SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Polymarket is the world's largest prediction market platform, enabling users to trade on outcomes across politics, economics, sports, culture, and current affairs. The company traded $21B in 2025 and is growing rapidly as an alternative news source.
The Global Intelligence and Investigations team sits within Legal and protects the integrity of Polymarket's markets and platform. This role leads the Threat Intelligence function, which is the external-facing arm responsible for understanding who targets Polymarket and the broader crypto and prediction-market ecosystem, then ensuring that intelligence drives actual defensive changes.
This is not a monitoring role. You will track real threat actors, build Python pipelines that turn raw data into actionable intelligence, and work directly with Product and Security to ship protections. The crypto context matters: transactions are irreversible, adversaries are sophisticated, and the gap between detecting a threat and acting on it has real financial consequences for users.
Key responsibilities include: monitoring external threat actors targeting crypto and prediction-market platforms across open and closed sources; building and maintaining Python pipelines that ingest, normalize, and enrich threat data from internal systems, external feeds, and intelligence partnerships; conducting on-chain analysis to identify suspicious activity and build monitoring systems; writing threat assessments that legal, compliance, and non-technical stakeholders can understand and act on; turning intelligence findings into working detections and automated defenses in coordination with Product and Security; managing relationships with external intelligence providers; and proactively identifying coverage gaps before exploitation.
You need strength on both sides: intelligence tradecraft and engineering. You must be able to track actors and produce written assessments that lawyers can act on, while also building the detection pipelines yourself. This is an end-to-end ownership role.