Blockchain Intelligence Analyst, Ransomware

TRM Labs
$115,000 - $150,000Remote

About The Position

TRM Labs is seeking a highly skilled and autonomous Blockchain Intelligence Analyst specializing in ransomware. This role involves leveraging blockchain analytics, cyber threat intelligence, and cryptocurrency attribution to trace ransomware proceeds, identify threat actor infrastructure, and generate actionable intelligence. The analyst will be responsible for leading complex investigations, developing high-confidence assessments, uncovering novel attribution, and enhancing the team's expertise through technical skills and mentorship. The position requires comfort in tracing funds across blockchains, identifying laundering infrastructure, correlating technical and financial data, and synthesizing information into clear, defensible intelligence for operational decision-making.

Requirements

  • 3-5+ years of professional experience in blockchain intelligence, crypto investigations, cybercrime analysis, threat intelligence, financial crime investigations, or a comparable senior analytical role.
  • Deep hands-on experience tracing funds across multiple blockchains and through laundering or obfuscation techniques such as mixers, chain-hopping, bridges, peel chains, and layered cash-out behavior.
  • Demonstrated ability to independently run complex investigations and synthesize findings into clear written intelligence products, including investigative assessments, lead packages, fund-flow analysis, and attribution reporting.
  • Deep understanding of the broader cybercrime ecosystem and the relationships among ransomware operators, affiliates, initial access brokers, malware developers, laundering networks, and cash-out services.
  • Excellent written and verbal communication skills, especially the ability to turn technically complex tracing findings into understandable, actionable intelligence for government and private-sector audiences.
  • Strong judgment, curiosity, and the ability to operate effectively in a fast-moving, high-stakes environment where timing matters and outputs must still stand up to scrutiny.
  • Experience leveraging AI tools and large language models (LLMs) to accelerate research, surface insights, and augment analytical workflows, with the ability to critically evaluate AI-generated outputs for accuracy and relevance.

Nice To Haves

  • Experience in government, national security, law enforcement, incident response, or mature private-sector investigative or threat intelligence programs.
  • Familiarity with OSINT, cybercrime infrastructure research, and cross-domain analytical methods that combine blockchain activity with off-chain signals and adversary behavior.
  • Comfort with modern investigative tooling, including AI and structured data environments such as TRM, Maltego, Palantir, or similar platforms.
  • Experience conducting HUMINT collection and engaging threat actors via dark web forums and encrypted messaging platforms.
  • Experience mentoring peers, shaping analytical standards, or improving investigative workflows without formal people management.
  • Advanced practitioner-level knowledge of crypto forensics concepts such as manual demixing, smart contracts, bridges, Ethereum- and TRON-based investigations, and OSINT-based data extraction.
  • Recognized subject matter depth, broader organizational influence, and a track record of shaping methodology or high-priority investigative strategy beyond individual case execution.

Responsibilities

  • Produce impactful finished intelligence on ransomware actors, affiliates, facilitators, and laundering pathways, including actor profiles, lead packages, attribution assessments, and operational reporting.
  • Lead complex end-to-end blockchain investigations from initial indicators to full attribution and actionable recovery or disruption opportunities.
  • Trace ransomware-related funds across multiple blockchains, bridges, mixers, peel chains, and nested services, identifying controllers, counterparties, cash-out services, and recovery touchpoints.
  • Correlate on-chain activity with OSINT, threat intelligence, attribution partner data, and off-chain identity or infrastructure signals.
  • Own investigative workstreams from discovery through validation, escalation, and written production, including drafting intelligence products.
  • Support TRM’s ransomware asset recovery mission by surfacing high-quality leads and identifying seizure or freeze opportunities.
  • Drive analytical leadership across active ransomware investigations by prioritizing work, maintaining rigorous standards, and mentoring other analysts.
  • Partner closely with internal and external stakeholders, including investigators, threat intelligence teammates, product teams, and public-sector or private-sector partners.
  • Contribute new attribution, refine investigative methodologies, and improve repeatable workflows for lead generation and asset recovery support.
  • Support external briefings, customer or partner engagements, and capability-building sessions where ransomware tracing, attribution, and recovery tradecraft must be explained clearly and credibly.

Benefits

  • AI-powered intelligence solutions
  • AI fluency is a baseline expectation
  • High velocity, high ownership team
  • Energized by hard problems, experimentation, and continuous feedback
  • Work at the intersection of AI, national security, and fighting crime
  • High level of personal ownership and accountability
  • Close collaboration across teams and functions
  • Frequent, high-touch communication
  • Creative problem solving and out-of-the-box thinking
  • A pace that rewards urgency, adaptability, and outcomes
  • Meaningful problems
  • Ambitious goals
  • Mission-driven colleagues
  • Exceptional place to grow and contribute
  • Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others.
  • Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service