Skip to main content
TRM Labs
TRM Labs

Staff Cyber Threat Intelligence Analyst

RemoteUnited States, United Kingdom only· UTC-6…UTC-5
Published
Role
Security
Experience
Lead
Employment
Full-time
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to US, GB only · UTC-6…UTC-5. Set where you work from to check your eligibility.

No BS summary

Staff Cyber Threat Intelligence Analyst, 8+ yrs experience in cyber threat intelligence or related field. Must produce finished intelligence products and have strong OSINT skills. US-based candidates only.

Required skills

OSINTAI toolsSlackNotion

Required languages

English Excellent written and verbal communication

What you'll do

  • Produce finished cyber threat intelligence including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs
  • Act as a staff-level analytical leader across multiple active actors and campaigns
  • Drive high-complexity investigations from seed indicators such as domains, IPs, hashes, aliases, or wallets to attributed actors, clusters, or campaign pictures
  • Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity
  • Triage large indicator sets, cluster infrastructure, and turn fragmented signals into defensible findings
  • Support incident responders, threat hunters, investigators, leadership, and external partners with timely intelligence products and briefings
  • Evaluate and operationalize new analytical tooling on real workflows
  • Improve investigation workflows, analytic standards, and repeatable methods
  • Partner across intelligence, engineering, and data science to translate investigative tradecraft into scalable analytical capabilities and product-informed improvements

What they require

  • 8+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field
  • Demonstrated experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping
  • Deep expertise in cyber investigations, infrastructure attribution, campaign analysis, and actor profiling
  • Strong OSINT instincts and ability to resolve identities, aliases, and behavior across fragmented sources
  • Ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads
  • Excellent judgment about analytical confidence, evidentiary strength, and defensibility in reports, referrals, or operational settings
  • Track record of leading complex investigations, improving workflows, shaping analytical standards, and raising quality beyond own cases
  • Excellent written and verbal communication skills for technical and non-technical audiences
  • Comfort operating in a fast-paced environment with changing priorities and ambiguity
  • AI fluency is required, with AI tools used for research, synthesis, and workflow acceleration under strong human quality control
  • Surge availability expected during time-sensitive disruption windows

Benefits

  • Distributed team with async-first approach via Slack and Notion
  • Structured syncs for alignment
  • High autonomy
  • Low bureaucracy
  • Work directly with analysts, engineers, and customers
  • Mission-driven work at the intersection of AI, national security, and fighting crime

Blockchain intelligence platform for investigating, monitoring, and detecting crypto fraud and financial crime

🇺🇸 United StatesAIMid-sizetrmlabs.com/

Details

Apply routeDom
Salary not disclosed