Senior Threat Intelligence Analyst, Hacks

TRM Labs
•$140,000 - $168,000•Remote

About The Position

As a Senior Threat Intelligence Analyst, you will lead TRM's hacks category, focusing on the metrics, the system that hits them, and the contractor team that supports this function around the clock. The role involves taking command during major hack incidents, leading the response, triaging, coordinating across teams, managing internal and customer communications, and producing incident reports. A key responsibility is ensuring major hacks are visible to customers within hours of public reporting, maintaining the completeness and accuracy of hack data (entity, theft addresses, date, amount, hack type), and designing systems with Data Science and engineering teams to attribute stolen funds as they move. The role also involves leveraging AI to automate analysis and response, while maintaining human quality control, and publishing technical analyses of significant hacks. Additionally, the analyst will develop approaches to proactively identify vulnerable contracts before exploitation.

Requirements

  • 5+ years of professional experience in blockchain intelligence, crypto investigations, cyber threat intelligence, incident response, or a closely related field.
  • Has owned incident response in a high-stakes environment (exchange, security firm, incident response, or CTI team): war rooms, incident reports, communications under pressure.
  • Strong blockchain tracing across major chains (BTC, EVM, TRON, Solana), including bridges, cross-chain swaps, and mixers.
  • Understands how DeFi, bridge, and exchange exploits work, and how attackers behave after the theft.
  • Applied AI fluency. We expect you to already be building AI-assisted or agentic workflows in your daily analytical work, to be able to show how you validate their outputs and where they fail, and to treat AI as a force multiplier.
  • Experience managing contractors or leading a small team.
  • Writes and briefs clearly, from technical deep-dives to executive summaries.
  • Hands-on and highly accountable: does the hardest work, not only coordinates it.

Nice To Haves

  • Smart-contract reverse-engineering (Solidity).
  • Experience at a security auditor or blockchain analytics firm.
  • Experience following specific well-known hacker groups.

Responsibilities

  • Take command when a big hack breaks and act as a leader.
  • Run the response: triage, coordination across teams, internal and customer communications, and the incident report afterwards.
  • Get every major hack into TRM fast. Make sure every major hack is visible to customers within hours of the first credible public report, around the clock.
  • Keep TRM's hack data complete and accurate. Every hack, at any size, is recorded with its entity, theft addresses, date, amount, and hack type.
  • Follow the money at scale. Design the system, with our Data Science and engineering teams, that carries hack-specific attribution downstream as stolen funds move.
  • Build the machine with AI. Leverage AI to build the tools and agents to automate key parts of hacks analysis and response, while ensuring human quality control over every output.
  • Explain how it happened. Root-cause the most important hacks and publish best-in-industry technical analysis that makes TRM the first source cited.
  • See the next one coming. Build approaches that spot vulnerable contracts before they are exploited, and get them into our product.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service