- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About TRM Labs
TRM Labs develops artificial intelligence-driven intelligence solutions designed to aid public and private sectors in investigating and disrupting criminal activities. Their platforms empower investigators to trace criminal behavior, build cases, and develop comprehensive pictures of threat actor networks. Leading organizations globally trust TRM to enhance safety and security.
Role Overview
As a Senior Cyber Threat Intelligence Analyst at TRM Labs, you will leverage AI-powered investigative platforms to combat cybercrime by managing threat intelligence investigations and developing capabilities covering the entire intelligence lifecycle. The role demands a seasoned analyst with proven experience in tracking cyber threat actors, delivering impactful intelligence, and collaborating across teams to strengthen the CTI function.
Key Responsibilities
- Manage comprehensive investigations starting from a single indicator (domain, IP, hash, alias, wallet) through to attributing actors, clusters, or campaigns.
- Proactively identify new intelligence collection opportunities and utilize gathered intelligence to preempt cyber threats.
- Develop network profiles of cyber threat actors including their command and control infrastructure, malware family associations, tactics, techniques, procedures, and operators.
- Integrate technical indicators with open-source intelligence, identity signals, infrastructure patterns, and financial transaction data to deepen adversary insights.
- Create detailed intelligence deliverables such as actor profiles, campaign analyses, indicator of compromise packages, infrastructure attributions, and operationally ready analytic reports.
- Serve as a senior analyst across multiple active cases simultaneously, driving quality improvements, sharing best practices, and mentoring other analysts.
- Analyze and synthesize large volumes of indicators into coherent, actionable intelligence suitable for stakeholders.
- Support teams involved in incident response, threat hunting, investigative activities, and partner engagement with timely and reliable intelligence outputs.
- Test and evaluate new analytical tools by applying them to live workflows, aiming to reduce analyst effort or improve intelligence quality.
- Contribute to refining investigation procedures, analytic standards, and workflows that enhance efficiency without compromising analytical rigor.
Candidate Profile
- Minimum five years of experience in cyber threat intelligence, intelligence analysis, incident investigation, or a closely related analytical discipline.
- Advanced proficiency with AI tools, such as Claude, to build custom automation workflows, scaling investigative efforts with rigorous human oversight.
- Proven ability to independently lead complex investigations from initial intrusion to final impact assessment.
- Expertise in combining direct data collection with open-source intelligence to resolve identities, aliases, and behavioral patterns from diverse fragmented sources.
- Experience delivering finalized intelligence products including actor profiles, campaign reports, attribution findings, and detailed infrastructure mappings (distinct from detection or threat feed roles).
- Exceptional judgment in assessing analytical confidence and evidentiary robustness applicable in operational, reporting, or referral contexts.
- Strong written and oral communication skills, able to tailor findings for both technical and non-technical audiences.
- Deeply familiar with cyber investigations, infrastructure attribution, campaign research, and profiling cyber adversaries.
- Capable of thriving in dynamic, fast-changing environments where ambiguity is common.
Preferred Attributes
- Proficiency in Russian, Chinese, or other languages extensively used by cyber threat actors, preferably with operational experience rather than just academic.
- Active presence in the cybersecurity community through conference presentations, published research, or participation in exclusive intelligence-sharing groups.
- Familiarity with cryptocurrency or blockchain tracing, bridging technical discoveries with financial processes such as wallet identification, laundering pathways, sanctions analysis, or identity-linked leads.
Team Environment
- Part of a globally distributed intelligence team combining expert tradecraft and innovative analytical methodologies across cyber, OSINT, and blockchain-enabled threat domains.
- Utilization of asynchronous collaboration tools (Slack, Notion) supplemented by scheduled synchronizations for strategic alignment.
- High autonomy with direct interaction among analysts, engineers, and customers, emphasizing impact and ownership.
Work Rhythms
- Weekly sync meetings to prioritize targets and review opportunities for disruption.
- Daily asynchronous updates on active investigations, returns, and deliverables via Slack.
- Main time zone alignment: US Eastern and Central Time zones.
- All outputs are documented within Notion and specialized investigative platforms.
- Availability to support surge periods during time-sensitive operational windows.
Work Culture
TRM Labs fosters a high-velocity, high-ownership environment where experimentation, rapid iteration, and continuous learning are paramount. The company values problem-solvers who can navigate ambiguity, adapt quickly, and deliver impactful results in a mission-driven atmosphere focused on national security and crime fighting via AI.
Application Process
Applicants are encouraged to apply directly and provide thorough, relevant information highlighting experiences and impact aligned with the role’s requirements. The interview procedure involves multiple stages designed to assess problem-solving ability, AI proficiency, and cultural alignment, including case studies and leadership evaluations.
Privacy and Compliance
By applying, candidates consent to TRM Labs processing personal data in line with their privacy policy. Personal information may be retained for up to 36 months to accommodate lengthy hiring cycles. Candidates in jurisdictions with data protection laws have rights to access or amend their data. Use of unauthorized AI tools during interviews is prohibited without prior consent from TRM.