Threat Intelligence Analyst — Scam Infrastructure

TRM Labs

Washington (District of Columbia)

On-site

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TRM Labs is seeking a Cyber Threat Intelligence Analyst in the Scam Disruption team to lead infrastructure-driven investigations, pivoting from a domain, IP, or certificate indicator to the network behind it, and delivering actionable intelligence to law enforcement partners.

You will fuse open-source, on-chain, and technical data to track scam campaigns and produce defensible assessments, guiding disruption operations with minimal supervision.

Qualifications

  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position).
  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs — and a habit of thinking in campaigns, not isolated indicators.
  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration.
  • Hands-on fluency with CTI tooling — passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring.
  • Experience building detection and clustering logic, rules, or automation yourself — not just configuring vendor tooling.
  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors.
  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, and calibrated, defensible analytic judgment.
  • Must be located in the Washington, D.C./MD/VA area (periodic in-person collaboration and travel may be required)

Responsibilities

  • Start from one indicator — a scam domain, IP, or certificate — and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns.
  • Track campaigns as they evolve — new domains, hosting and registrar changes, certificate reuse — and stay on actors as they rebuild and re-register after takedowns and seizures, anticipating their next infrastructure.
  • Drive attribution of threat actors by leveraging open-source and commercially available data.
  • Fuse technical infrastructure with the on-chain picture — carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out.
  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds.
  • Produce defensible, calibrated assessments — assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call.
  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on.
  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM's collection capabilities.

Skills

Cyber Threat Intel
Infrastructure Attribution
Campaign Tracking
CTI Tools
Open-Source Intel
Data-driven Analysis

Tools

Passive DNS
WHOIS
Certificate Fingerprinting
Shodan
On-Chain Data

Job description

TRM Labs is seeking a Cyber Threat Intelligence Analyst in the Scam Disruption team to lead infrastructure-driven investigations, pivoting from a domain, IP, or certificate indicator to the network behind it, and delivering actionable intelligence to law enforcement partners.

You will fuse open-source, on-chain, and technical data to track scam campaigns and produce defensible assessments, guiding disruption operations with minimal supervision.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence Analyst: Campaign-focused Investigator
Cyber Threat Intelligence Analyst: Campaign-focused Investigator

Apply • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Threat Intelligence Architect, Scams (Remote)
Threat Intelligence Architect, Scams (Remote)

Unchain Data • Washington, Northern (KY)

Hybrid
USD 95,000 - 140,000
Competitive compensation
Remote-friendly environment
Senior CTI Analyst: Campaigns & Infrastructure
Senior CTI Analyst: Campaigns & Infrastructure

TRM Labs • Washington

On-site
USD 140,000 - 180,000
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs • Washington

On-site
USD 140,000 - 180,000
Threat Intelligence Analyst Scams
Threat Intelligence Analyst Scams

Unchain Data • Washington, Northern (KY)

Hybrid
USD 95,000 - 140,000
Competitive compensation
Remote-friendly environment
AI-Driven Cyber Threat Intelligence Lead
AI-Driven Cyber Threat Intelligence Lead

TRM • United States

Hybrid
USD 150,000 - 230,000
All-Source Investigator: Disrupt Scam Networks
All-Source Investigator: Disrupt Scam Networks

TRM Labs • San Francisco (CA)

Hybrid
GBP 81,000 - 119,000
Equity
On-Chain Threat Hunter - Blockchain Intelligence
On-Chain Threat Hunter - Blockchain Intelligence

TRM Labs • United States

On-site
USD 120,000 - 160,000
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

Apply • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)
Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs • Washington

On-site
USD 150,000 - 210,000