Lead, Threat Intelligence
About Polymarket
Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future.
We're growing fast, both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire.
About the Role
Global Intelligence and Investigations exists to protect the integrity of Polymarket's markets and platform. This team sits within Legal and operates at the intersection of analysis, engineering, and real-world consequence. Threat Intelligence is the external-facing arm of that work, responsible for understanding who is targeting Polymarket and the broader crypto and prediction-market ecosystem, and making sure that intelligence actually changes how we defend ourselves.
This is not a monitoring role. You will track real threat actors, build the pipelines that turn raw data into actionable intelligence, and work directly with Product and Security to get protections shipped. The crypto context matters here. Transactions are irreversible, adversaries are often sophisticated, and the gap between detecting a threat and acting on it has real financial consequences for real users. The work has weight.
We're hiring one person to own this end to end. That means you need to be strong on both sides: the intelligence tradecraft and the engineering. If you can track an actor but need someone else to build the detection, or you can build pipelines but can't produce a written assessment a lawyer can act on, this is not the right fit. If you can do both, we want to talk.
What You'll Do
-
Monitor external threat actors targeting crypto and prediction-market platforms, tracking campaigns, tactics, and infrastructure across open and closed sources.
-
Build and maintain Python pipelines that ingest, normalize, and enrich threat data from internal systems, external feeds, and intelligence partnerships.
-
Conduct on-chain analysis to identify suspicious activity and build monitoring systems that surface what matters before it becomes a problem.
-
Write threat assessments that legal, compliance, and non-technical stakeholders can read, understand, and act on without losing the nuance that makes them useful.
-
Turn intelligence findings into working detections and automated defenses, coordinating with Product and Security to get them deployed.
-
Manage relationships with external intelligence providers and integrate the data they supply into internal systems and workflows.
-
Identify gaps in coverage before they are exploited, and take ownership of closing them without waiting to be asked.
What We're Looking For
-
Demonstrated threat intelligence experience tracking real external actors, running collection and analysis, and producing intelligence that directly changed how a team defended itself or took action.
-
Hands-on engineering skills in Python, SQL, and data pipelines. You build detections and automation yourself. You do not spec them out for someone else to build.
-
On-chain analysis experience in crypto contexts, including familiarity with how adversaries use blockchain infrastructure and how to follow activity across chains.
-
Clear understanding of why crypto threats are different, irreversibility, pseudonymity, cross-border actors, and how that shapes both the threat landscape and the stakes.
-
Ability to distill complex, sensitive information into written assessments that legal and compliance teams can use to make real decisions.
-
Strong independent judgment. You can identify what matters, prioritize without being told, and build without a detailed brief.
-
(Plus) Experience tracking sophisticated or state-linked threat actors.
-
(Plus) Experience building threat intelligence platforms, feed automation, or enrichment pipelines at scale.
-
(Plus) Hands-on experience with blockchain analytics tooling such as Chainalysis, TRM Labs, or Elliptic.
-
(Plus) Brand protection or anti-abuse work at scale.
-
(Plus) Prior experience at a crypto-native or prediction-market platform.
Benefits
-
Competitive salary & equity
-
Unlimited PTO
-
Full Health, Vision, & Dental coverage
-
401k match
-
Hardware setup: new MacBook Pro, big display, & accessories
View all remote jobs at Polymarket →
FAQ
- Is the Lead, Threat Intelligence position at Polymarket remote?
- Yes. This role was posted on Remote Backend Jobs, a job board that lists exclusively fully remote positions.
- When was this Lead, Threat Intelligence job posted?
- This listing was posted on August 27, 2026 and is still open for applications.
- How do I apply for the Lead, Threat Intelligence position at Polymarket?
- Use the apply button on this page — it takes you directly to the employer’s application page.
More remote blockchain jobs
Java Backend Engineer (Chatbot)
BinanceRemote
Backend Engineer (Contract - LATAM)
NexusRemote
Senior DevOps Engineer
Lemon.ioLATAM, Europe, USA, Canada, APAC
Senior Data Engineer
Trust WalletRemote
Senior Graphic Designer
Lemon.ioAmericas, Europe, Asia, Africa, Oceania