Senior All-Source Investigator, Severe Harms

Trm-Labs

San Francisco (CA)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TRM Labs is seeking a Severe Harms All-Source Investigator to join a remote-friendly team addressing complex cases involving sextortion and CSAM monetization. The role emphasizes tracing financial rails, building legal-process returns, and supporting disruption with on-chain/off-chain fusion.

You will work independently yet with guidance from a Lead Investigator, building genuine casework skills on challenging material while collaborating across legal, engineering, and external partners.

Qualifications

  • 3–5 years of investigative or casework experience across illicit-finance, financial-crime, cybercrime, trust & safety, all-source intelligence, OSINT, or direct human-source engagement.

Responsibilities

  • Run point on target packages from referral to disruption, including legal process and on/off-chain fusion.
  • Perform OSINT collection, link analysis, and engagement with subjects/sources to attribute actors.
  • Produce defensible, actionable outputs suitable for law enforcement or partners.
  • Map networks to show how a criminal network operates beyond isolated indicators.
  • Apply AI where it speeds up work whilemaintaining necessary human judgment.
  • Collaborate with engineers, legal counterparts, and external partners.
  • Follow TRM protocols for evidence handling, escalation, and reporting.
  • Manage content exposure and seek support as needed.

Skills

Investigative experience
AI fluency
OSINT
Human-source engagement
Written communication

Job description

Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Role

Sextortion — extorting money or further imagery from victims, disproportionately minors, under threat of releasing explicit images — has been named a national emergency by the FBI and NCMEC, and financial sextortion cases have been directly linked to a rise in teen suicides. In parallel, CSAM distribution networks increasingly monetize through cryptocurrency, using crypto's speed and pseudonymity to move money across borders faster than any single agency can follow.

TRM's Severe Harms pod exists to close that gap. We fuse on-chain and off-chain intelligence to trace the financial rails behind this abuse, working alongside Law Enforcement and Government Partners, and TRM's financial-institution and exchange partners to identify offenders, disrupt activity, and support victim identification and safeguarding. It is some of the most consequential and difficult work at TRM.

As a Severe Harms All-Source Investigator, you will be one of the investigators running that flywheel every day — tracing the financial rails behind sextortion and CSAM monetization, building the target packages and legal-process returns that lead to disruption, and working cases from referral through to an actionable outcome.

This is an individual-contributor role for someone who wants to do the work directly, not manage it. You will build genuine casework skill on some of the most consequential and difficult material at TRM, with a manager and a Lead Investigator supporting your growth.

The Impact You Will Have
  • Work your caseload. Run point on target packages from referral to disruption: legal process → on-chain/off-chain fusion → targeting, on your own cases under normal review.

  • Run all-source collection. Combine OSINT, link analysis, and direct engagement with subjects and sources to identify and attribute actors — not just trace the money.

  • Build defensible, actionable outputs. Every attribution write-up and legal-process return you produce should hold up when tested by Law Enforcement and Government Partners, or a court — with growing independence over time.

  • Map networks, not just events. Build a picture of how a network actually operates, rather than a catalogue of isolated indicators.

  • Use AI to accelerate your own casework. Apply it where it genuinely speeds up or sharpens your work, and know where human judgment has to stay in the loop given the sensitivity of the material.

  • Partner across the ecosystem. Work directly with legal, engineering, and external partners on the specific leads and referrals in front of you.

  • Practice victim-centered, trauma-informed investigative work, and follow TRM's protocols for evidence handling, escalation, and mandatory reporting.

  • Take care of yourself and your teammates. Actively manage your own content exposure and psychological well-being, and know when and how to ask for support.

What We're Looking For
  • You are an operator. 3–5 years of relevant investigative or casework experience — illicit-finance, financial-crime, cybercrime, trust & safety, all-source intelligence, OSINT, or direct human-source engagement, or a comparable law-enforcement/intelligence-adjacent background. You have taken a body of information and driven it to a real outcome, not just written a report about it.

  • Real collection capability, whether that's hands-on experience building or adapting tools to pull signal from open web, social, and forum sources, or direct experience engaging subjects and sources yourself. Ideally you've done some of both, but real strength in one is enough.

  • You know how to work a case with other people, not just alone. You can point to investigations you've co-run with another investigator, or handed off cleanly without losing momentum.

  • You're comfortable working to someone else's clock. You've delivered real answers under RFI-style pressure — a partner or requester needing something in hours or days, not on a self-paced research timeline — and can point to examples.

  • Genuine interest in, and some exposure to, child exploitation, sextortion, or closely adjacent investigative work, including CT or Serious Organised Crime. We will teach you the ecosystem specifics; we are looking for the instinct and resilience for this material, plus at least some track record adjacent to it.

  • AI fluency (required). You use AI in your own work today and have a clear, honest view of where it helps and where it does not — especially given the sensitivity of this material.

  • Working knowledge of legal process — subpoenas, warrants, preservation requests — or a fast willingness to learn it. You do not need to be a lawyer; you need to understand how high-quality investigative documentation supports downstream action.

  • Solid written communication. You can produce a clear, defensible written package under review.

  • Sound judgment with difficult material. The maturity to work with emotionally demanding content without it compromising your judgment or your well-being.

