Skip to main content
TRM Labs
TRM Labs

Cyber Threat Intelligence Analyst

RemoteUnited States, United Kingdom only· UTC-6…UTC-5
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to US, GB only · UTC-6…UTC-5. Set where you work from to check your eligibility.

No BS summary

Cyber Threat Intelligence Analyst, 3+ years experience in cyber threat intelligence or related field. Must produce finished intelligence products and have strong OSINT skills. US-based candidates only.

Required skills

OSINTAI toolsSlackNotion

Required languages

English Excellent written and verbal communication

What you'll do

  • Conduct ad hoc investigations and time-sensitive blockchain analysis for partners.
  • Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs.
  • Analyze multiple active actors and campaigns while improving quality and sharing tradecraft.
  • Assist in complex investigations from seed indicators such as domains, IPs, hashes, aliases, or wallets through to attributed actors, clusters, or campaign pictures.
  • Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity.
  • Triage large indicator sets, cluster infrastructure, and turn fragmented signals into defensible findings.
  • Support incident responders, threat hunters, investigators, and partner-facing teams with intelligence products and briefings.
  • Evaluate new analytical tooling on real workflows and identify where it reduces analyst effort or improves output quality.
  • Contribute to stronger investigation workflows, analytic standards, and repeatable methods.

What they require

  • 3+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field.
  • Experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping.
  • Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling.
  • Strong OSINT instincts and ability to resolve identities, aliases, and behavior across fragmented sources.
  • Ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads.
  • Excellent judgment about analytical confidence, evidentiary strength, and defensibility in reports, referrals, or operational settings.
  • Track record of independently driving complex investigations, improving workflows, and elevating analytical quality.
  • Excellent written and verbal communication skills for technical and non-technical audiences.
  • Comfort operating in a fast-paced environment with changing priorities and ambiguity.
  • AI fluency is required, with AI tools used for research, synthesis, and workflow acceleration under strong human quality control.
  • Ability to collaborate across analysts, engineers, data scientists, and partner-facing teams.
  • Surge availability during time-sensitive disruption windows.

Benefits

  • Distributed team with async-first approach via Slack and Notion.
  • High autonomy, high standards, and low bureaucracy.
  • Work directly with analysts, engineers, and customers.
  • Structured weekly team syncs and daily async standups.
  • Mission-driven work at the intersection of AI, national security, and fighting crime.
  • Reasonable accommodations available for applicants with disabilities.

Blockchain intelligence platform for investigating, monitoring, and detecting crypto fraud and financial crime

🇺🇸 United StatesAIMid-sizetrmlabs.com/

Details

Apply routeDom
Salary not disclosed