Cyber Threat Intelligence Analyst Scams

Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.

Maintainer signals as of 9/25/2026

450 Townsend Street, San Francisco, CA 94107, United States
About TRM Labs

TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.

View jobs by TRM Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will investigate scam infrastructure by pivoting from domains, IPs, and certificates to connected networks and financial activity. You will track campaigns, attribute threat actors, develop detection and clustering logic, and synthesize technical, open-source, on-chain, and financial intelligence into actionable targeting packages.

Requirements

  • 5+ years of cyber threat intelligence or threat infrastructure analysis experience
  • Infrastructure attribution and campaign-tracking experience
  • Experience tracking actors or campaigns through takedowns and re-registration
  • Fluency with passive DNS, WHOIS, certificate fingerprinting, Shodan-style fingerprinting, and phishing monitoring
  • Experience building detection, clustering, rules, or automation
  • Attribution tradecraft using open-source and commercial data
  • Experience producing actionable intelligence for government, law-enforcement, or equivalent consumers
  • Must be located in the Washington, D.C., Maryland, or Virginia area

Responsibilities

  • Map scam infrastructure from domains, IPs, certificates, registrars, nameservers, hosting, and ASNs
  • Track campaigns through infrastructure changes, takedowns, and re-registration
  • Attribute threat actors using open-source and commercial data
  • Trace investigations from technical infrastructure to wallets, laundering paths, and cash-out
  • Build clustering logic, detection rules, automation, and tooling
  • Produce calibrated and defensible intelligence assessments
  • Create actionable intelligence and targeting packages for government and law-enforcement consumers
  • Own the intelligence cycle and partner with subject-matter experts, data, engineering, and product

Benefits

  • Equity plan eligibility

Hiring Process

Recruiter intro → hiring manager interview → first round of 1–2 interviews → final panel round → references → offer → onboarding.

Cyber Threat Intelligence Analyst Scams at TRM Labs | JobStash