Global Investigations, Sextortion
Job description
Global Investigations, Sextortion at Trm Labs.
About the role
You will own the end-to-end lifecycle of high-impact sextortion investigations, driving cases from initial lead validation through to suspect identification, evidence packaging, and disruption. You will act as the primary technical and analytical lead within the Global Investigations team, leveraging open-source intelligence and financial tracing to build comprehensive targeting packages. In this role, you will directly coordinate with major law enforcement partners and global platform teams to ensure investigative outputs are actionable and court-ready. You will be accountable for maintaining the integrity, speed, and discretion required in cases involving child exploitation and financial crime. The position requires a high degree of ownership over complex, ambiguous investigations where decisions directly affect victim safety and suspect apprehension. You will translate raw data and reports into clear narratives that support rapid legal and enforcement actions.
Key facts
What you'll do
- Lead end-to-end OSINT-driven investigations targeting sextortion actors, mapping their aliases, personas, infrastructure, and social-media footprints across the open web and encrypted channels.
- Follow the money across the payment rails this threat actually uses, including consumer payment apps, gift cards, and cryptocurrency where cases are crypto-enabled, and translate findings into legal process requests.
- Pivot on strategic selectors - such as a handle, phone number, email, username, image, domain, account, or a cryptocurrency address - to expand a single report into a broad surrounding network.
- Produce high-quality, actionable targeting packages that connect OSINT findings, financial evidence, and victim reporting to identify responsible actors and enable law-enforcement action and platform takedowns.
- Validate time-sensitive victim and infrastructure signals, triage leads by confidence level, and move high-priority matters through established escalation workflows with precision and urgency.
- Drive victim safety outcomes by supporting and coordinating appropriate outreach and remediation activities in collaboration with partner agencies and platform teams.
- Operate within integrated workflows from AI-supported triage of inbound reporting to fast, high-stakes investigation, targeting, and disruption in coordination with NCMEC, IC3, U.S. and international partners, and platform/consortium intel networks.
- Apply creative tactical thinking to pivot across platforms, payment methods, and identifiers when standard paths go cold, maintaining momentum without sacrificing accuracy.
- Use AI tools to synthesize large volumes of data, cluster leads, draft investigative outputs, and accelerate analysis while documenting how these tools materially improve speed and quality.
- Maintain strict discretion and care when handling sensitive material, ensuring all outputs meet the rigor required for formal legal, compliance, and enforcement workflows.
- Build and manage complex cases that can support formal legal processes, compliance escalations, platform referrals, and asset-preservation activities.
- Continuously refine operational playbooks based on evolving threat actor behaviors, emerging platforms, and lessons learned from completed investigations.
Requirements
- Hold US citizenship and be able to obtain Public Trust clearance.
- Possess law-enforcement experience as a current, former, or retired professional, including sworn officers or investigators from state, local, or federal backgrounds.
- Have demonstrated background in ICAC task forces or similar cybercrime, child-exploitation, financial-crime, or digital-investigations teams.
- Bring proven OSINT investigation experience identifying online actors, aliases, accounts, infrastructure, communication patterns, and linked personas.
- Show financial-investigations experience tracing payment apps, gift cards, and crypto-enabled flows to follow funds across platforms and identify actionable selectors.
- Have a strong understanding of sextortion and victim-centered cybercrime investigations, managing sensitivity, urgency, and victim impact without losing rigor.
- Be familiar with legal-process mechanisms such as preservation requests, subpoenas, and 2703(d) orders, including drafting requests and interpreting returns.
- Have a minimum of 5-7 years of investigative experience across relevant domains such as OSINT, cybercrime, crypto investigations, asset recovery, law enforcement, trust and safety, or blockchain analytics.
- Demonstrate experience producing investigative packages that support formal legal, compliance, platform escalation, asset-preservation, or enforcement workflows.
- Exhibit a bias to action, figuring out the first move when handed something new and persisting when the playbook ends.
- Show creative tactical thinking, pivoting from selectors like handles, wallets, images, phone numbers, emails, transactions, or platform accounts into a broader network view.
- Display AI fluency with concrete examples of how AI tools have been used to synthesize returns, cluster leads, draft outputs, and accelerate investigative speed.
Nice to have
- Prior experience with TRM Labs platforms or financial-intelligence tools.
- Background in building or influencing threat intelligence sharing consortia.
- Familiarity with international liaison networks or cross-jurisdictional investigation practices.
Practical notes
- This is a full-time position located in the United States.
- Travel may be required depending on case needs and operational priorities.
- Visa sponsorship may be considered for qualified candidates where applicable.
- Applicants must be able to meet all position requirements and pass relevant background checks.