TRM Labs builds AI-powered blockchain intelligence tools that help governments and financial institutions detect and disrupt crypto-related crime.
BUILD A SAFER WORLD. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure. Sector Engagement Leads own the relationships that drive our mission forward. You will be the primary point of contact for dozens of organizations in your sector, selected from the hundreds of critical-infrastructure entities we serve. Your mandate: earn their trust, ensure they are operational on our platform, and translate complex threat intelligence into immediate defensive actions. This is a builder's role. We are looking for leaders who can solve high-stakes problems and scale a critical function from a standing start. If you are energized by delivering real-world impact in under-resourced environments, this is your team. The impact you will have - Execute sector-wide engagement. Own the end-to-end adoption and defensive outcomes for your portfolio of SLTT and critical-infrastructure entities. - Accelerate operational capability. Partner with Solutions Engineering to move entities from provisioning to active operation on TRM's platform through agentic CTI/IR workflows. - Operationalize intelligence. Convert sector threat activity and entity findings into prioritized, plain-language guidance that small teams can act on immediately. - Strengthen the ecosystem. Build durable partnerships with fusion centers, sector ISACs (Health-ISAC, WaterISAC, MS-ISAC), CISA, and law enforcement to amplify collective defense. - Drive the feedback loop. Identify sector patterns for the Threat Intelligence team and advocate for the field's needs in product and program strategy. - Scale the model. Define engagement playbooks, success metrics, and onboarding standards as the program expands. - Advocate for your sector. Represent your community's interests to TRM leadership and external government stakeholders. What we're looking for - 8+ years of relevant experience. Proven track record in public sector security, critical-infrastructure defense, or customer-facing technical roles, specifically earning trust with resource-constrained stakeholders. - Sector authority. You have deep credibility in your focus area. You understand how these organizations operate and why generic security guidance fails. - CTI fluency. Ability to analyze threat intelligence, determine what is critical, and translate it into a tactical plan for an operational team. - Bias toward action. You anticipate roadblocks and drive outcomes independently. You frame work in short, aggressive timelines and iterate rapidly. - Strategic clarity. You resolve ambiguity for diverse audiences: entity operators, government partners, and internal teams. - Bias to action / TRM Speed. You frame work in short, real timelines, run fast learning loops, and move when the plan stops working. - Mission commitment. You are motivated by protecting essential services and exercising sound judgment in sensitive government contexts. - Location. This is a US-based remote role, with a preference for the Washington, DC metro area for proximity to government stakeholders. - Onsite meetings & events. Expect periodic in-person meetings with government and entity stakeholders, and to serve as TRM's on-the-ground presence at select cyber threat intelligence (CTI) and critical-infrastructure (CI) events and conferences. Travel is estimated at ~25–40%. - On-call & first response. You'll help build and share an on-call rotation with teammates, taking turns as first responder for your cohort when an entity is in an active incident. - Working hours. Maintain meaningful overlap with U.S. business hours for stakeholder collaboration, and be reachable during active incidents per the on-call schedule. Nice to have - Former practitioner in your sector (e.g., hospital, utility, county/city, or district security or operations leadership). - Active relationships with the relevant sector ISAC, fusion centers, CISA regional advisors, or relevant law enforcement. - Experience standing up or running a collective-defense, SLTT, or public-private security program. - Familiarity with ransomware tradecraft, incident response, and the value of cryptocurrency/payment tracing. - OT/ICS experience (especially for the Water & Critical Infrastructure focus). - Experience operating in fast-moving, ambiguous, standing-start environments. What success looks like - Your cohort is fully operational and actively using TRM capabilities to defend their environments. - Entities have taken documented defensive actions based on your guidance, resulting in incident avoidance or containment. - You are the first-call partner for your entities, sector ISACs, and fusion centers. - You have established the engagement playbook and success metrics that define the future of the program. - Every entity in your cohort is onboarded onto the platform and actively using the workflows, with ≥80% active month over month. - A measurable, quarter-over-quarter drop in your cohort's internet-exposed and known-exploited (KEV) vulnerabilities. - Median time from onboarding to an entity's first independent, unaided use of a workflow under 14 days. - Tailored, plain-language advisories delivered to your entities with documented action taken on the highest-severity items (delivered and acted on). - An active sector peer community where a lesson learned at one entity is adopted across the cohort. - Every entity reaches "measurable defensive use," contributing to the program's sector coverage goals. About the team This team is dedicated to cybercrime and SLTT-resilience. Our goal is to provide real defensive capability to the country's most under-resourced organizations: rural hospitals, wate