Skip to main content
TRM Labs
TRM Labs

Lead Cyber Threat Intelligence Analyst

RemoteUnited States, United Kingdom only· UTC-6…UTC-5
Published
Role
Security
Experience
Lead
Company size
Startup
Salary not disclosed
Check eligibility

Open to US, GB only · UTC-6…UTC-5. Set where you work from to check your eligibility.

No BS summary

Lead cyber threat intelligence analyst with 8+ years in CTI/intelligence analysis/investigations and 1+ year people lead or manager experience. Must be US-based with Eastern/Central overlap and strong blockchain/financial-rail investigation, OSINT, infrastructure attribution, and applied agentic AI workflow skills.

Core skills

OSINTAgentic AI workflowsCyber Threat Intelligence

What you'll do

  • Produce finished cyber threat intelligence including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs.
  • Act as senior analytical lead across multiple active actors and campaigns, prioritize work, improve quality, and coach analysts.
  • Lead complex investigations from seed indicators such as domains, IPs, hashes, aliases, or wallets to attributed actors, clusters, or campaign pictures.
  • Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity.
  • Triage large indicator sets, cluster infrastructure, and turn fragmented signals into defensible findings.
  • Support incident responders, threat hunters, investigators, leadership, and external partners with intelligence products and briefings.
  • Evaluate and operationalize new analytical tooling on real workflows.
  • Improve investigation workflows, analytic standards, and repeatable methods.

What they require

  • 8+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field.
  • At least 1+ years of experience in a people lead or manager role.
  • Demonstrated experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping.
  • Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling.
  • Strong OSINT instincts and ability to resolve identities, aliases, and behavior across fragmented sources.
  • Ability to connect technical findings to financial infrastructure including wallets, laundering paths, sanctions exposure, or identity-linked leads.
  • Excellent judgment about analytical confidence, evidentiary strength, and defensibility in reports, referrals, or operational settings.
  • Track record of leading complex investigations, improving workflows, and helping other analysts do better work.
  • Excellent written and verbal communication skills for technical and non-technical audiences.
  • Comfort operating in a fast-paced environment with changing priorities and ambiguity.
  • AI fluency required, including designing, building, and iterating on agentic AI workflows rather than simply prompting LLMs.
  • Surge availability expected during time-sensitive disruption windows.
  • Primary time zone overlap with US Eastern / Central.

Benefits

  • Distributed team with async-first approach via Slack and Notion.
  • High autonomy, high standards, low bureaucracy.
  • Work directly with analysts, engineers, and customers.
  • Reasonable accommodations for applicants with disabilities.

Blockchain intelligence platform for investigating, monitoring, and detecting crypto fraud and financial crime

🇺🇸 United StatesAIMid-sizetrmlabs.com/

Details

Apply routeDom
Salary not disclosed