TRM Labs

TRM Labs

Staff Cyber Threat Intelligence Analyst

United States · Staff+

Sponsorship not specifiedDetected 25 days ago
Data ScienceA/B TestingCybersecurityResearchLeadershipCommunicationCollaborationProblem SolvingMentoringAdaptability

About the role

  • Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs.
  • Act as a staff-level analytical leader across multiple active actors and campaigns at once, raising quality, shaping standards, and coaching other analysts through exemplary tradecraft and judgment.
  • Triage large indicator sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings while improving the repeatability and rigor of how this work is done across the team.

Responsibilities

  • BUILD A SAFER WORLD.
  • TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks.
  • Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.
  • Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.
  • We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.
  • You will collaborate with blockchain intelligence experts, engineers, and data scientists to raise the quality, repeatability, and operational relevance of TRM's cyber threat intelligence capabilities.
  • Drive the highest-complexity investigations from seed indicators such as domains, IPs, hashes, aliases, or wallets through to attributed actors, clusters, or campaign pictures, and codify the methods others can reuse.
  • Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity to build a fuller understanding of adversary behavior.
  • We are building a safer world.
  • This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined.

Requirements

  • 8+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field.
  • Deep expertise in cyber investigations, infrastructure attribution, campaign analysis, and actor profiling, including the ability to set a high bar for analytical rigor in these areas.
  • Strong OSINT instincts and the ability to resolve identities, aliases, and behavior across fragmented sources.
  • Excellent judgment about analytical confidence, evidentiary strength, and what can or cannot be defended in a report, referral, or operational setting, including the ability to guide others on those standards.
  • Excellent written and verbal communication skills, with the ability to package findings for technical and non-technical audiences alike.
  • Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.
  • AI fluency is required.
  • Work that often requires operating with a high degree of ambiguity

Nice to have

  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment

Skills

  • All output documented in Notion and TRM's investigative tools
  • Surge availability expected during time-sensitive disruption windows

Company info

  • TRM's intelligence and investigations work combines national-security-grade tradecraft with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.
  • This role sits at the intersection of intelligence production, investigations, and product-informed tradecraft, helping ensure TRM's analytical capabilities remain operationally relevant, scalable, and high-quality across multiple use cases and stakeholders.
  • High autonomy, high standards, low bureaucracy - work directly with analysts, engineers, and customers who depend on your output
  • Weekly team syncs to align targeting priorities and review disruption opportunities
  • Daily async standups via Slack on active work, returns, and target packages in flight
  • Primary time zone overlap: US Eastern / Central
  • Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.
  • That promise shows up in how we work every day.

This listing is sourced directly from TRM Labs's careers page and normalized into a canonical job model.