Staff Cyber Threat Intelligence Analyst
United States
Thailand
Japan
Philippines
Singapore
Ireland
United Kingdom
South KoreaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
TRM Labs builds the AI Investigations platform trusted by law enforcement and financial institutions to investigate and disrupt financial crime at scale. As a Staff Cyber Threat Intelligence Analyst, you will drive the highest-complexity investigations on TRM's investigations platform, and you'll codify the methods, workflows, and analytical standards the rest of the team reuses. This is a role for CTI leaders with a track record of strengthening organizations and delivering significant impact for customers.
The impact you will have:
- Run high-complexity investigations end-to-end, from a single seed indicator — a domain, IP, hash, alias, or wallet — through to an attributed actor, cluster, or campaign picture.
- Identify new CTI collection opportunities and rapidly leverage the intelligence to get ahead of cyber threats
- Build the network picture around cyber threat actors: C2 infrastructure, malware families, TTPs, and the people operating them.
- Fuse technical indicators with OSINT and identity work, and follow findings into financial rails where the investigation goes there.
- Set the analytical standard: raise the bar on rigor and confidence judgments across the team, and coach other analysts through exemplary tradecraft rather than process.
- Partner directly with engineering and data science to turn investigative tradecraft into scalable capability — tooling and workflows the whole team benefits from, not one-off analysis.
- Support incident responders, threat hunters, investigators, leadership, and external partners with timely, high-confidence intelligence products and briefings, especially where judgment, prioritization, and ambiguity are unusually high.
What we're looking for:
- 8+ years in cyber threat intelligence, intelligence analysis, incident-driven investigations, or closely related analytical work.
- If you're at the 5-7 year mark and this reads like a stretch, please apply to the Senior posting instead. Same team, same work, different scope.
- AI fluency is required — you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce.
- A track record of raising the quality of work beyond your own cases — shaping standards, improving workflows, and helping other analysts do better work.
- Direct experience partnering with engineering, data science, or product to make an investigative method repeatable at scale. This one is not optional at Staff.
- Strong ability to combine direct collection and OSINT to deliver unique intelligence — resolving identities, aliases, and behavior across fragmented sources.
- Experience producing finished intelligence, such as actor profiles, campaign reporting, attribution assessments, infrastructure mapping. Detection rules and threat feeds are a different discipline.
- Judgment strong enough to guide others on evidentiary standards, not just apply them yourself.
- Excellent written and verbal communication — you can package a finding for a technical analyst and for a non-technical partner.
- Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.
Preferred Qualifications
- Working proficiency in Russian, Chinese, or another language heavily used by cyber actors — particularly if you've used it operationally, in forums or persona work, rather than academically.
- A public presence: conference talks, published research, invite-only sharing circles.
- Hands-on crypto or blockchain tracing, and the ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation.
About the Team:
- TRM's Intelligence Team combines expert tradecraft and boundary-pushing innovation with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.
- Distributed and async-first via Slack and Notion, with structured syncs for alignment.
- High autonomy, high standards, low bureaucracy — you work directly with analysts, engineers, and partners who depend on your output.
Team Operating Rhythms:
- Weekly team syncs to align targeting priorities and review disruption opportunities
- Daily async standups via Slack on active work, returns, and target packages in flight
- Primary time zone overlap: US Eastern / Central
- All output documented in Notion and TRM’s investigative tools
- Surge availability expected during time-sensitive disruption windows
Learn about TRM Speed in this position:
- Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.
- Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.
- Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at TRM Labs
Explore Top Companies in this Space
Paxos
Blockchain / Fintech / Financial Services / Enterprise Software
CertiK
Blockchain / Cybersecurity / Web3
Polymarket
Blockchain / FinTech / Prediction Markets
Sigma Prime
Cybersecurity / Blockchain / Software Engineering
TRM Labs
View Company ProfileTRM Labs is a premier, enterprise-grade blockchain intelligence platform engineered to orchestrate massive-scale risk management and financial crime prevention across the global crypto ecosystem. Operating as a high-velocity digital risk ecosystem, the company eliminates the operational friction of complex on-chain monitoring by seamlessly unifying cross-chain transaction data with advanced behavioral forensics. Moving beyond the limitations of legacy compliance tools, TRM Labs provides an all-in-one suite for automated anti-money laundering (AML), entity-level risk screening, and deep-dive forensic investigations. Under the hood, their highly scalable proprietary architecture utilizes machine learning to map thousands of complex blockchain entities in real-time, instantly surfacing high-risk exposures and illicit activities across over 100 distinct chains. What sets TRM Labs apart is its uncompromising dedication to frictionless compliance and investigative speed; by bridging the gap between vast blockchain datasets and actionable regulatory insights, the platform empowers financial institutions, government agencies, and crypto businesses to dramatically accelerate their security postures and maintain absolute regulatory integrity.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.