Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs

Washington

On-site

USD 140,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

TRM Labs is seeking a Cyber Threat Intelligence Analyst to lead infrastructure-driven investigations in the Scam Disruption team. You will pivot from single indicators to multi-layer infrastructure, tracking campaigns and attributing threat actors with open-source and commercial data.

You will fuse on-chain and off-chain intelligence to build actionable targeting packages for law enforcement and government partners, owning the intelligence cycle end to end with minimal supervision.

Qualifications

  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles.
  • Hands-on infrastructure attribution across shared certificates, registrars, nameservers, hosting, and ASNs.
  • Experience tracking campaigns and maintaining focus on actor or campaign continuity.
  • Proficiency with CTI tooling such as passive DNS, WHOIS, fingerprinting, and phishing monitoring.
  • Experience building detection, clustering logic, rules, or automation.
  • Ability to produce actionable intelligence and targeted packages for government or law-enforcement.
  • Must be located in the Washington, D.C./MD/VA area.

Responsibilities

  • Own the intelligence cycle end to end with minimal supervision.
  • Pivot from indicators (domains, IPs, certificates) to the wider infrastructure network behind them.
  • Drive attribution of threat actors using open-source and commercial data.
  • Fuse infrastructure with on-chain data to map investigations from infrastructure to wallet and cash-out.
  • Develop clustering logic, detection rules, and automation to surface malicious infrastructure proactively.
  • Provide defensible, calibrated assessments with confidence and evidence-weighting.

Skills

Cyber threat intel
Infrastructure attribution
Campaign tracking
CTI tooling
Detection & clustering
Attribution tradecraft
Actionable intelligence

Tools

Passive DNS
WHOIS
Shodan fingerprinting
Phishing monitoring

Job description

Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Role

The Scam Disruption team is TRM’s tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst , you’ll lead infrastructure-driven investigative work: pivoting from a single domain, IP, or certificate to the network behind it, following it to the money, and delivering actionable intelligence to law enforcement and government partners.

You’ll track scam infrastructure as it evolves, fusing technical, open-source, and on-chain data to build the operational pictures that help dismantle scam operations.

The Impact You Will Have
  • Start from one indicator — a scam domain, IP, or certificate — and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns.

  • Track campaigns as they evolve — new domains, hosting and registrar changes, certificate reuse — and stay on actors as they rebuild and re-register after takedowns and seizures, anticipating their next infrastructure.

  • Drive attribution of threat actors by leveraging open-source and commercially available data.

  • Fuse technical infrastructure with the on-chain picture — carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out.

  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds.

  • Produce defensible, calibrated assessments — assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call.

  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on.

  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM’s collection capabilities.

What We’re Looking For
  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position).

  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs — and a habit of thinking in campaigns, not isolated indicators.

  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration.

  • Hands-on fluency with CTI tooling — passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring.

  • Experience building detection and clustering logic, rules, or automation yourself — not just configuring vendor tooling.

  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors.

  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, and calibrated, defensible analytic judgment.

  • Must be located in the Washington, D.C./MD/VA area (periodic in-person collaboration and travel may be required)

About the Team
  • The Scam Disruption team operates within TRM’s Blockchain Intelligence organization, alongside threat intelligence analysts, on-chain investigators, and federal partners

  • All-Source Investigators and Cyber Threat Intelligence Analysts are the operational core, converting strategy and tooling into prosecutable, actionable intelligence

  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment

  • High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output

Team Operating Rhythms
  • Weekly team syncs to align targeting priorities and review disruption opportunities

  • Daily async standups via Slack on active work, returns, and target packages in flight

  • Primary time zone overlap: US Eastern / Central

  • All output documented in Notion and TRM’s investigative tools

  • Surge availability expected during time-sensitive disruption windows

Join Our Mission

We seek people whose work matters, who build with speed and rigor, and who take pride in protecting others through their craft. If you’re excited by TRM’s mission but don’t check every box, apply anyway.

Build to protect civilization. Let’s do it together.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs • Washington

On-site
USD 150,000 - 210,000
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

Apply • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Threat Intelligence Analyst Scams
Threat Intelligence Analyst Scams

Unchain Data • Washington, Northern (KY)

Hybrid
USD 95,000 - 140,000
Competitive compensation
Remote-friendly environment
Threat Intelligence Analyst — Scam Infrastructure
Threat Intelligence Analyst — Scam Infrastructure

TRM Labs • Washington

On-site
USD 150,000 - 210,000
Threat Intelligence Architect, Scams (Remote)
Threat Intelligence Architect, Scams (Remote)

Unchain Data • Washington, Northern (KY)

Hybrid
USD 95,000 - 140,000
Competitive compensation
Remote-friendly environment
Cyber Threat Intelligence Analyst: Campaign-focused Investigator
Cyber Threat Intelligence Analyst: Campaign-focused Investigator

Apply • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Blockchain Intelligence Analyst
Blockchain Intelligence Analyst

Crypto Pro Network • Mission (KS)

Remote
USD 80,000 - 120,000
Senior Data Scientist, Blockchain Insights
Senior Data Scientist, Blockchain Insights

Crypto Pro Network • United States

On-site
USD 170,000 - 195,000
Senior Analytics Engineer
Senior Analytics Engineer

Crypto Pro Network • United States

Remote
USD 110,000 - 150,000
Opportunity to work on impactful projects
Collaborative and inclusive culture
Flexible working hours
All Source Investigator
All Source Investigator

TRM Labs • San Francisco (CA)

Hybrid
GBP 81,000 - 119,000
Equity