TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
TRM's Blockchain Intelligence team is the world's leading source of actionable crypto crime intelligence — and scams are the fastest-growing threat category we track. As a Threat Intelligence Analyst specializing in scams, you will own TRM's intelligence production on pig butchering syndicates, romance fraud networks, and investment scam operations: tracing their infrastructure, uncovering their actors, and delivering leads and insights that directly influence how law enforcement and financial institutions fight back.
You will map the infrastructure behind global scam syndicates — tracing victim funds through complex laundering chains and building attribution that TRM's customers and law enforcement partners rely on to take action against some of the most prolific criminal networks operating today
You will produce Snap Leads, Timely Insights, and contribute to published reports reaching law enforcement agencies, financial institutions, and crypto businesses worldwide, directly influencing investigations and shaping industry understanding of the scam threat landscape
You will use AI tools — including Claude, Perplexity, and AI-assisted OSINT workflows — as core components of your research process to accelerate hypothesis generation, pattern recognition, and intelligence drafting at a pace manual methods cannot match
You will monitor global scam channels, forums, and social media platforms to surface proactive collection not visible through on-chain analysis alone, expanding TRM's proprietary attribution database with intelligence only TRM can provide
You will collaborate with TRM's GTM, Product, and Data teams to ensure your intelligence is embedded in the platform and reaches the customers who need it most
3+ years of experience in threat intelligence, fraud investigation, or crypto crime analysis, with demonstrated knowledge of scam ecosystems (pig butchering, romance fraud, investment fraud, or equivalent)
Working proficiency in blockchain analysis — you can trace funds, identify clusters, and use tools like TRM Investigator or Chainalysis Reactor to follow laundering chains and build attribution chains
A track record of producing actionable intelligence outputs: you have written leads, reports, or briefs that reached real operational consumers and influenced investigative or business decisions
Strong AI fluency — you use Claude, Perplexity, or equivalent tools as core parts of your research workflow; you can articulate specific ways AI has accelerated your work
Excellent written communication: you can write a BLUF-style intelligence report that a financial investigator, law enforcement analyst, or compliance officer can act on immediately
A self-starter mindset: at L4, you are expected to generate your own collection priorities, pursue investigative threads independently, and deliver substantive output without being told exactly what to look for
TRM's Blockchain Intelligence team combines the tradecraft of national security intelligence with the analytical depth of blockchain forensics — producing intelligence you will not find anywhere else in the industry
The team operates with high autonomy, a strong bias toward output, and direct access to the customers and law enforcement agencies who rely on the intelligence we produce
We work distributed, not distant — with structured async communication and regular syncs to align on collection priorities and share findings across the team
Expect high intellectual rigor, low bureaucracy, and fast iteration: you will go from an investigative thread to a published insight in days, not months
Team syncs on a regular cadence to align collection priorities and review in-progress investigations; exact schedule confirmed at intake
Primary time zone overlap is US Eastern/Central, with flexibility for international team members
Communication is async-first via Slack; Notion is used for documentation and playbook tracking
Distributed, not distant — team members are expected to proactively share findings and surface blockers rather than waiting for scheduled check-ins
We are building a safer world. That promise shows up in how we work every day.
TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.
Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.
At TRM, you should expect:
Priorities and targets to change quickly as we experiment and iterate
Work that often requires operating with a high degree of ambiguity
A high level of personal ownership and accountability
Close collaboration across teams and functions
Frequent, high-touch communication
Creative problem solving and out-of-the-box thinking
A pace that rewards urgency, adaptability, and outcomes
This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.
We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.
At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like
AI fluency is a baseline expectation at TRM.
We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.
At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:
Accelerate repeatable workflows
Structure and solve problems
Improve output quality
Increase speed and leverage
You will be evaluated on applied AI fluency during the interview process.
We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.
Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.
Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.
Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.
At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.
TRM is a Series C company with $220M in total funding, backed by Blockchain Capital, Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the TRM Privacy Policy.
Our typical hiring cycles for specialized roles span 24 to 36 months. Accordingly, we retain your personal information for up to 36 months to evaluate your application and to consider you for current and future employment opportunities, unless you request earlier deletion or a different retention period is required or permitted by law.
To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form.
TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.