
Blockchain Intelligence Analyst, Ransomware
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States, +1 more state.
• Generate comprehensive intelligence on ransomware actors, affiliates, facilitators, and laundering methods.
• Oversee intricate end-to-end blockchain investigations, guiding them from initial indicators to attribution and opportunities for recovery or disruption.
• Track ransomware funds across various blockchains, bridges, mixers, peel chains, and nested services.
• Connect on-chain activities with OSINT, threat intelligence, partner data, and off-chain identity or infrastructure signals.
• Manage investigative workflows from discovery to validation, escalation, and written documentation.
• Identify leads and opportunities for seizure or freezing to assist with ransomware asset recovery.
• Prioritize investigative tasks, uphold analytical standards, and mentor analysts in an informal capacity.
• Collaborate with investigators, threat intelligence teams, product teams, and partners from both public and private sectors.
• Enhance ransomware coverage, investigative methodologies, lead-generation processes, and asset-recovery support.
• Assist in external briefings, customer interactions, and capacity-building sessions.
• Engage in weekly team meetings and daily asynchronous Slack standups.
• Record findings in Notion and TRM investigative tools.
• Provide availability during critical disruption periods.
• 3–5+ years of professional experience in blockchain intelligence, cryptocurrency investigations, cybercrime analysis, threat intelligence, financial crime investigations, or a similar senior analytical position.
• Extensive hands-on experience with blockchain tracing across multiple platforms.
• Proficient in tracing laundering and obfuscation techniques, including mixers, chain-hopping, bridges, peel chains, and complex cash-out behaviors.
• Capable of independently conducting sophisticated investigations and producing investigative assessments, lead packages, fund-flow analyses, and attribution reports.
• In-depth knowledge of the ransomware domain, including understanding ransomware operators, affiliates, initial access brokers, malware developers, laundering networks, and cash-out services.
• Exceptional written and verbal communication abilities.
• Strong judgment, curiosity, and execution skills in fast-paced, high-stakes environments.
• Experience with AI tools and large language models, with the ability to critically assess AI-generated results.
• Familiarity with OSINT, cybercrime infrastructure research, and cross-domain analytical techniques.
• Preferred: experience in government, national security, law enforcement, incident response, or advanced investigative/threat-intelligence programs.
• Preferred: knowledge of TRM, Maltego, Palantir, or similar platforms.
• Preferred: experience in HUMINT collection and engaging threat actors through dark web forums and encrypted messaging platforms.
• Preferred: mentoring colleagues and enhancing investigative workflows.
• Preferred: practitioner-level understanding of manual demixing, smart contracts, bridges, Ethereum- and TRON-based investigations, and OSINT-based data extraction.
• Must have primary time-zone overlap with US Eastern/Central.
• Availability during critical disruption periods is essential.
• Eligibility for an equity plan.
• Competitive benefits package.
• Access to wellness programs.
• Time off from work.
• Reasonable accommodations for applicants with disabilities.
• Distributed-first/remote work environment.
Kodex
DarkTower
AlertMedia
ZeroFox
Get handpicked remote jobs straight to your inbox weekly.