← All jobs
TL

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM LabsWashington DC
Type
Full-time
Work setup
Remote
Experience
Mid
Posted
Today
🌍 Fully remote

What security roles in crypto pay

64 salaries · our own data
median $202k$145k$268k

Most security roles in crypto pay between $145k and $268k, with a median of $202k.

As a Cyber Threat Intelligence Analyst on TRM Labs' Scam Disruption team, you lead infrastructure-driven investigative work against pig butchering syndicates, romance fraud networks, and investment scam operations. You pivot from a single domain, IP, or certificate to map the network behind it, follow the money, and deliver actionable intelligence to law enforcement and government partners. You track scam infrastructure as it evolves, fusing technical, open-source, and on-chain data to build the operational pictures that dismantle scam operations.

What you'll do

  • Start from one indicator, such as a scam domain, IP, or certificate, and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns
  • Track campaigns as they evolve through new domains, hosting and registrar changes, and certificate reuse, and stay on actors as they rebuild and re-register after takedowns and seizures
  • Drive attribution of threat actors by leveraging open-source and commercially available data
  • Fuse technical infrastructure with the on-chain picture, carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out
  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds
  • Produce defensible, calibrated assessments by assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call
  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on
  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams subject-matter expert team and with data, engineering, and product to sharpen TRM's collection capabilities

What you bring

  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles
  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs, and a habit of thinking in campaigns, not isolated indicators
  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration
  • Hands-on fluency with CTI tooling, including passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring
  • Experience building detection and clustering logic, rules, or automation yourself, not just configuring vendor tooling
  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors
  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, with calibrated, defensible analytic judgment
  • Must be located in the Washington, D.C., MD, or VA area (periodic in-person collaboration and travel may be required)

What we offer

  • Work on meaningful problems at the intersection of AI, national security, and fighting crime
  • High autonomy and ownership with minimal bureaucracy
  • Distributed team with async-first approach via Slack and Notion, plus structured syncs for alignment
  • Primary time zone overlap: US Eastern and Central
  • Weekly team syncs to align targeting priorities and review disruption opportunities

About TRM Labs

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. A Series C company with $220M in total funding backed by Goldman Sachs, Bessemer, Y Combinator, and Thoma Bravo, TRM is headquartered in San Francisco and operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only) | CryptoJobsHQ