack on active work, returns, and target packages in flight.

– Primary time zone overlap: US Eastern / Central.

– All output documented in Notion and TRM’s investigative tools.

– Surge availability. There is no formal on-call rotation. During active disruption windows, typically when a partner needs an answer in hours rather than days, the team flexes hours to meet the moment.

LEARN ABOUT TRM SPEED IN THIS POSITION

– Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.

– Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.

– Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.

APPLICATION INSTRUCTIONS

If you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.

Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.

If you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.

WHAT TO EXPECT FROM OUR INTERVIEW PROCESS

Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.

– Recruiter Intro: Explore your experience, motivations, and alignment with the role.

– Hiring Manager: Dive deeper into your relevant experience, skills, and impact.

– First Round: Typically 1–2 interviews focused on the skills most critical to the role.

– Final Round: Typically 3–5 interviews to go deeper on your craft, problem-solving, and alignment with TRM.

– References: We’ll speak with former colleagues who can provide perspective on your work and impact.

– Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.

– Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.

Your recruiter will share your specific interview plan and preparation guidance along the way.

Learn more about interviewing at TRM

LIFE AT TRM

We are building a safer world. That promise shows up in how we work every day.

TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

At TRM, you should expect:

– Priorities and targets to change quickly as we experiment and iterate

– Work that often requires operating with a high degree of ambiguity

– A high level of personal ownership and accountability

– Close collaboration across teams and functions

– Frequent, high-touch communication

– Creative problem solving and out-of-the-box thinking

– A pace that rewards urgency, adaptability, and outcomes

This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.

We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.

At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more about Interviewing at TRM

 

AI FLUENCY AT TRM

AI fluency is a baseline expectation at TRM.

We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.

At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:

– Accelerate repeatable workflows

– Structure and solve problems

– Improve output quality

– Increase speed and leverage

You will be evaluated on applied AI fluency during the interview process.

LEADERSHIP PRINCIPLES

We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.

– Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

– Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.

– Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.

JOIN OUR MISSION

At TRM, we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.

TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Learn more about building tools for defenders

PRIVACY POLICY AND ADDITIONAL INFORMATION

By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy

We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.

Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at View email address on codingjobboard.com.

To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form No response will be provided to inquiries unrelated to job posting compliance.

The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form

RECRUITMENT AGENCIES

TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.

LEARN MORE: COMPANY VALUES | INTERVIEWING | FAQS

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior Cyber Threat Response Advisor in Remote vacancy
  •  ...Senior DevOps Engineer Who We Are MOXFIVE is building technologies that leverage AI to streamline the response, recovery, and resilience from cyber-attacks in enterprises. We are looking for a talented Senior DevOps Engineer to join as a core member of our founding... 

    Moxfive

    Remote
    5 days ago
  • $2000 per year

     ...growing. This is a general track for Senior+ (Senior/Staff/Principal) Engineers in any...  ...Managers, Directors, VPs) to take joint responsibility for outcomes at team, department and...  ...Software security – fuzzing, tabletop threat models, analysis, audit Build systems... 

    Canonical

    Remote
    7 days ago
  •  ...cases, and construct operating pictures of threat networks. Leading agencies and businesses...  ...for TRM’s products and services. As a Senior Software Engineer on Data Infrastructure...  ...please submit a report through this form No response will be provided to inquiries unrelated... 

    TRM Labs

    Remote
    12 days ago
  •  ...Responsibilities Lead feature development through scoping, architecture, deployment, and iteration based on user data. Build and maintain production-grade web applications and scalable software features. Use AI tools such as Cursor, Copilot, and Claude to accelerate... 

    Parity

    Remote
    8 days ago
  •  ...who will help us create our internal solutions such as a Feature Store and will be ready to perform operational tasks. Key Responsibilities: Development Features store and other future data services; Development EL / ELT / ETL pipelines; Integration new tools... 

    Tabby

    Remote
    14 days ago
  •  ...Responsibilities Evaluate AI-generated coding interactions from end to end. Judge whether outputs are useful, correct at a high level...  ...video explanations of evaluation feedback. Requirements Senior, staff, or principal-level software engineering experience,... 

    G2i Inc.

    Remote
    6 days ago
  •  ...enjoy the internet on their terms.  About this role: As a Senior Software Engineer on the Ecosystem Services Team, you’ll build...  ...services in the cloud rather than handing that responsibility to someone else ~ Hands-on experience with observability and... 

    Mozilla

    Remote
    7 days ago
  •  ...Summary The Wikimedia Foundation is looking for a Senior Software Engineer, iOS to join the App Growth team within the Core Experiences...  ...work day to occur between 14:00 UTC and 21:00 UTC. You are responsible for: Delivery and enablement – Delivery of medium... 

    Wikimedia Foundation

    Remote
    7 days ago
  • $130000 - $195000 per year

     ...Nvidia, and Bridgewater. ABOUT THE ROLE We’re hiring a Senior Technical Support Engineer to lead our customer support experience...  ...technical support looks like for modern AI platforms KEY RESPONSIBILITIES – Be the go-to escalation point for technical support... 

    LangChain

    Remote
    6 days ago
  •  ...the place for you. What you get to do: We’re looking for a Senior Software Engineer to design, build, and scale Java backend...  ...performance, reliability, scalability). – Participate in incident response and support rotations – This role includes participation in... 

    Paymentology

    Remote
    12 days ago
  •  ...scale their portfolios. We’re looking for a highly ambitious Senior Software Engineer who wants to build systems that solve real...  ...see their impact. EXTREME OWNERSHIP Have the freedom and responsibility to make technical decisions and deliver systems that matter.... 

