Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs
Washington DC
Workplace: RemoteFull timeUSD 115,000 - 160,000 annuallyFunction: CybersecurityExperience: 5+ yearsSkills: ["Investigative thinking","Analytical judgment","Attention to detail","Ownership","Collaboration"]

Lead infrastructure-driven investigations to disrupt pig butchering, romance fraud, and investment scams. Pivot from domains, IPs, or certificates to map shared infrastructure across certificates, registrars, nameservers, hosting, and ASNs, then track actors through takedowns and re-registration. Fuse OSINT and on-chain evidence to produce calibrated, defensible assessments and actionable targeting packages for law-enforcement and government partners, owning the intelligence cycle end to end.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
TRM Labs
TRM Labs
18 hours ago

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead infrastructure-driven investigations to disrupt pig butchering, romance fraud, and investment scams. Pivot from domains, IPs, or certificates to map shared infrastructure across certificates, registrars, nameservers, hosting, and ASNs, then track actors through takedowns and re-registration. Fuse OSINT and on-chain evidence to produce calibrated, defensible assessments and actionable targeting packages for law-enforcement and government partners, owning the intelligence cycle end to end.
Location: Washington DC
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Pivot from a single scam indicator (domain, IP, certificate) to map the wider infrastructure behind scam operations.
  • •Track and analyze evolving scam campaigns as infrastructure changes over time, including after takedowns.
  • •Leverage open-source and commercially available data to drive threat actor attribution.
  • •Fuse technical infrastructure with on-chain evidence through the laundering and cash-out path.
  • •Build detection/clustering logic and automation/tooling to proactively surface malicious infrastructure and produce defensible assessments.
Travel: Low travel

Pay and Benefits

Salary: USD 115,000 - 160,000 annually
Equity and Bonus:Equity

Key Requirements

  • •5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (not entry-level).
  • •Hands-on infrastructure attribution and campaign tracking using shared certificates, registrars, nameservers, hosting, and ASNs.
  • •Experience tracking actors or campaigns over time, including through takedowns and re-registration.
  • •Hands-on fluency with CTI tooling such as passive DNS, WHOIS, certificate/shodan-style fingerprinting, and phishing monitoring.
  • •Ability to produce actionable, defensible intelligence or targeting packages for government or law-enforcement consumers with calibrated judgment.
Experience:5+ yearsCyber threat intelligenceThreat infrastructure analysisOSINTOn-chain intelligenceFraud disruptionBlockchain intelligence
Skills:Investigative thinkingAnalytical judgmentAttention to detailOwnershipCollaboration
Tech Stack:Passive DNSWHOISShodanCertificatesOn-chain dataOSINTSlackNotion

Company Brief

TRM Labs
Provides blockchain intelligence and crypto risk management solutions to help financial institutions, governments, and crypto firms detect fraud, trace illicit activity, and comply with regulatory requirements across digital asset ecosystems.
Industry: RegTech
Company Size: Large (251 to 1,000 employees)
Growth: Growth Stage Startup
Headquarters: San Francisco, United States
Founded: 2018
WebsiteLinkedIn