> Markdown version of [/jobs/ext/2720699-cyber-threat-intelligence-analyst](https://www.wearedevelopers.com/jobs/ext/2720699-cyber-threat-intelligence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Analyst - **Company:** TRMS LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Computer Telephony Integration, Intelligence Analysis, Open Source Intelligence, Blockchain, Cybercrime - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-cyber-threat-intelligence-analyst-trmlabs-com-8565105 ## About the Role * 5+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field. * AI fluency is required - you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce. * A track record of driving complex investigations independently. You can walk us through a specific intrusion end-to-end - initial access through impact. * Strong ability to combine direct collection and OSINT to deliver unique intelligence - resolving identities, aliases, and behavior across fragmented sources. * Experience producing finished intelligence, such as actor profiles, campaign reporting, attribution assessments, and infrastructure mapping. Detection rules and threat feeds are a different discipline. * Excellent judgment about analytical confidence and evidentiary strength: what can and cannot be defended in a report, a referral, or an operational setting. * Excellent written and verbal communication - you can package a finding for a technical analyst and for a non-technical partner. * AI fluency - you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce. * Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling. * A track record of independently driving complex investigations, improving workflows, and elevating the quality of analytical work around you. * Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal., * Working proficiency in Russian, Chinese, or another language heavily used by cyber actors - particularly if you've used it operationally, in forums or persona work, rather than academically. * A public presence: conference talks, published research, invite-only sharing circles. * Hands-on crypto or blockchain tracing, and the ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation., * Priorities and targets to change quickly as we experiment and iterate * Work that often requires operating with a high degree of ambiguity * A high level of personal ownership and accountability * Close collaboration across teams and functions * Frequent, high-touch communication * Creative problem solving and out-of-the-box thinking * A pace that rewards urgency, adaptability, and outcomes This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment. We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here. At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like ## Description TRM Labs builds the AI Investigations platform trusted by law enforcement and financial institutions to investigate and disrupt financial crime at scale. As a Senior Cyber Threat Intelligence Analyst, you will help disrupt cyber threats at scale by driving CTI investigations and building capabilities across the full intelligence lifecycle. This is a role for analysts with a track record of collecting intelligence on cyber actors, a perspective on how to best deliver impact for CTI customers, and motivation to collaborate with TRM colleagues and partners to strengthen our CTI function. The impact you will have: * Run investigations end-to-end, from a single seed indicator - a domain, IP, hash, alias, or wallet - through to an attributed actor, cluster, or campaign picture. * Identify new CTI collection opportunities and rapidly leverage the intelligence to get ahead of cyber threats. * Build the network picture around cyber threat actors: C2 infrastructure, malware families, TTPs, and the people operating them. * Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity to build a fuller understanding of adversary behavior. * Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs. * Act as a senior analyst across multiple active actors and campaigns at once, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution. * Triage large indicator sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings that stakeholders can act on immediately. * Support incident responders, threat hunters, investigators, and partner-facing teams with timely, high-confidence intelligence products and briefings. * Help evaluate new analytical tooling by pressure-testing it on real workflows and identifying where it meaningfully reduces analyst effort or improves output quality. * Contribute to stronger investigation workflows, analytic standards, and repeatable methods that improve analyst throughput without sacrificing rigor., * TRM's Intelligence Team combines expert tradecraft and boundary-pushing innovation with deep analytical workflows across cyber, OSINT, and blockchain-enabled threat activity. * Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment * High autonomy, high standards, low bureaucracy - work directly with analysts, engineers, and customers who depend on your output Team Operating Rhythms: * Weekly team syncs to align targeting priorities and review disruption opportunities * Daily async standups via Slack on active work, returns, and target packages in flight * Primary time zone overlap: US Eastern / Central * All output documented in Notion and TRM's investigative tools * Surge availability expected during time-sensitive disruption windows, We hire and grow against three leadership principles. They're the standards for how we operate, treat each other, and make decisions. * Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment - test, ship, measure, and iterate quickly. * Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday. * Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset - giving and receiving feedback to make the team stronger., By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy. We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM. Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at privacy@trmlabs.com. To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Your First Pitch Is to AI: How to Make Your Brand/Product Visible in the Age of Generative Search](https://www.wearedevelopers.com/videos/100121-your-first-pitch-is-to-ai-how-to-make-your-brand-product-visible-in-the-age-of-generative-search) - [Pragmatic Blockchain Design Patterns: Integrating Blockchain into Business Processes](https://www.wearedevelopers.com/videos/1579-pragmatic-blockchain-design-patterns-integrating-blockchain-into-business-processes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Synthetic Insiders: The New AI Risk to Your Org](https://www.wearedevelopers.com/videos/100057-synthetic-insiders-the-new-ai-risk-to-your-org) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Tips on mastering remote job interviews](https://www.wearedevelopers.com/magazine/23-tips-on-mastering-remote-job-interviews) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [How to Ensure a Reasonable Salary Before an Interview](https://www.wearedevelopers.com/magazine/322-how-to-ensure-a-reasonable-salary-before-an-interview)