Staff Cyber Threat Intelligence Analyst
TRM Labs · UK, USA
Skills in this posting
The posting
Build a Safer World.
TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
About the role
As a Staff Cyber Threat Intelligence Analyst , you will conduct high-complexity investigations, support time-sensitive blockchain analysis for our partners, and shape investigative methods, workflows, and analytical capabilities that allow TRM to scale rapidly and effectively.
You will collaborate with blockchain intelligence experts, engineers, and data scientists to raise the quality, repeatability, and operational relevance of TRM’s cyber threat intelligence capabilities.
The impact you will have
Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs.
Act as a staff-level analytical leader across multiple active actors and campaigns at once, raising quality, shaping standards, and coaching other analysts through exemplary tradecraft and judgment.
Drive the highest-complexity investigations from seed indicators such as domains, IPs, hashes, aliases, or wallets through to attributed actors, clusters, or campaign pictures, and codify the methods others can reuse.
Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity to build a fuller understanding of adversary behavior.
Triage large indicator sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings while improving the repeatability and rigor of how this work is done across the team.
Support incident responders, threat hunters, investigators, leadership, and external partners with timely, high-confidence intelligence products and briefings, especially where judgment, prioritization, and ambiguity are unusually high.
Evaluate and operationalize new analytical tooling by pressure-testing it on real workflows and identifying where it meaningfully reduces analyst effort, improves quality, or creates reusable leverage across investigations.
Drive better investigation workflows, analytic standards, and repeatable methods that increase analyst throughput without sacrificing rigor.
Partner across intelligence, engineering, and data science to translate investigative tradecraft into scalable analytical capabilities and product-informed improvements.
What we're looking for
8+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field.
Demonstrated experience producing finished intelligence products such as actor profiles, campaign reports, attribution assessments, or infrastructure mapping.
Deep expertise in cyber investigations, infrastructure attribution, campaign analysis, and actor profiling, including the ability to set a high bar for analytical rigor in these areas.
Strong OSINT instincts and the ability to resolve identities, aliases, and behavior across fragmented sources.
The ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation.
Excellent judgment about analytical confidence, evidentiary strength, and what can or cannot be defended in a report, referral, or operational setting, including the ability to guide others on those standards.
A track record of leading complex investigations, improving workflows, shaping analytical standards, and raising the quality of work beyond your own cases.
Excellent written and verbal communication skills, with the ability to package findings for technical and non-technical audiences alike.
Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.
AI fluency is required. AI tools should be a meaningful part of your research, synthesis, and workflow acceleration toolkit, with strong human quality control over the resulting output.
About the Team
TRM's intelligence and investigations work combines national-security-grade tradecraft with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.
This role sits at the intersection of intelligence production, investigations, and product-informed tradecraft, helping ensure TRM’s analytical capabilities remain operationally relevant, scalable, and high-quality across multiple use cases and stakeholders.
Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment
High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output
Team Operating Rhythms
Weekly team syncs to align targeting priorities and review disruption opportunities
Daily async standups via Slack on active work, returns, and target packages in flight
Primary time zone overlap: US Eastern / Central
All output documented in Notion and TRM’s investigative tools
Surge availability expected during time-sensitive disruption windows
Learn about TRM Speed in this position
Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.
Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.
Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.
Application Instructions
If you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.
Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.
If you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.
What to Expect From Our Interview Process
Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.
Recruiter Intro: Explore your experience, motivations, and alignment with the role.
Hiring Manager: Dive deeper into your relevant experience, skills, and impact.
First Round: Typically 1–2 interviews focused on the skills most critical to the role.
Final Round: Typically 3–5 interviews to go deeper on your craft, problem-solving, and alignment with TRM.
References: We’ll speak with former colleagues who can provide perspective on your work and impact.
Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.
Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- Careers a security engineer can move intoevery measured route out
- Penetration Tester → Security Engineer51% readiness
- All open security engineer rolesthe full board
Where these skills also reach
- 79 open penetration tester roles78% readiness from security engineer
- 358 open network engineer roles61% readiness from security engineer
- 700 open systems administrator roles52% readiness from security engineer
- 1961 open systems engineer roles51% readiness from security engineer
More security engineer roles
Product Security Engineer at YipitDataUSA · RemoteTodayApply
Cybersecurity Engineer (m/f/d) at IsaraerospaceParsdorf, BavariaTodayApply
Sr Cloud Security Engineer I at American Specialty Health, Inc.United States · Remote$146k–$170kTodayApply
Director, Cyber Security at Ziply FiberUnited States · Remote$165k–$200kTodayApply
Global Security Analyst at TranscomCroatia; Estonia; Lithuania; Portugal; Spain · RemoteTodayApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.