SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
TRM Labs is an AI-powered intelligence platform helping public and private sector agencies investigate and disrupt crime by tracing illicit activity and mapping threat networks. The company is Series C-funded ($220M) and headquartered in San Francisco with distributed hubs across Los Angeles, New York, Washington D.C., London, and Singapore.
You will lead TRM's hacks category end-to-end, owning the metrics, systems, and contractor team that respond to major cryptocurrency protocol drains and exchange compromises. Your core responsibilities include:
- Command incident response when major hacks break: triage, cross-team coordination, internal and customer communications, and post-incident reporting.
- Ensure every major hack is visible to customers within hours of credible public reports, operating 24/7.
- Maintain complete and accurate hack data (entity, theft addresses, date, amount, hack type) across all sizes.
- Design systems with Data Science and Engineering teams to track hack-specific attribution as stolen funds move downstream.
- Build AI-assisted tools and agents to automate key parts of hacks analysis while maintaining human quality control.
- Produce best-in-industry technical analysis and root-cause reports that position TRM as the authoritative source.
- Develop proactive approaches to identify vulnerable contracts before exploitation.
You will work closely with the Nation States, Cyber Threat Intelligence, and Global Investigations teams, plus Data Science and Engineering on automation and Marketing on publications. The role includes on-call responsibilities and monthly metrics reviews with your manager.
TRM operates at high velocity with a mission-driven culture that rewards speed, ownership, and impact. The environment is intense and fast-moving; priorities shift as the company experiments and iterates. Success requires comfort with ambiguity, adaptability, and a focus on outcomes over process.
REQUIREMENTS:
- 5+ years of professional experience in blockchain intelligence, crypto investigations, cyber threat intelligence, incident response, or closely related field.
- Demonstrated ownership of incident response in high-stakes environments (exchange, security firm, incident response team, or CTI team), including war rooms, incident reports, and communications under pressure.
- Strong blockchain tracing expertise across major chains (BTC, EVM, TRON, Solana), including bridges, cross-chain swaps, and mixers.
- Understanding of how DeFi, bridge, and exchange exploits work and attacker behavior post-theft.
- Applied AI fluency: already building AI-assisted or agentic workflows in daily analytical work, able to validate outputs and identify failure modes, treating AI as a force multiplier.
- Experience managing contractors or leading a small team.
- Clear writing and briefing skills, from technical deep-dives to executive summaries.
- Hands-on, highly accountable approach: does the hardest work, not just coordinates.
NICE TO HAVE:
- Smart-contract reverse-engineering (Solidity).
- Experience at a security auditor or blockchain analytics firm.
- Experience tracking specific well-known hacker groups.