Senior Blockchain Intelligence Analyst – Ransomware

🕒 July 28

🇺🇸 United States – Remote

💵 $150k - $168k / year

⏰ Full Time

🟠 Senior

🕵️ Threat Intelligence Specialist

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of TRM Labs

TRM Labs

201 - 500 employees

Founded 2018

₿ Crypto

📋 Compliance

🤝 B2B

Crypto • Compliance • B2B

TRM Labs is a blockchain intelligence company that provides transaction-monitoring, forensics, and compliance solutions for businesses and public-sector organizations dealing with cryptocurrencies. Their platform and products (examples: Compliance360, Investigation360, Seizure360, Supervision360, BlockInt API, MCP, wallet screening, Know-Your-Asset) help banks, crypto firms, regulators, law enforcement, and tax authorities detect, investigate, and block illicit crypto activity, support seizures, and meet AML/CTF and supervision requirements. TRM also offers training and certification (TRM Academy) and professional services such as incident response and capacity development.

📋 Description

• Produce impactful finished intelligence on ransomware actors, affiliates, facilitators, and laundering pathways, including actor profiles, lead packages, attribution assessments, and operational reporting suitable for investigative, executive, and partner audiences. • Lead complex end-to-end blockchain investigations from initial seed indicators such as victim payment addresses, deposit addresses, transactions, exchange exposure, infrastructure leads, or IP-linked activity through to full attribution and actionable recovery or disruption opportunities. • Trace ransomware-related funds across multiple blockchains, bridges, mixers, peel chains, and nested services, identifying controllers, counterparties, cash-out services, and recovery touchpoints. • Correlate on-chain activity with OSINT, threat intelligence, attribution partner data, and off-chain identity or infrastructure signals to build a complete picture of adversary behavior within the broader cybercrime ecosystem. • Own investigative workstreams from discovery through validation, escalation, and written production, including drafting intelligence products that are source-cited, auditable, and operationally useful. • Support TRM’s ransomware asset recovery mission by surfacing high-quality leads, identifying seizure or freeze opportunities, and helping partners move quickly before funds are off-ramped. • Drive analytical leadership across active ransomware investigations by prioritizing work, maintaining rigorous standards, and mentoring other analysts without formal people management responsibilities. • Partner closely with internal and external stakeholders, including investigators, threat intelligence teammates, product teams, and public-sector or private-sector partners, to ensure analytical outputs reflect real investigative tradecraft and support cross-functional operations. • Help strengthen TRM’s ransomware coverage by contributing new attribution, refining investigative methodologies, and improving repeatable workflows for lead generation and asset recovery support. • Support external briefings, customer or partner engagements, and capability-building sessions where ransomware tracing, attribution, and recovery tradecraft must be explained clearly and credibly.

🎯 Requirements

• 5-8+ years of professional experience in blockchain intelligence, crypto investigations, cybercrime analysis, threat intelligence, financial crime investigations, or a comparable senior analytical role. • Blockchain tracing expertise — Deep hands-on experience tracing funds across multiple blockchains and through laundering or obfuscation techniques such as mixers, chain-hopping, bridges, peel chains, and layered cash-out behavior. • Extensive investigative tradecraft — Demonstrated ability to independently run complex investigations and synthesize findings into clear written intelligence products, including investigative assessments, lead packages, fund-flow analysis, and attribution reporting. • Ransomware domain expertise — including a deep understanding of the broader cybercrime ecosystem and the relationships among ransomware operators, affiliates, initial access brokers, malware developers, laundering networks, and cash-out services. • Excellent written and verbal communication — especially the ability to turn technically complex tracing findings into understandable, actionable intelligence for government and private-sector audiences. • Judgment and execution — Strong judgment, curiosity, and the ability to operate effectively in a fast-moving, high-stakes environment where timing matters and outputs must still stand up to scrutiny. • AI fluency — Experience leveraging AI tools and large language models (LLMs) to accelerate research, surface insights, and augment analytical workflows, with the ability to critically evaluate AI-generated outputs for accuracy and relevance.

🏖️ Benefits

• Individual pay is determined by skills, qualifications, experience, and location. Salary ranges are benchmarked to local market rates for the country in which this role is based. • We do not ask candidates about salary history at any stage of the hiring process. • This role may also be eligible to participate in TRM's equity plan

Apply Now

Similar Jobs

🕒 July 20

LMI

1001 - 5000

📦 Logistics

🏥 Healthcare

🎖️ Defense

Logistics Operations Center Global Operations and Intel Analyst at LMI supporting Army logistics. Involves operational planning, situational awareness, and executive decision support in a remote role.

🇺🇸 United States – Remote

💵 $100k - $135k / year

⏰ Full Time

🟠 Senior

🔴 Lead

🕵️ Threat Intelligence Specialist

🦅 H1B Visa Sponsor

infoinfo

🕒 April 1

PUNCH Cyber Analytics Group

11 - 50

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Cyber Threat Intelligence Analyst at PUNCH consulting clients to expand CTI programs. Required significant cybersecurity experience and expertise in Microsoft ecosystems.

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

🕵️ Threat Intelligence Specialist

🕒 March 31

People and Technology

51 - 200

📦 Logistics

🏭 Manufacturing

💼 Consulting

Intelligence Analyst utilizing military expertise for execution of business best-practices. Long-distance telecommuting is possible, focusing on supply chain logistics experience.

🇺🇸 United States – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🕵️ Threat Intelligence Specialist

🕒 January 27

Control Risks

1001 - 5000

📦 Logistics

📣 Marketing

✈️ Travel

Senior Cyber Threat Intelligence Analyst focusing on triaging cyber events and conducting threat hunting. Collaborating with the SOC team to enhance defense strategies against cyber threats.

🇺🇸 United States – Remote

💵 $120k - $140k / year

💰 Private Equity Round on 2011-03

⏰ Full Time

🟠 Senior

🕵️ Threat Intelligence Specialist

🦅 H1B Visa Sponsor

infoinfo

🕒 November 10, 2025

Tryaq

1 - 10

💼 Consulting

🔒 Cybersecurity

☁️ SaaS

Threat Intelligence Specialist for a cybersecurity company focusing on dark web and threat intelligence operations. Required skills in Python, analytical skills, and knowledge of cybercrime.

🇺🇸 United States – Remote

💰 $400k Pre Seed Round - Tryaq on 2025-03

⏰ Full Time

🟡 Mid-level

🟠 Senior

🕵️ Threat Intelligence Specialist