Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)

TRM Labs•Washington DC, DC
•Hybrid

About The Position

The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst, you'll lead infrastructure-driven investigative work: pivoting from a single domain, IP, or certificate to the network behind it, following it to the money, and delivering actionable intelligence to law enforcement and government partners. You'll track scam infrastructure as it evolves, fusing technical, open-source, and on-chain data to build the operational pictures that help dismantle scam operations.

Requirements

  • 5+ years of proven experience in cyber threat intelligence or threat infrastructure analysis roles (this is not an entry-level position).
  • Hands-on infrastructure attribution: infrastructure pivoting and campaign tracking across shared certificates, registrars, nameservers, hosting, and ASNs — and a habit of thinking in campaigns, not isolated indicators.
  • A track record of staying on an actor or campaign over time, including through takedowns and re-registration.
  • Hands-on fluency with CTI tooling — passive DNS, WHOIS, certificate or Shodan-style fingerprinting, and phishing monitoring.
  • Experience building detection and clustering logic, rules, or automation yourself — not just configuring vendor tooling.
  • Attribution tradecraft: using open-source and commercially available data to drive attribution of threat actors.
  • Demonstrated ability to produce actionable intelligence or targeting packages for a government, law-enforcement, or equivalent consumer who acted on them, and calibrated, defensible analytic judgment.
  • Must be located in the Washington, D.C./MD/VA area (periodic in-person collaboration and travel may be required).

Nice To Haves

  • If you’re excited by TRM’s mission but don’t check every box, apply anyway.
  • If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit.
  • If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute.
  • If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.

Responsibilities

  • Start from one indicator — a scam domain, IP, or certificate — and pivot across shared certificates, registrars, nameservers, hosting, and ASNs to map the wider infrastructure behind Southeast Asia scam operations, clustering one-off indicators into campaigns.
  • Track campaigns as they evolve — new domains, hosting and registrar changes, certificate reuse — and stay on actors as they rebuild and re-register after takedowns and seizures, anticipating their next infrastructure.
  • Drive attribution of threat actors by leveraging open-source and commercially available data.
  • Fuse technical infrastructure with the on-chain picture — carrying an investigation from infrastructure through to the wallet, the laundering path, and the cash-out.
  • Build clustering logic, detection rules, and automation or tooling to surface malicious infrastructure proactively, rather than waiting on off-the-shelf feeds.
  • Produce defensible, calibrated assessments — assigning confidence, weighing evidence across sources, and standing behind a malicious-versus-benign call.
  • Synthesize on-chain and off-chain intelligence (OSINT, technical, and financial) into targeting packages that a government or law-enforcement consumer can act on.
  • Own the intelligence cycle end to end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM's collection capabilities.

Benefits

  • AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime.
  • Platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks.
  • Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
  • Distributed team with an async-first approach via Slack and Notion, plus structured syncs for alignment
  • High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output
  • TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others.
  • Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service