Cyber Threat Intelligence Analyst Scams
Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.
Maintainer signals as of 9/25/2026
Funding history
Investors
About TRM Labs
TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will investigate scam infrastructure from domains, IPs, and certificates through to wallets, laundering paths, and cash-out. You will track campaigns, attribute threat actors, build detection and clustering logic, produce defensible assessments, and create actionable targeting packages for government and law-enforcement consumers.
Requirements
- 5+ years of experience in cyber threat intelligence or threat infrastructure analysis
- Experience with infrastructure pivoting and campaign tracking across certificates, registrars, nameservers, hosting, and ASNs
- Experience tracking actors or campaigns through takedowns and re-registration
- Fluency with passive DNS, WHOIS, certificate fingerprinting, Shodan-style fingerprinting, and phishing monitoring
- Experience building detection logic, clustering rules, or automation
- Experience attributing threat actors using open-source and commercial data
- Ability to produce actionable intelligence for government or law-enforcement consumers
- Must be located in the Washington, D.C./Maryland/Virginia area
Responsibilities
- Map scam infrastructure by pivoting across certificates, registrars, nameservers, hosting, and ASNs
- Track scam campaigns through infrastructure changes, takedowns, and re-registration
- Attribute threat actors using open-source and commercial data
- Connect technical infrastructure intelligence to on-chain wallet, laundering, and cash-out activity
- Build detection logic, clustering rules, automation, and tooling
- Produce calibrated and defensible intelligence assessments
- Create actionable targeting packages from on-chain and off-chain intelligence
- Own investigations end to end and partner with subject-matter experts, data, engineering, and product
Benefits
- Equity
Hiring Process
Recruiter intro; hiring manager interview; first round of 1–2 skill-focused interviews; final round of 3–5 interviews; references; offer; onboarding.
