Remote job
Remote confirmedSenior Cyber Threat Intelligence Analyst
TRM Labs
Our assessment
- Our reading of the full posting text confirms it: fully remote.
- The posting states no salary. Comparable roles in our index (16 postings): median 3,167 euros per month, middle range 2,230 to 5,125 euros.
- 9 more open roles from this employer in our index. 8 of them fully remote.
This section only: calculated automatically by nomado24, from our own job index and our own reading of the posting text. Not stated by the employer.
Job description
BUILD A SAFER WORLD.
TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
ABOUT THE ROLE:
TRM Labs builds the AI Investigations platform trusted by law enforcement and financial institutions to investigate and disrupt financial crime at scale. As a Senior Cyber Threat Intelligence Analyst, you will help disrupt cyber threats at scale by driving CTI investigations and building capabilities across the full intelligence lifecycle.
This is a role for analysts with a track record of collecting intelligence on cyber actors, a perspective on how to best deliver impact for CTI customers, and motivation to collaborate with TRM colleagues and partners to strengthen our CTI function.
THE IMPACT YOU WILL HAVE:
- Run investigations end-to-end, from a single seed indicator — a domain, IP, hash, alias, or wallet — through to an attributed actor, cluster, or campaign picture.
- Identify new CTI collection opportunities and rapidly leverage the intelligence to get ahead of cyber threats.
- Build the network picture around cyber threat actors: C2 infrastructure, malware families, TTPs, and the people operating them.
- Correlate technical indicators with OSINT, identity signals, infrastructure patterns, and financial-rail activity to build a fuller understanding of adversary behavior.
- Produce finished cyber threat intelligence, including actor profiles, campaign reports, IOC packages, infrastructure attributions, and evidence-ready analytical outputs.
- Act as a senior analyst across multiple active actors and campaigns at once, helping improve quality, share tradecraft, and informally support other analysts through strong analytical execution.
- Triage large indicator sets, cluster infrastructure, and turn fragmented signals into clear, defensible findings that stakeholders can act on immediately.
- Support incident responders, threat hunters, investigators, and partner-facing teams with timely, high-confidence intelligence products and briefings.
- Help evaluate new analytical tooling by pressure-testing it on real workflows and identifying where it meaningfully reduces analyst effort or improves output quality.
- Contribute to stronger investigation workflows, analytic standards, and repeatable methods that improve analyst throughput without sacrificing rigor.
WHAT WE'RE LOOKING FOR:
- 5+ years of experience in cyber threat intelligence, intelligence analysis, incident-driven investigations, or a closely related analytical field.
- AI fluency is required — you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce.
- A track record of driving complex investigations independently. You can walk us through a specific intrusion end-to-end — initial access through impact.
- Strong ability to combine direct collection and OSINT to deliver unique intelligence — resolving identities, aliases, and behavior across fragmented sources.
- Experience producing finished intelligence, such as actor profiles, campaign reporting, attribution assessments, and infrastructure mapping. Detection rules and threat feeds are a different discipline.
- Excellent judgment about analytical confidence and evidentiary strength: what can and cannot be defended in a report, a referral, or an operational setting.
- Excellent written and verbal communication — you can package a finding for a technical analyst and for a non-technical partner.
- AI fluency — you build your own tools and agentic workflows with AI tools like Claude to automate and scale investigative work, and you apply real human quality control to validate what they produce.
- Deep familiarity with cyber investigations, infrastructure attribution, campaign analysis, and actor profiling.
- A track record of independently driving complex investigations, improving workflows, and elevating the quality of analytical work around you.
- Comfort operating in a fast-paced environment where priorities can change quickly and ambiguity is normal.
PREFERRED QUALIFICATIONS
- Working proficiency in Russian, Chinese, or another language heavily used by cyber actors — particularly if you've used it operationally, in forums or persona work, rather than academically.
- A public presence: conference talks, published research, invite-only sharing circles.
- Hands-on crypto or blockchain tracing, and the ability to connect technical findings to financial infrastructure, including wallets, laundering paths, sanctions exposure, or identity-linked leads when relevant to the investigation.
ABOUT THE TEAM:
- TRM's Intelligence …
This role is provided by an external source. Applications are handled on the source website.
