# Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only) at TRM Labs

- Company: TRM Labs
- What the company does: Trusted by public sector agencies and private sector institutions on the front lines of illicit activity, including criminal networks, sanctioned actors and state-backed threats. Backed by Bessemer and Y Combinator.
- Company website: https://www.trmlabs.com/
- Type: Startups (AI role)
- Level: Analyst
- Location: Washington DC
- Work setup: Remote
- Pay: $115K to $160K base salary per year (USD)
- Posted: 2026-09-23
- Apply by: 2026-11-07
- Apply: https://jobs.ashbyhq.com/trm-labs/b92524ba-69cf-422e-82b7-1a570b724602
- Page: https://www.1752.vc/careers/jobs/trm-labs-cyber-threat-intelligence-analyst-scams-dc-md-va-only/

## About the role

The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst , you'll lead infrastructure-driven investigative work: pivoting from a single domain, IP, or certificate to the network behind it, following it to the money, and delivering actionable intelligence to law enforcement and government partners.

## What they're looking for

- 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position)
- Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs — and a habit of thinking in campaigns, not isolated indicators
- A track record of staying on an actor or campaign over time, including through takedowns and re-registration
- Hands-on fluency with CTI tooling — passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring
- Experience building detection and clustering logic, rules, or automation yourself — not just configuring vendor tooling
- Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors

Tags: R&D
