Blockchain Intelligence Analyst (Ransomware)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote in the United States or United Kingdom; primary time zone overlap with US Eastern / Central. Surge availability is expected during time-sensitive disruption windows.
Salary: $115K–$150K annually, plus potential equity participation. Pay is benchmarked to the local market for the country where the role is based.
Company
provides AI-powered blockchain intelligence solutions that help public- and private-sector organizations investigate financial crime, disrupt illicit activity, and improve security.
What you will do
- Produce source-cited, auditable intelligence on ransomware actors, affiliates, facilitators, laundering pathways, and attribution assessments.
- Lead end-to-end blockchain investigations from seed indicators through attribution, actionable leads, and recovery or disruption opportunities.
- Trace funds across multiple blockchains, bridges, mixers, peel chains, nested services, and cash-out infrastructure.
- Correlate on-chain activity with OSINT, cyber threat intelligence, infrastructure research, identity signals, and adversary behavior.
- Partner with investigators, threat intelligence specialists, product teams, and public- and private-sector stakeholders.
- Mentor analysts, refine investigative tradecraft, improve repeatable workflows, and support external briefings and capability-building sessions.
Requirements
- 3–5+ years of professional experience in blockchain intelligence, crypto investigations, cybercrime analysis, threat intelligence, financial crime investigations, or a comparable senior analytical role.
- Deep hands-on experience tracing funds across multiple blockchains and through mixers, chain-hopping, bridges, peel chains, and layered cash-out behavior.
- Ability to independently conduct complex investigations and write clear investigative assessments, lead packages, fund-flow analyses, and attribution reports.
- Deep ransomware and cybercrime ecosystem expertise, including ransomware operators, affiliates, initial access brokers, malware developers, laundering networks, and cash-out services.
- Excellent written and verbal communication, strong judgment, curiosity, and the ability to work effectively in a fast-moving, high-stakes environment.
- AI fluency is required, including practical use of AI tools and large language models with critical evaluation of generated outputs.
Nice to have
- Experience in government, national security, law enforcement, incident response, or mature investigative and threat intelligence programs.
- HUMINT collection experience and engagement with threat actors through dark web forums or encrypted messaging platforms.
- Advanced knowledge of manual demixing, smart contracts, bridges, Ethereum- and TRON-based investigations, and OSINT data extraction.
- Experience with TRM, Maltego, Palantir, or similar investigative and structured-data platforms.
- Experience mentoring peers or shaping analytical standards and investigative workflows.
Culture & Benefits
- Distributed-first work model with remote collaboration and documented workflows in Notion and TRM investigative tools.
- Weekly team syncs and daily asynchronous Slack standups for targeting priorities, active work, returns, and target packages.
- High ownership, rapid iteration, frequent cross-functional communication, and a strong focus on clarity and measurable impact.
- Work at the intersection of AI, national security, blockchain intelligence, and crime disruption.
- Potential participation in TRM's equity plan.
Hiring process
- Applied AI fluency is evaluated during the interview process.
- AI tools such as interview notetakers, assistants, and real-time coaching tools are not permitted during interviews without prior approval.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →