SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
TRM Labs is seeking a Senior Cyber Threat Response Advisor to lead end-to-end cyber threat analysis focused on critical infrastructure resilience. This is a senior individual-contributor role within TRM's Cybercrime and Primary Intelligence organization.
You will analyze critical-infrastructure sectors (energy, water, healthcare, financial services, telecommunications, transportation, government systems) to identify organizations most important to protect, surface vulnerabilities and exposures affecting them, and deliver actionable intelligence to critical-infrastructure entities, government partners, and ISACs.
Key responsibilities include:
- Run all-source analysis end-to-end on high-consequence targets, fusing OSINT, external exposure discovery, and threat-actor collection into defensible findings
- Conduct cyber threat collection combining OSINT, attack-surface discovery, and direct threat-actor collection to find and validate exposures and actors positioned to exploit them
- Build AI-assisted tools and workflows to achieve mission objectives at scale while maintaining human quality control
- Map C2 infrastructure, malware families, TTPs, and threat actors to provide network-level context rather than isolated indicators
- Triage large indicator and exposure sets, cluster infrastructure, and turn fragmented signals into clear, actionable findings
- Produce finished intelligence including exposure notifications, actor/campaign profiles, IOC packages, and infrastructure attributions
- Act as senior advisor across multiple active threats, improving quality and supporting other analysts through strong execution
- Partner directly with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on specific exposures and referrals
The role operates in a distributed, async-first environment with primary time-zone overlap in US Eastern/Central. You will work with high autonomy and high standards, with weekly team syncs, daily async standups via Slack, and surge availability during active disruption windows when partners need answers in hours rather than days.
Travel: Up to 50% within the United States, regularly onsite with critical-infrastructure operators, government partners, and ISACs.
REQUIREMENTS:
- 5+ years in cyber threat intelligence, incident response, or closely related analytical field, including experience as primary point of contact for an outside organization during live incident or remediation
- Track record of driving complex analysis independently—taking fragmented information and driving it to real, actionable outcomes, not just writing reports
- Comfort working to external timelines; demonstrated ability to deliver real answers under RFI-style pressure (hours or days, not self-paced research)
- Applied AI fluency required: already building AI-assisted or agentic workflows in daily analytical work; ability to validate outputs and identify failure modes; treating AI as force multiplier for remediation at scale with strong human quality control
- Real collection capability: hands-on experience building or adapting tools for open web, social, forum sources, external attack-surface/exposure discovery, or direct threat-actor collection (strength in one is sufficient; some of both is ideal)
- Demonstrated experience producing finished intelligence: actor profiles, campaign reporting, attribution assessments, exposure notifications, infrastructure mapping
- Strong OSINT instincts; ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources
- Excellent judgment about analytical confidence and evidentiary strength—what can and cannot be defended in reports, referrals, or operational settings
- Excellent written and verbal communication; ability to package findings for technical analysts and non-technical partners
- Comfort in fast-paced environment with changing priorities and normal ambiguity
- Must be based in the United States; U.S. citizenship required
NICE-TO-HAVE:
- Direct familiarity with one or more critical-infrastructure sectors and their operating environments (ICS/OT/SCADA, healthcare, energy, financial-sector security)
- Experience working with or delivering intelligence to government partners, ISACs, or sector coordinating bodies
- Working proficiency in a language heavily used by cyber actors, particularly if used operationally
- Public presence: conference talks, published research, or invite-only sharing circles