Cyber Threat Intelligence Analyst Scams

Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.

Maintainer signals as of 9/25/2026

450 Townsend Street, San Francisco, CA 94107, United States
About TRM Labs

TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.

View jobs by TRM Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will investigate scam infrastructure from domains, IPs, and certificates through to wallets, laundering paths, and cash-out. You will track campaigns, attribute threat actors, build detection and clustering logic, produce defensible assessments, and create actionable targeting packages for government and law-enforcement consumers.

Requirements

  • 5+ years of experience in cyber threat intelligence or threat infrastructure analysis
  • Experience with infrastructure pivoting and campaign tracking across certificates, registrars, nameservers, hosting, and ASNs
  • Experience tracking actors or campaigns through takedowns and re-registration
  • Fluency with passive DNS, WHOIS, certificate fingerprinting, Shodan-style fingerprinting, and phishing monitoring
  • Experience building detection logic, clustering rules, or automation
  • Experience attributing threat actors using open-source and commercial data
  • Ability to produce actionable intelligence for government or law-enforcement consumers
  • Must be located in the Washington, D.C./Maryland/Virginia area

Responsibilities

  • Map scam infrastructure by pivoting across certificates, registrars, nameservers, hosting, and ASNs
  • Track scam campaigns through infrastructure changes, takedowns, and re-registration
  • Attribute threat actors using open-source and commercial data
  • Connect technical infrastructure intelligence to on-chain wallet, laundering, and cash-out activity
  • Build detection logic, clustering rules, automation, and tooling
  • Produce calibrated and defensible intelligence assessments
  • Create actionable targeting packages from on-chain and off-chain intelligence
  • Own investigations end to end and partner with subject-matter experts, data, engineering, and product

Benefits

  • Equity

Hiring Process

Recruiter intro; hiring manager interview; first round of 1–2 skill-focused interviews; final round of 3–5 interviews; references; offer; onboarding.