Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TRM Labs

Cyber Threat Intelligence Analyst, Scams

TRM Labs

. Pivot from scam domains, IPs, or certificates across certificates, registrars, nameservers, hosting, and ASNs to map scam infrastructure .

Posted 9/23/2026full-timeUnited StatesMid-LevelSenior💰 $115,000 - $160,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cyber threat intelligence and infrastructure analysis, with a strong ability to produce actionable intelligence and assessments. Proficient in using CTI tooling and building detection logic to identify and mitigate malicious activities.

Highest-signal resume keywords
Cyber Threat IntelligenceInfrastructure AttributionDetection Logic DevelopmentOpen-Source Intelligence (OSINT)AI Fluency

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat Infrastructure AnalysisClustering LogicDetection RulesAutomationPhishing MonitoringPassive DNSWHOISCertificate FingerprintingAnalytic JudgmentActionable Intelligence Production
Soft Skills
Analytical ThinkingCollaborationCommunication
Tools & Technologies
NotionTRM Investigative Tools
Industry Keywords
Scam InfrastructureThreat Actor AttributionTakedownsRe-registrationFederal PartnersTime-Sensitive Disruption

Tech Stack

Tools & technologies
DNS

About the role

Key responsibilities & impact
  • Pivot from scam domains, IPs, or certificates across certificates, registrars, nameservers, hosting, and ASNs to map scam infrastructure
  • Track scam campaigns through domain, hosting, registrar, and certificate changes, takedowns, seizures, and re-registration
  • Drive threat-actor attribution using open-source and commercially available data
  • Connect technical infrastructure investigations to wallets, laundering paths, and cash-out points
  • Build clustering logic, detection rules, automation, and tooling to identify malicious infrastructure proactively
  • Produce calibrated, defensible assessments with confidence levels and evidence weighting
  • Synthesize OSINT, technical, financial, on-chain, and off-chain intelligence into actionable targeting packages
  • Own the intelligence cycle end to end with minimal supervision
  • Partner with the Scams SME team, data, engineering, product, analysts, and federal partners
  • Document output in Notion and TRM investigative tools
  • Participate in weekly team syncs and daily async standups

Requirements

What you’ll need
  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles
  • Hands-on infrastructure attribution across shared certificates, registrars, nameservers, hosting, and ASNs
  • Experience tracking actors or campaigns through takedowns and re-registration
  • Fluency with CTI tooling, including passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring
  • Experience building detection and clustering logic, rules, or automation
  • Experience using open-source and commercially available data for threat-actor attribution
  • Ability to produce actionable intelligence or targeting packages for government, law-enforcement, or equivalent consumers
  • Calibrated and defensible analytic judgment
  • Must be located in the Washington, D.C./MD/VA area
  • Ability to work with primary time-zone overlap in US Eastern/Central
  • Surge availability during time-sensitive disruption windows
  • AI fluency, including applying AI to accelerate workflows, structure and solve problems, improve output quality, and increase speed and leverage

Benefits

Comp & perks
  • Equity plan eligibility
  • Distributed-first, async-first work approach
  • Periodic in-person collaboration and travel may be required
  • High autonomy and low bureaucracy
  • Global team collaboration
  • Professional growth opportunities
  • Wellness programs and time away from work, varying by country and local employment requirements