Staff Cyber Threat Intelligence Analyst
Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.
Funding history
Investors
About TRM Labs
TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.
Skills
About the Role
Conduct high-complexity investigations, support time-sensitive blockchain analysis, shape investigative methods and workflows, produce finished cyber threat intelligence, and partner with intelligence, engineering, and data science teams to build scalable analytical capabilities.
Requirements
- 8+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related field.
- Experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping.
- Deep expertise in cyber investigations, infrastructure attribution, campaign analysis, and actor profiling.
- Strong OSINT instincts and ability to resolve identities, aliases, and behavior across fragmented sources.
- Ability to connect technical findings to wallets, laundering paths, sanctions exposure, or identity-linked leads.
- Excellent judgment regarding analytical confidence, evidentiary strength, and defensibility of findings.
- Experience leading complex investigations, improving workflows, and shaping analytical standards.
- Excellent written and verbal communication skills.
- Comfort working in a fast-paced, ambiguous environment with changing priorities.
- Required AI fluency and meaningful use of AI tools with strong human quality control.
Responsibilities
- Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready outputs.
- Lead complex investigations from domains, IPs, hashes, aliases, or wallets to attributed actors, clusters, or campaign assessments.
- Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity.
- Triage large indicator sets, cluster infrastructure, and turn fragmented signals into defensible findings.
- Support incident responders, threat hunters, leadership, and external partners with timely intelligence products and briefings.
- Evaluate and operationalize analytical tooling to improve analyst effort, quality, and reusable investigative leverage.
- Improve investigation workflows, analytical standards, and repeatable methods across the team.
- Partner with intelligence, engineering, and data science to translate investigative tradecraft into scalable capabilities.
