Intelligence Analyst - TRM Labs - Cyber Threat Intelligence Analyst
Requirements
• 3+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field. • Demonstrated experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping. • Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling. • Strong OSINT instincts and the ability to resolve identities, aliases, and behavior across fragmented sources. • The ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation. • Excellent judgment about analytical confidence, evidentiary strength, and what can or cannot be defended in a report, referral, or operational setting. • A track record of independently driving complex investigations, improving workflows, and elevating the quality of analytical work around you. • Excellent written and verbal communication skills, with the ability to package findings for technical and non-technical audiences alike. • Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal. • AI fluency is required. AI tools should be a meaningful part of your research, synthesis, and workflow acceleration toolkit, with strong human quality control over the resulting output.
Responsibilities
• As a Cyber Threat Intelligence Analyst, the role involves conducting ad hoc investigations, time-sensitive blockchain analysis for partners, and contributing to investigative methods and workflows that help scale operations rapidly and effectively. • The analyst will collaborate closely with blockchain intelligence experts, engineers, and data scientists to deliver high-confidence analytical support. • Producing finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs. • Acting as an analyst across multiple active actors and campaigns, improving quality and sharing tradecraft. • Assisting in complex investigations from seed indicators (domains, IPs, hashes, aliases, wallets) to attributed actors and campaign pictures. • Correlating technical indicators with OSINT, identity signals, and financial activity. • Supporting incident responders and partners with timely intelligence products and briefings. • Evaluating new analytical tooling and contributing to stronger investigation workflows. • 3+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or closely related analytical field. • Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling. • Strong OSINT instincts and ability to resolve identities across fragmented sources. • Ability to connect technical findings to financial infrastructure (wallets, laundering paths, sanctions exposure). • Excellent judgment on analytical confidence and evidentiary strength. • Track record of independently driving complex investigations and improving workflows. • Excellent written and verbal communication skills. • Comfort in fast-paced, ambiguous environments. • High autonomy, high standards, low bureaucracy. • Opportunity to work on meaningful mission-driven problems at the intersection of AI, national security, and fighting crime. • Subscribe and mute notifications to avoid noise. • Use search by role or skills to find jobs, or look in the pinned messages (there is a short list of all vacancies). DYOR! I don t verify jobs.
Benefits
• The impact includes: • Triage large indicator sets and turning fragmented signals into clear, defensible findings. • AI fluency required, with strong human quality control over AI outputs. Perks & • Benefits: Distributed-first team with async-first approach via Slack and Notion. • If you're asked to download and run files on your computer, or if you're asked for payment, that's a scam. I'm not hiring myself! I just sharing fresh real Web3 jobs daily. #NFA #DYOR All my other social media!
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT