Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TRM Labs

Cyber Threat Intelligence Analyst, Scams

TRM Labs

. Pivot from scam domains, IPs, or certificates across shared certificates, registrars, nameservers, hosting, and ASNs to map scam infrastructure .

Posted 10/1/2026full-timeUnited StatesMid-LevelSenior💰 $115,000 - $160,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cyber threat intelligence, focusing on infrastructure attribution, detection logic, and actionable intelligence production. Proficient in synthesizing diverse intelligence sources to support government and law enforcement operations.

Highest-signal resume keywords
Cyber Threat IntelligenceInfrastructure AttributionDetection Logic DevelopmentOpen-Source Data UtilizationAnalytic Judgment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat Infrastructure AnalysisClustering LogicDetection RulesPassive DNSWHOISCertificate FingerprintingPhishing MonitoringCampaign TrackingActionable Intelligence ProductionAnalytic Assessment
Soft Skills
CollaborationCommunicationAnalytic Judgment
Tools & Technologies
NotionTRM Investigative Tools
Industry Keywords
Scam InfrastructureThreat Actor AttributionOn-Chain DataOff-Chain IntelligenceTime-Sensitive Disruption

Tech Stack

Tools & technologies
DNS

About the role

Key responsibilities & impact
  • Pivot from scam domains, IPs, or certificates across shared certificates, registrars, nameservers, hosting, and ASNs to map scam infrastructure
  • Track scam campaigns through new domains, hosting and registrar changes, certificate reuse, takedowns, and seizures
  • Drive threat actor attribution using open-source and commercially available data
  • Fuse technical infrastructure intelligence with on-chain data from wallets through laundering paths and cash-out points
  • Build clustering logic, detection rules, automation, and tooling to proactively identify malicious infrastructure
  • Produce calibrated, defensible assessments and determine malicious-versus-benign activity
  • Synthesize OSINT, technical, financial, on-chain, and off-chain intelligence into actionable targeting packages
  • Own the intelligence cycle end to end with minimal supervision
  • Partner with the Scams SME team, data, engineering, product, analysts, and government or law-enforcement partners
  • Participate in weekly team syncs and daily async standups
  • Document output in Notion and TRM investigative tools
  • Support time-sensitive disruption windows

Requirements

What you’ll need
  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles
  • Hands-on infrastructure attribution across shared certificates, registrars, nameservers, hosting, and ASNs
  • Experience tracking actors or campaigns through takedowns and re-registration
  • Hands-on fluency with passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring
  • Experience building detection and clustering logic, rules, or automation
  • Experience using open-source and commercially available data for threat actor attribution
  • Ability to produce actionable intelligence or targeting packages for government, law-enforcement, or equivalent consumers
  • Calibrated and defensible analytic judgment
  • Must be located in the Washington, D.C./MD/VA area
  • Periodic in-person collaboration and travel may be required
  • Surge availability during time-sensitive disruption windows
  • AI fluency is a baseline expectation
  • Legally authorized to work in the country of employment

Benefits

Comp & perks
  • Equity plan eligibility
  • Distributed-first work environment
  • Async-first approach via Slack and Notion
  • High autonomy and low bureaucracy
  • Global team collaboration
  • Reasonable accommodations for applicants with disabilities