About The Team
Zillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe.
Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India.
About The Role
We are seeking a highly skilled and motivated SOC Security Analyst to join our cybersecurity team. In this role, you will be responsible for protecting our organization's digital assets through proactive investigation, detection, and response strategies. Utilizing your expertise in incident response, forensic analysis, and threat intelligence, you will drive efforts to safeguard our systems against malicious actors and security vulnerabilities.
This role is pivotal in implementing advanced security measures, managing incident response playbooks, and ensuring the organization remains resilient against emerging threats.
You Will Get To:
Security Operations
- Monitor, triage, and resolve SOC tickets across endpoints, identity, cloud, network, and application sources.
- Investigate security alerts from SIEM, EDR, and cloud security platforms, assessing severity and scope with support from senior analysts on ambiguous cases.
- Execute established incident response playbooks for common scenarios such as phishing, account compromise, endpoint alerts, and cloud alerts.
- Reach a clear verdict — malicious, benign, or needs escalation — and get to root cause on the alerts you own.
- Maintain accurate, thorough documentation of every investigation, response action, and outcome.
Incident Response Support
- Support incident response on security incidents, taking assigned investigative workstreams and reporting findings back to the incident lead.
- Gain exposure to a broad range of incident types including identity attacks, phishing, SaaS events, cloud alerts, and endpoint compromises.
- Collect and preserve evidence from compromised systems across Windows, macOS, Linux, and cloud environments under the guidance of senior responders.
- Participate in on-call rotation for security alerts, following documented escalation paths.
- Contribute investigation timelines and technical detail to post-incident reports.
Cloud Security
- Triage AWS security alerts such as GuardDuty findings, CloudTrail anomalies, and IAM events using established playbooks.
- Build working knowledge of AWS security services and partner with senior responders and engineers on cloud investigations.
Learning and Continuous Improvement
- Monitor threat intelligence for indicators of compromise relevant to Zillow's environment.
- Flag false positives, noisy alerts, and playbook gaps to detection engineering so we can improve alert fidelity.
- Participate in tabletop exercises and team training sessions to build investigation skills.
- Contribute to the cyber defense program through documentation improvements, process automation, post-incident follow-through, and other duties as required.
- Continuous improvement throughout Zillow’s security program as required
This role has been categorized as an Office position. “Office” employees regularly work at the Zillow India office for approximately 80 to 100 percent of their time each month. Employees must live within a reasonable commuting distance of the office. Zillow has not defined a reasonable distance, and expects employees will use judgment in determining this for themselves and understand the implications re: time commitment and cost of daily commute.
In addition to a competitive base pay, employees in this role are eligible for incentive compensation subject to applicable laws and relevant Zillow policies. Actual amounts will vary depending on experience, performance and location.
Who you are
Qualifications
- Education: Bachelor’s degree in Computer Science, Cybersecurity, or related field; relevant certifications (Security+, CySA+, GCIH, AWS SAA) preferred.
- Experience:
- 3+ years in IT, or cybersecurity with a focus on incident response and threat intelligence.
- Strong knowledge of AWS security, cloud incident response, and forensic analysis tools.
- Knowledge of multiple computing platforms, such as Windows, MacOS, Linux, and networks.
- Proficiency in SIEM tools, such as Exabeam, and endpoint detection tools, such as CrowdStrike.
- Skills:
- Expertise in scripting and automation for security operations (Python, PowerShell, etc.).
- Familiarity with regulatory compliance frameworks and secure coding practices.
- Deep understanding of MITRE ATT&CK framework and common attack vectors.
- Exceptional problem-solving and analytical abilities.
- Strong communication skills to effectively collaborate with technical and non-technical teams.
Get to know us
At Zillow, we’re reimagining how people move—through the real estate market and through their careers. As the most-visited real estate platform in the U.S., we help people navigate buying, selling, financing and renting with greater ease and confidence. Whether you're working in tech, sales, operations, or design, you’ll be part of a company reshaping an industry and helping more people make home a reality.
Zillow is honored to be recognized among the best workplaces in the U.S. Zillow was named one of FORTUNE 100 Best Companies to Work For® in 2026, and included on TIME’s America’s Best Companies 2026 list, reflecting our commitment to creating an innovative, inclusive, and engaging culture where employees are empowered to grow.
No matter where you sit in the organization, your work will help drive innovation, support our customers, and move the industry—and your career—forward, together.
Zillow Group is committed to fostering an inclusive, innovative environment and to providing equal employment opportunities. We comply with applicable laws that prohibit discrimination in employment and recruitment.
If you have a disability or special need that requires accommodation during the recruitment process, please contact your recruiter directly.
Qualified applicants will be considered for employment in accordance with applicable law.