  • Fully remote, US- or UK-based. Expect occasional travel, unevenly distributed, with periodic DC-based working sessions.

Nice-to-Have
  • Crypto or on-chain experience. A genuine advantage, but we teach on-chain tradecraft — we cannot teach the instinct built from years investigating crimes against children.

  • Sextortion/CSAM-ecosystem familiarity. Direct experience with financial sextortion schemes, CSAM distribution networks, or platform-based grooming and extortion patterns will shorten your ramp considerably, but the team knows this ecosystem well and can bring you up to speed on it.

Vetting

Given the sensitivity of the material and data handled, successful completion of an enhanced background check is required as a condition of employment.

About the Team
  • The Severe Harms pod operates within TRM's Primary Intelligence organization, alongside the other threat categories comprised of threat intelligence analysts, on-chain investigators and data scientists.

  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment.

  • High autonomy, high standards, low bureaucracy — you work directly with engineers, analysts, legal counterparts, and the partners and customers who depend on the team's output.

Team Operating Rhythms
  • Weekly 1:1 with your manager

  • Weekly team sync covering active work, throughput, and escalations

  • 6-week performance pulse check-in

  • Quarterly career-pathing conversation

  • Mandatory wellness check-ins and access to specialized counseling/EAP resources, on a standing cadence

  • Primary time-zone overlap: US Eastern / Central

  • Surge availability expected during time-sensitive referral and disruption windows

What to Expect From Our Interview Process

Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.

  • Recruiter Intro: Explore your experience, motivations, and alignment with the role.

  • Hiring Manager: Dive deeper into your relevant experience, skills, and impact.

  • First Round: Typically 1–2 interviews focused on the skills most critical to the role.

  • Final Round: Typically 3–5 interviews to go deeper on your craft, problem-solving, and alignment with TRM.

  • References: We'll speak with former colleagues who can provide perspective on your work and impact.

  • Offer: If it's a mutual fit, your recruiter will walk you through your offer and answer your questions.

  • Welcome to TRM: Once you sign, we'll get you ready for your first day and onboarding.

Your recruiter will share your specific interview plan and preparation guidance along the way.

Learn more about interviewing at TRM

Life at TRM

We are building a safer world. That promise shows up in how we work every day.

TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

At TRM, you should expect:

  • Priorities and targets to change quickly as we experiment and iterate

  • Work that often requires operating with a high degree of ambiguity

  • A high level of personal ownership and accountability

  • Close collaboration across teams and functions

  • Frequent, high-touch communication

  • Creative problem solving and out-of-the-box thinking

  • A pace that rewards urgency, adaptability, and outcomes

This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.

We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.

At the same time, many people find this work deeply rewarding. If you're excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like

AI Fluency at TRM

AI fluency is a baseline expectation at TRM.

We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.

At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:

  • Accelerate repeatable workflows

  • Structure and solve problems

  • Improve output quality

  • Increase speed and leverage

You will be evaluated on applied AI fluency during the interview process.

Leadership Principles

We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.

  • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

  • Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday.

  • Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset — giving and receiving feedback to make the team stronger.

Join our Mission

At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you're excited by TRM’s mission but don't check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.

TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.

Privacy Policy and Additional Information

By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy.

We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.

Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, and request deletion of your personal data at any time before that period end. To exercise any of these rights, contact us at privacy@trmlabs.com.

To notify TRM Labs that you believe this job posting is non-compliant, you can submit a report through our form. No response will be provided to inquiries unrelated to job posting compliance.

The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via our form.

Learn More

Company Values | Interviewing | FAQs

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Cyber Threat Intelligence Analyst
Staff Cyber Threat Intelligence Analyst

TRM • United States

Hybrid
USD 150,000 - 230,000
Global Investigator
Global Investigator

TRM Labs • United States

On-site
USD 80,000 - 100,000
High autonomy
Work with a mission-driven team
Continuous feedback environment
Insights Editor TRM Labs Workplace 14 hours ago
Insights Editor TRM Labs Workplace 14 hours ago

Content Creators • Northern (KY)

Hybrid
USD 90,000 - 140,000
Insights Editor
Insights Editor

TRM Labs • United States

On-site
USD 140,000 - 190,000
Senior Software Engineer, Full Stack | Product Engineering - SF Only
Senior Software Engineer, Full Stack | Product Engineering - SF Only

TRM Labs • San Francisco (CA)

On-site
USD 180,000 - 210,000
Equity plan
Senior Software Engineer, Graph Analytics
Senior Software Engineer, Graph Analytics

TRM Labs • United States

Hybrid
USD 200,000 - 220,000
Equity plan
Senior Software Engineer, Data Product - SF Only
Senior Software Engineer, Data Product - SF Only

TRM Labs • San Francisco (CA)

On-site
USD 190,000 - 220,000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

TRM Labs • United States

On-site
USD 210,000 - 230,000
Equity plan
Global Investigator - National Security
Global Investigator - National Security

TRM Labs • United States

On-site
USD 171,000 - 187,000
Equity plan
Senior Software Engineer, Frontend | Product Engineering
Senior Software Engineer, Frontend | Product Engineering

TRM Labs • United States

On-site
USD 210,000 - 230,000