TRM Labs

Senior Cyber Threat Intelligence Analyst

TRM Labs

Dublin, County Dublin, Ireland · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Overview

TRM Labs offers AI-driven intelligence solutions that empower government and private entities to investigate and counteract criminal activity. Their platform supports tracing illicit behaviour, case construction, and profiling cyber threat networks, trusted globally by law enforcement and financial organizations to enhance security.

Role Summary

As a Senior Cyber Threat Intelligence Analyst at TRM Labs, you will lead initiatives to combat cyber threats by conducting comprehensive CTI investigations and developing capabilities across all phases of the intelligence lifecycle. You will collaborate closely with internal teams and external partners to elevate the CTI function.

Key Responsibilities

  • Manage investigations from initial indicator (such as domain, IP, hash, alias, or wallet) to detailed attribution of actors, clusters, or campaigns.
  • Discover novel CTI data sources and act quickly to leverage intelligence for preemptive cyber threat mitigation.
  • Construct comprehensive profiles illustrating cyber adversaries' control infrastructures, malware families, tactics, techniques, and operators.
  • Integrate technical indicators with open-source intelligence, identity markers, infrastructure patterns, and financial transaction insights to deepen adversary profiling.
  • Create intelligence outputs including actor profiles, campaign analyses, indicator packages, infrastructure links, and evidentiary analytical reports.
  • Provide senior analyst leadership across multiple threats and campaigns, enhancing quality, sharing best practices, and mentoring colleagues through exemplary analytical work.
  • Evaluate and cluster large datasets of indicators to transform scattered signals into actionable and defensible intelligence.
  • Support incident handlers, threat hunters, investigators, and partner teams with accurate, prompt intelligence and briefings.
  • Assess new analytical tools by testing them in actual workflows to determine their effect on reducing effort and improving analysis quality.
  • Participate in refining investigation workflows, analytical standards, and repeatable approaches that boost analyst productivity without compromising rigor.

Candidate Requirements

  • Minimum five years of experience in cyber threat intelligence, intelligence analysis, incident investigations, or related analytical roles.
  • Proficiency in AI tools—developing automated investigative workflows with platforms like Claude while ensuring human oversight for quality assurance.
  • Proven autonomous management of complex investigations, able to narrate intrusion sequences from entry to impact.
  • Advanced skills in combining direct intelligence collection and OSINT to produce unique insights, resolving identities and behaviors from fragmented sources.
  • Experience delivering polished intelligence reports including actor profiling, campaign documentation, attribution conclusions, and infrastructure mapping (not detection rule creation).
  • Strong judgment in assessing analytical confidence levels and evidentiary support appropriate for reports, referrals, and operations.
  • Excellent verbal and written communication tailored to technical teams and non-technical stakeholders.
  • In-depth knowledge of cyber threat investigations encompassing infrastructure attribution and campaign analytics.
  • Ability to adapt effectively in fast-changing, ambiguous environments with shifting priorities.

Preferred Qualifications

  • Operational proficiency in languages often utilized by cyber adversaries such as Russian or Chinese, especially for forum engagement or persona work.
  • Active visibility in the cybersecurity community via conference presentations, publications, or invite-only intelligence sharing.
  • Practical experience in cryptocurrency or blockchain tracing linking technical indicators to financial infrastructure, including wallet activity, laundering chains, sanctions compliance, or identity leads.

Team Environment

  • Join TRM's Intelligence Team combining expert tradecraft with innovative analytical workflows intersecting cyber, OSINT, and blockchain threat activity.
  • Operate within a distributed, asynchronous-first team culture using platforms like Slack and Notion paired with regular sync meetings.
  • Benefit from high autonomy and low bureaucracy while collaborating closely with analysts, engineers, and customers reliant on your analysis.

Working Rhythm

  • Weekly team meetings to coordinate targeting and disruption strategies.
  • Daily asynchronous updates via Slack on ongoing investigations and returns.
  • Primary overlap with US Eastern and Central time zones.
  • Comprehensive documentation in internal platforms.
  • Possibility of surge duties during critical disruption operations.

Recruitment Process

Applicants should carefully review the detailed job description and demonstrate relevant experience. The multi-stage interview includes recruiter introductions, hiring manager discussions, skill-focused interviews, leadership principles evaluation, references check, and final offers. AI fluency and investigative thinking form critical assessment pillars.

About the Company Culture

TRM Labs fosters a dynamic, mission-driven environment with rapid pace and high ownership. Embracing experimentation, collaboration, and continuous improvement, the organization values impact-oriented, masterful craftsmanship and supportive teammates. This fast-evolving setting rewards adaptability, urgency, and creative problem-solving, appealing to those seeking meaningful challenges.

Privacy and Legal

By applying, candidates consent to TRM Labs processing personal data for recruitment purposes under their privacy guidelines, retaining information for up to 36 months. Candidates have data access and deletion rights where applicable under GDPR and related laws.

Industry

Cybersecurity

How they work

Teamwork & Collaboration Problem Solving Attention to Detail Adaptability
🤖
Online · instant AI help
Broxer