Protecting one billion people from cyber threats? If you find this proposition more exciting than scary, come on board and grow with us.
Whalebone is a global company working on user-centric cybersecurity products for telcos, ISPs, enterprises, public institutions, and governments that provide millions of everyday internet users unyielding protection from malware, phishing schemes, ransomware, and other malicious digital attacks without the need for them to download anything. Whalebone is headquartered in Brno, Czech Republic.
At this point, Whalebone has 400+ customers in telecommunications and corporate sectors (A1, O2 Telefonica, Tele2, Panasonic, Bauhaus, and many others) around the globe. With over 160 team members of multiple nationalities, Whalebone ranked 22nd in Deloitte’s list of fastest-growing companies in Central Europe.
We create cybersecurity products that people can actually use. We protect them against viruses and fraud on the network so that the users do not have to handle anything.
Thanks to this approach, we already protect tens of millions of people worldwide. Become a significant part of an important and ambitious project as a Threat Intelligence Specialist.
About the team
Whalebone's Threat Intelligence team protects millions of users at the DNS layer, including through DNS4EU, the European public DNS resolver. We see DNS traffic at a scale few teams in Europe get to work with, and we turn it into detections, threat indicators, and published research.
The team is small and senior: you'd be the third specialist alongside two experienced threat intelligence analysts. There is no alert queue and no ticket conveyor, we hunt, we design detections, and we publish. Our environment is Python-first with ClickHouse and Elasticsearch for analysis; when a proof-of-concept works, a dedicated platform team takes it to production, so your time stays
Responsibilities
- Hunt proactively in our DNS telemetry and PassiveDNS data, form hypotheses about attacker behavior, test them against the data, and chase what you find
- Pivot on indicators across OSINT, commercial feeds, and internal telemetry to uncover campaigns and attacker infrastructure
- Turn findings into new detection approaches from idea to working proof-of-concept
- Track the global threat landscape (malware families, cybercrime, nation-state activity) and assess what it means for our customers
- Publish your research: blog posts, threat intelligence reports, indicators, briefings, and conference talks if that's your thing
How we measure success
We're transparent about evaluation from day one:
- Your hunts produce findings that become production detections and threat indicators
- Detection efficacy improves against independent benchmarks
- Your research gets published and builds the team's and your own external reputation
Requirements
Several years of hands-on security experience – e.g., SOC L2/L3, incident response, network security monitoring / NDR, malware analysis, detection engineering, or security research
- A hunter's mindset: hypothesis-driven, curious, comfortable with ambiguity, able to tell "weird but benign" from "quiet but malicious"
- Solid knowledge of current adversary techniques and the threat landscape
- Ability to get answers out of data, Python and SQL as working tools; AI-assisted workflows are perfectly fine, we're not hiring a developer
- Ability to communicate findings clearly, in writing and in person
Nice to have
- DNS knowledge or experience with network telemetry at scale
- Threat intelligence tooling: MISP, VirusTotal, urlscan, or similar pivoting platforms
- Tracking threat actors, campaigns, and TTPs using frameworks such as MITRE ATT&CK
- Basics of statistics or machine learning for evaluating detection quality
No TI or DNS background? Apply anyway.
DNS internals and threat intelligence workflows are exactly the things we can teach quickly. Deep security instincts, hunting discipline, and curiosity are what we can't, and that's what we're hiring for.
Why work with us?
Meaningful job helping the company scale and shape a brand-new role
- 20+5 vacation days, a rewarding financial package, performance bonuses, and the option to choose ESOP as a benefit
- Office-based company culture with home office options, up to 4 sick days annually based on your selected working setup, and up to two weeks of Work From Anywhere each year
- You will be supported to learn, grow, and gain new experiences with us
- Regular events & team buildings – grill, enjoy pub quizzes, or have breakfast with us
- Your opinion will matter to us – discuss your ideas and feedback directly with the CEO or CTO if you feel they should hear them
- Mobile phone tariff available for friends and family members
- Access to the ALZA special benefits program
- Multisport Card available through the company program
- 15% discount on all coffee products on the Coffeespot e-shop
- Access to wellbeing support through Hedepy
Position details
- Team: Threat Intelligence
- Work setup: Onsite
- Location: Jezuitská 14/13, Brno, Czech Republic
Job type: Full-time
Apply now and help us protect the online world around us!