← Back to results

Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

Lead investigative work against scams, providing actionable intelligence to law enforcement and government partners.

Location
Washington DC, United States
Compensation
Not disclosed
Level
senior
Type
full time

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at TRM Labs → Save job Scanned from trmlabs.com

What you'll build

  • Track scam infrastructure
  • Drive attribution of threat actors
  • Produce actionable intelligence
  • Own the intelligence cycle end to end
  • Build clustering logic and detection rules

Must have

  • 5+ years of proven experience in cyber threat intelligence
  • Hands-on infrastructure attribution
  • Experience building detection and clustering logic
  • Demonstrated ability to produce actionable intelligence

Practical constraints

  • Must be located in the Washington, D.C./MD/VA area
  • Periodic in-person collaboration and travel may be required

Requirements

Experience
5+ years
Visa
No sponsorship (stated in posting)

Not disclosed in this posting: compensation, work arrangement.

Joblaze summary

In the role of Cyber Threat Intelligence Analyst focused on scams, the individual will conduct in-depth investigations into scam networks, tracing their infrastructure and financial flows to provide actionable intelligence to law enforcement. Key skills include hands-on experience with cyber threat intelligence tools, infrastructure attribution, and the ability to synthesize complex data into coherent targeting packages. This position is suited for seasoned professionals with over five years of relevant experience, particularly those who excel in high-pressure environments and enjoy tackling intricate problems. The Scam Disruption team operates with a high degree of autonomy, emphasizing col

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 25, 2026. Last confirmed on TRM Labs's careers page September 25, 2026.
  • AI appears in 5.8% of 310 comparable senior security roles in United States; infrastructure appears in 0.6% of 310 comparable senior security roles in United States.

Quick facts

How much experience is required?
At least 5 years of relevant experience for this Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only) role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, Automation, OSINT, cyber threat intelligence, infrastructure, phishing monitoring.
What seniority level is this role?
TRM Labs targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only) role at TRM Labs.

From the original posting

About the Role

The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst, you'll lead infrastructure-driven investigative work: pivoting from a single domain, IP, or certificate to the network behind it, following it to the money, and delivering actionable intelligence to law enforcement and government partners.

You'll track scam infrastructure as it evolves, fusing technical, open-source, and on-chain data to build the operational pictures that help dismantle scam operations.

 

The Impact You Will Have

  • Start from one indicator — a scam domain, IP, or certificate — and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns.

  • Track campaigns as they evolve — new domains, hosting and registrar changes, certificate reuse — and stay on actors as they rebuild and re-register after takedowns and seizures, anticipating their next infrastructure.

  • Drive attribution of threat actors by leveraging open-source and commercially available data.

  • Fuse technical infrastructure with the on-chain picture — carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out.

  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds.

  • Produce defensible, calibrated assessments — assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call.

  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on.

  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM's collection capabilities.

 

What We're Looking For

  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position).

  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs — and a habit of thinking in campaigns, not isolated indicators.

  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration.

  • Hands-on fluency with CTI tooling — passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring.

  • Experience building detection and clustering logic, rules, or automation yourself — not just configuring vendor tooling.

  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors.

  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, and calibrated, defensible analytic judgment.

  • Must be located in the Washington, D.C./MD/VA area (periodic in-person collaboration and travel may be required)

 

About the Team

  • The Scam Disruption team operates within TRM’s Blockchain Intelligence organization, alongside threat intelligence analysts, on-chain investigators, and federal partners

  • All-Source Investigators and Cyber Threat Intelligence Analysts are the operational core, converting strategy and tooling into prosecutable, actionable intelligence

  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment

  • High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output

 

Team Operating Rhythms

  • Weekly team syncs to align targeting priorities and review disruption opportunities

  • Daily async standups via Slack on active work, returns, and target packages in flight

  • Primary time zone overlap: US Eastern / Central

  • All output documented in Notion and TRM’s investigative tools

  • Surge availability expected during time-sensitive disruption windows

 

Join Our Mission

We seek people whose work matters, who build with speed and rigor, and who take pride in protecting others through their craft. If you’re excited by TRM’s mission but don’t check every box, apply anyway.

 

Build to protect civilization. Let’s do it together.

  • Recruiter Intro: Explore your experience, motivations, and alignment with the role.

Learn more about interviewing at TRM

At TRM, you should expect:

  • Priorities and targets to change quickly as we experiment and iterate

  • Close collaboration across teams and functions

  • Frequent, high-touch communication

  • Creative problem solving and out-of-the-box thinking

 
  • Accelerate repeatable workflows

  • Structure and solve problems

  • Improve output quality

  • Increase speed and leverage

  • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

Standard company text repeated across TRM Labs's postings is omitted here.

Similar positions