TRM Labs

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cyber threat intelligence or threat infrastructure analysis roles
  • Experience with infrastructure attribution and campaign tracking
  • Track record of following actors or campaigns over time
  • Fluency with CTI tooling and methodologies
  • Experience building detection and clustering logic from scratch
  • Ability to produce actionable intelligence for government or law enforcement
  • Located in Washington, D.C./MD/VA area for in-person collaboration

Responsibilities

  • Lead investigative work pivoting from domains, IPs, or certificates
  • Track evolving scam campaigns and anticipate infrastructure changes
  • Drive attribution of threat actors using various data sources
  • Fuse technical infrastructure with on-chain data for investigations
  • Develop automation and detection tools for proactive threat monitoring
  • Produce defensible assessments to classify malicious activity
  • Synthesize intelligence into actionable targeting packages for law enforcement

Benefits

  • High autonomy with minimal bureaucracy
  • Collaborative environment with federal partners
  • Access to cutting-edge tools and technology
  • Flexibility with a distributed team
  • Opportunities for personal and professional growth
  • Mission-driven culture with a focus on protecting individuals from scams
Full Job Description
About the Role

The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst, you'll lead infrastructure-driven investigative work: pivoting from a single domain, IP, or certificate to the network behind it, following it to the money, and delivering actionable intelligence to law enforcement and government partners.

You'll track scam infrastructure as it evolves, fusing technical, open-source, and on-chain data to build the operational pictures that help dismantle scam operations.

The Impact You Will Have
  • Start from one indicator - a scam domain, IP, or certificate - and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns.
  • Track campaigns as they evolve - new domains, hosting and registrar changes, certificate reuse - and stay on actors as they rebuild and re-register after takedowns and seizures, anticipating their next infrastructure.
  • Drive attribution of threat actors by leveraging open-source and commercially available data.
  • Fuse technical infrastructure with the on-chain picture - carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out.
  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds.
  • Produce defensible, calibrated assessments - assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call.
  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on.
  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM's collection capabilities.


What We're Looking For
  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position).
  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs - and a habit of thinking in campaigns, not isolated indicators.
  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration.
  • Hands-on fluency with CTI tooling - passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring.
  • Experience building detection and clustering logic, rules, or automation yourself - not just configuring vendor tooling.
  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors.
  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, and calibrated, defensible analytic judgment.
  • Must be located in the Washington, D.C./MD/VA area (periodic in-person collaboration and travel may be required)


About the Team
  • The Scam Disruption team operates within TRM's Blockchain Intelligence organization, alongside threat intelligence analysts, on-chain investigators, and federal partners
  • All-Source Investigators and Cyber Threat Intelligence Analysts are the operational core, converting strategy and tooling into prosecutable, actionable intelligence
  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment
  • High autonomy, high standards, low bureaucracy - work directly with analysts, engineers, and customers who depend on your output


Team Operating Rhythms
  • Weekly team syncs to align targeting priorities and review disruption opportunities
  • Daily async standups via Slack on active work, returns, and target packages in flight
  • Primary time zone overlap: US Eastern / Central
  • All output documented in Notion and TRM's investigative tools
  • Surge availability expected during time-sensitive disruption windows


Join Our Mission

We seek people whose work matters, who build with speed and rigor, and who take pride in protecting others through their craft. If you're excited by TRM's mission but don't check every box, apply anyway.

Build to protect civilization. Let's do it together.
Application Instructions

If you're interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.

Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.

If you send your resume directly to someone at TRM, we can't guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you're considered.

What to Expect From Our Interview Process

Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.
  • Recruiter Intro: Explore your experience, motivations, and alignment with the role.
  • Hiring Manager: Dive deeper into your relevant experience, skills, and impact.
  • First Round: Typically 1-2 interviews focused on the skills most critical to the role.
  • Final Round: Typically 3-5 interviews to go deeper on your craft, problem-solving, and alignment with TRM.
  • References: We'll speak with former colleagues who can provide perspective on your work and impact.
  • Offer: If it's a mutual fit, your recruiter will walk you through your offer and answer your questions.
  • Welcome to TRM: Once you sign, we'll get you ready for your first day and onboarding.

Your recruiter will share your specific interview plan and preparation guidance along the way.

Learn more about interviewing at TRM

AI Fluency at TRM

AI fluency is a baseline expectation at TRM.

We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.

At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:
  • Accelerate repeatable workflows
  • Structure and solve problems
  • Improve output quality
  • Increase speed and leverage

You will be evaluated on applied AI fluency during the interview process.

Leadership Principles

We hire and grow against three leadership principles. They're the standards for how we operate, treat each other, and make decisions.
  • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment - test, ship, measure, and iterate quickly.
  • Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday.
  • Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset - giving and receiving feedback to make the team stronger.

Join our Mission

At TRM, we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you're excited by TRM's mission but don't check every box, we encourage you to apply - we hire for slope, judgment, and the will to learn fast.

TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Learn more about building tools for defenders.

Learn More: Company Values | Interviewing | FAQs

About TRM Labs

Industry
Founded
2017

Similar Jobs

More Jobs at TRM Labs

More Information Technology Jobs

Find similar Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only) jobs: