TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
TRM Labs builds the AI Investigations platform trusted by law enforcement and financial institutions to investigate and disrupt financial crime at scale. As a Staff Cyber Threat Intelligence Analyst, you will drive the highest-complexity investigations on TRM's investigations platform, and you'll codify the methods, workflows, and analytical standards the rest of the team reuses. This is a role for CTI leaders with a track record of strengthening organizations and delivering significant impact for customers.
Run high-complexity investigations end-to-end, from a single seed indicator — a domain, IP, hash, alias, or wallet — through to an attributed actor, cluster, or campaign picture.
Identify new CTI collection opportunities and rapidly leverage the intelligence to get ahead of cyber threats
Build the network picture around cyber threat actors: C2 infrastructure, malware families, TTPs, and the people operating them.
Fuse technical indicators with OSINT and identity work, and follow findings into financial rails where the investigation goes there.
Set the analytical standard: raise the bar on rigor and confidence judgments across the team, and coach other analysts through exemplary tradecraft rather than process.
Partner directly with engineering and data science to turn investigative tradecraft into scalable capability — tooling and workflows the whole team benefits from, not one-off analysis.
Support incident responders, threat hunters, investigators, leadership, and external partners with timely, high-confidence intelligence products and briefings, especially where judgment, prioritization, and ambiguity are unusually high.
8+ years in cyber threat intelligence, intelligence analysis, incident-driven investigations, or closely related analytical work.
If you're at the 5-7 year mark and this reads like a stretch, please apply to the Senior posting instead. Same team, same work, different scope.
AI fluency is required — you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce.
A track record of raising the quality of work beyond your own cases — shaping standards, improving workflows, and helping other analysts do better work.
Direct experience partnering with engineering, data science, or product to make an investigative method repeatable at scale. This one is not optional at Staff.
Strong ability to combine direct collection and OSINT to deliver unique intelligence — resolving identities, aliases, and behavior across fragmented sources.
Experience producing finished intelligence, such as actor profiles, campaign reporting, attribution assessments, infrastructure mapping. Detection rules and threat feeds are a different discipline.
Judgment strong enough to guide others on evidentiary standards, not just apply them yourself.
Excellent written and verbal communication — you can package a finding for a technical analyst and for a non-technical partner.
Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.
Working proficiency in Russian, Chinese, or another language heavily used by cyber actors — particularly if you've used it operationally, in forums or persona work, rather than academically.
A public presence: conference talks, published research, invite-only sharing circles.
Hands-on crypto or blockchain tracing, and the ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation.
TRM's Intelligence Team combines expert tradecraft and boundary-pushing innovation with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity.
Distributed and async-first via Slack and Notion, with structured syncs for alignment.
High autonomy, high standards, low bureaucracy — you work directly with analysts, engineers, and partners who depend on your output.
Weekly team syncs to align targeting priorities and review disruption opportunities
Daily async standups via Slack on active work, returns, and target packages in flight
Primary time zone overlap: US Eastern / Central
All output documented in Notion and TRM’s investigative tools
Surge availability expected during time-sensitive disruption windows
Move quickly from a single lead or indicator to an initial analytical picture while the signal is still operationally useful.
Support partners and internal teams on time-sensitive issues where fast, defensible judgment matters more than perfect information.
Continuously adapt your tradecraft as adversaries, data sources, and analytical tooling evolve.
If you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.
Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.
If you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.
Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.
Recruiter Intro: Explore your experience, motivations, and alignment with the role.
Hiring Manager: Dive deeper into your relevant experience, skills, and impact.
First Round: Typically 1–2 interviews focused on the skills most critical to the role.
Final Round: Typically 3–5 interviews to go deeper on your craft, problem-solving, and alignment with TRM.
References: We’ll speak with former colleagues who can provide perspective on your work and impact.
Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.
Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.
Your recruiter will share your specific interview plan and preparation guidance along the way.
Learn more about interviewing at TRM
We are building a safer world. That promise shows up in how we work every day.
TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.
Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.
At TRM, you should expect:
Priorities and targets to change quickly as we experiment and iterate
Work that often requires operating with a high degree of ambiguity
A high level of personal ownership and accountability
Close collaboration across teams and functions
Frequent, high-touch communication
Creative problem solving and out-of-the-box thinking
A pace that rewards urgency, adaptability, and outcomes
This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.
We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.
At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like
AI fluency is a baseline expectation at TRM.
We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.
At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:
Accelerate repeatable workflows
Structure and solve problems
Improve output quality
Increase speed and leverage
You will be evaluated on applied AI fluency during the interview process.
We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.
Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.
Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.
Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.
At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.
TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy.
We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.
Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at [email protected].
To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form.
TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.
Compensation Range: $150K - $215K