    The Flex

    Remote
    12 days ago
  • $1000 per year

     ...Responsibilities Build and operate agents across the testing lifecycle, including test design, generation, maintenance, execution, and failure triage. Own infrastructure for agent-driven testing, including environments, test data, tool interfaces, guardrails, runtime... 

    Camunda

    Remote
    9 days ago
  •  ...information, please see our  Privacy Policy   We’re looking for Senior AI Engineers to design, build and run LLM-powered agents and...  ...for our engineers. As part of our team, your responsibilities in this role will include: Design and build LLM agents and... 

    Infuse

    Remote
    14 days ago
  •  ...one open, programmable blockchain platform. We are seeking a Senior Software Engineer with experience working with AWS-based backend...  ...to the Core browser extension wallet. The Core team is responsible for delivering a best-in-class wallet experience for the Avalanche... 

    Ava Labs

    Remote
    12 days ago
  • $1000 per year

     ...Camunda’s Revenue Operations organization is looking for a Senior GTM Systems AI and Automation Engineer to design, build and operate...  ...and technical documentation; mentor teammates on responsible AI-assisted development. – Design and deploy workflows on orchestration... 

    Camunda

    Remote
    12 days ago
  • $1000 per year

     ...Responsibilities Design and maintain Camunda’s Kubernetes-based multi-cloud platform for availability, scalability, and fault tolerance. Establish infrastructure configuration best practices and network services used by engineering teams. Implement and improve... 

    Camunda

    Remote
    16 days ago
  •  ...vision and roadmap, translating ecosystem needs into tools and experiences that accelerate platform adoption. About the Role As a Senior Experience Engineer , you will lead the end-to-end delivery of features, from initial problem discovery to production deployment.... 

    Parity

    Remote
    4 days ago
  •  ...widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of... 

    Cohere

    Remote
    16 days ago
  • $1000 per year

     ...your CV, keep reading. About the role: We’re looking for a Senior Site Reliability Engineer who’s passionate about building...  ...alert on what matters. – Strong 3rd-level support and incident response skills – You’ve responded to production incidents, diagnosed complex... 

    Camunda

    Remote
    11 days ago
  •  ...next few months. Join us!! The Role  We're hiring a Staff/Senior Security Engineer to lead our signing and treasury security...  ...and DeFi positions, keep it integrated with our SOC 2 incident-response workflows, and contribute to playbooks for evolving risk scenarios... 

    Ethena Labs

    Remote
    12 days ago
  •  ...Responsibilities Deliver major features and architectural improvements across automated moderation pipelines, Reviewer tools, and DevHub. Build full-stack features using React/TypeScript frontends, Django backends, and MySQL. Create observability systems and... 

    Mozilla

    Remote
    14 days ago
  •  ...Responsibilities Write code and tests, build prototypes, and profile and analyze Firefox performance bottlenecks. Develop performance-critical software using primarily C++ and JavaScript, with other languages as needed. Debug and resolve performance issues using... 

    Mozilla

    Remote
    15 days ago
  •  ...energizing rather than exhausting, keep reading. THE ROLE As Senior Product Manager, Ad Monetization, you’ll join a small product...  ...ambiguity, making decisions under uncertainty, and taking responsibility for the outcomes of those decisions. – You communicate clearly... 

    RevenueCat

    Remote
    15 days ago
  • $1000 per year

     ...to Work” winner (USA & Japan, 2024–2025) and a Top-5 Company for Work-From-Anywhere Jobs (FlexJobs, 2025). We are looking for Senior CV Engineer . Your main tasks will be: Train and fine-tune generative models (text2image, image2image, video2image, IP-adapters... 

    Social Discovery Group

    Remote
    12 days ago
  •  ...We are seeking a Senior iOS Engineer to own the client side implementation of how members join, pay, and stay with Raya. Member...  ...entitlement source of truth, and reconciliation. Requirements: Responsibilities Own the iOS subscription and payments stack end to end... 

    Raya

    Remote
    8 days ago
  •  ...systems that enable rapid iteration while maintaining a high bar for quality, reliability, and scalability.   YOUR MISSION  As a Senior Software Engineer on the Growth & Engagement team, you’ll build the products, platforms, and experimentation capabilities that help... 

    MURAL

    Remote
    4 days ago
  •  ...and scale their portfolios. We’re looking for an ambitious Senior Full-Stack Product Engineer who wants to turn real customer problems...  ..., how it should work, and how to measure its success. Take responsibility for features from the first conversation through ongoing... 

    The Flex

    Remote
    11 days ago
  •  ...for our clients.   The opportunity – We’re looking for a Senior React Native Engineer who thinks like a product builder. –...  ...experiences in React Native across a financial product where responsiveness, reliability and trust matter, whether improving product discovery... 

    Kraken

    Remote
    12 days ago
  • $1000 per year

     ...rare on your CV, keep reading. About the Role: Camunda is going through the AI-First transformation, and we are looking for a Senior Software Engineer to join our Engineering Operations Team. As part of this high-impact platform team, you will play a key role in... 

    Camunda

    Remote
    11 days ago
  • $21393 per year

     ...Application Prep Guide ! Referrals Know the right person for this role? Please consider . We offer a reward of $3,000 for a Senior Manager or above role, and $500 for a Manager role, paid if we end up hiring your referral. Thank you for sending great people our... 

    GiveDirectly

    Remote
    7 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Cyber Threat Response Advisor. Be the first to apply!