Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TRM Labs

Senior Cyber Threat Response Advisor

TRM Labs

. Analyze critical-infrastructure sectors and identify organizations most important to protect .

Posted 9/29/2026full-timeRemote • United StatesSenior💰 $140,000 - $168,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Cyber Threat Intelligence and Incident Response, with a strong focus on OSINT, AI-assisted workflows, and producing actionable intelligence outputs. Capable of driving complex analyses independently and effectively communicating findings to diverse stakeholders.

Highest-signal resume keywords
Cyber Threat IntelligenceOSINT CollectionAI-Assisted WorkflowsIncident ResponseAnalytical Execution

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Exposure MappingThreat Actor ProfilingAttribution AssessmentInfrastructure MappingTriage AnalysisVulnerability AssessmentData ClusteringSignal AnalysisRFI ResponseAnalytical Judgment
Soft Skills
Excellent CommunicationJudgmentAdaptabilityCollaborationProblem-Solving
Tools & Technologies
NotionTRM Investigative ToolsAI ToolsThreat Intelligence Platforms
Industry Keywords
Critical-InfrastructureGovernment PartnersISACsCyber ActorsIncident Remediation

About the role

Key responsibilities & impact
  • Analyze critical-infrastructure sectors and identify organizations most important to protect
  • Surface vulnerabilities and exposures from initial signal through actionable defender notification
  • Combine OSINT, external attack-surface and exposure discovery, and direct threat-actor collection
  • Use AI to build tools and workflows that accelerate remediation at scale, with human quality control
  • Feed effective methods into TRM tooling and workflows
  • Map C2 infrastructure, malware families, TTPs, and threat actors
  • Triage large indicator and exposure sets and cluster infrastructure
  • Produce exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions
  • Advise across multiple active threats and support other analysts through analytical execution
  • Partner with critical-infrastructure entities, government partners, ISACs, engineers, and internal teams
  • Participate in weekly team syncs and daily async standups
  • Document output in Notion and TRM investigative tools
  • Flex hours during active disruption windows to meet urgent partner needs

Requirements

What you’ll need
  • 5+ years in cyber threat intelligence, incident response, or a closely related analytical field
  • Experience as the primary point of contact for an outside organization during a live incident or remediation
  • Ability to drive complex analysis independently to actionable outcomes
  • Experience delivering real answers under RFI-style time pressure
  • Applied AI fluency, including building AI-assisted or agentic workflows and validating outputs
  • Hands-on collection capability in OSINT, external attack-surface and exposure discovery, or direct threat-actor collection
  • Experience producing finished intelligence such as actor profiles, campaign reporting, attribution assessments, exposure notifications, or infrastructure mapping
  • Strong OSINT skills and ability to resolve identities, aliases, infrastructure, and behavior across fragmented sources
  • Excellent judgment regarding analytical confidence and evidentiary strength
  • Excellent written and verbal communication
  • Comfort working in a fast-paced, ambiguous environment
  • Willingness to travel up to 50% within the United States
  • Must be based in the United States
  • U.S. citizenship required
  • Familiarity with critical-infrastructure sectors, government partners, ISACs, or sector coordinating bodies is a plus
  • Working proficiency in a language heavily used by cyber actors is a plus
  • Public presence through conference talks, published research, or invite-only sharing circles is a plus

Benefits

Comp & perks
  • Equity plan eligibility
  • Distributed-first remote work
  • Async-first work via Slack and Notion
  • High autonomy and low bureaucracy
  • Global team collaboration
  • Flexible hours during active disruption windows
  • Competitive benefits, wellness programs, and time away from work, varying by country and local employment requirements