- Location
- Bengaluru, India
- Workplace
- Onsite
- Type
- Full-time
- Department
- Security
- Experience
- 5+ years
- Education
- Master
- Source
- Workday
Description
About the team
About the teamZillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe.
Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India.
About the role
About the Role
We're looking for an Information Security Analyst to be a core contributor to our security operations and incident response capabilities. In this role, you'll own the day-to-day SOC workload — triaging and resolving security alerts, investigating incidents, and executing response playbooks — while also taking on moderate-complexity incident response investigations with increasing independence.
You bring enough experience to work independently on most security events, make sound triage decisions, and know when to escalate. You contribute to playbook improvements, support other analysts, and partner with other teams during incident response.
You Will Get To
Security Operations
Monitor, triage, and resolve tier-1 and tier-2 SOC tickets across endpoints, identity, cloud, network, and application sources.
Investigate security alerts from SIEM, EDR, and cloud security platforms, accurately assessing severity and scope.
Execute incident response playbooks for scenarios such as phishing, account compromise, endpoint alerts, and cloud alerts.
Serve as an escalation point for other analysts, helping guide triage and investigation decisions.
Maintain accurate documentation of all investigations, response actions, and outcomes.
Incident Response
Lead response on low-to-moderate complexity security incidents, owning investigation from detection through containment, remediation, and post-mortem documentation.
Investigate a broad range of incident types including identity attacks, phishing, SaaS events, cloud attacks, supply chain alerts, and endpoint compromises.
Conduct forensic analysis of compromised systems across Windows, macOS, Linux, and cloud environments, preserving evidence and documenting findings.
Participate in on-call rotation for after-hours security incidents, escalating to senior responders when appropriate.
Contribute to post-incident reports and root cause analyses, capturing lessons learned and recommending improvements.
Cloud Security
Investigate AWS security alerts such as GuardDuty findings, CloudTrail anomalies, IAM events, and compute events.
Apply cloud security knowledge to scope and contain incidents in AWS environments, partnering with senior responders and engineers on complex cloud investigations.
Detection and Continuous Improvement
Analyze threat intelligence and monitor for indicators of compromise relevant to Zillow's environment.
Contribute to detection logic refinement and playbook updates based on investigation findings and emerging threats.
Participate in tabletop exercises and help identify gaps in the team's response capabilities.
Collaborate with detection engineering to tune out false positives and improve alert fidelity.
Drive continuous improvement to the cyber defense program through lessons learned, process automation, tooling enhancements, post-incident follow-through and other duties as required.
Partner with cloud and platform engineering on containment actions and long-term security hardening recommendations.
Who you are
5+ years of experience in cybersecurity, with hands-on experience in security operations, SOC, or incident response.
Proven ability to independently investigate and resolve moderate-complexity security incidents — you don't need step-by-step guidance on standard event types.
Working knowledge of AWS security services (GuardDuty, CloudTrail, IAM, S3, EC2) and experience investigating cloud-based security events.
Proficiency with SIEM platforms (e.g., Exabeam, Splunk) and EDR tools (e.g., CrowdStrike).
Solid understanding of attacker TTPs and the MITRE ATT&CK framework, with the ability to apply them during active investigations.
Experience investigating identity-based attacks including Okta and AD attacks, phishing, account compromise, and MFA abuse.
Understanding of Windows, macOS, and Linux environments and common forensic artifacts — logs, process activity, and persistence mechanisms.
Familiarity with scripting (Python, Bash, or PowerShell) for basic automation and investigation tasks.
Clear written and verbal communication — you document thoroughly and keep stakeholders informed during incidents.
Sound judgment on when to drive to resolution independently versus when to escalate to senior responders.
Plus: Background in IT systems administration, software engineering, or a technical field — helpful for cross-team collaboration and understanding the environments you're defending.
Plus: Experience with SOAR platforms or automated response workflows.
Plus: Relevant certifications: Security+, CySA+, GCIH, GCFR, AWS SSA.
Get to know us
At Zillow, we’re reimagining how people move—through the real estate market and through their careers.
As the most-visited real estate platform in the U.S., Zillow helps millions of customers navigate buying, selling, financing, and renting with greater ease and confidence. Our teams in India play a critical role in building and scaling the technology, products, and operations that power this experience.
Whether you’re working in tech, operations, or shared services, you’ll collaborate with global partners to solve meaningful problems and help more people make home a reality.
Zillow is honored to be recognized among the best workplaces in the U.S.. Zillow was named one of FORTUNE 100 Best Companies to Work For® in 2025, and included on the PEOPLE Companies That Care® 2025 list, reflecting our commitment to creating an innovative, inclusive, and engaging culture where employees are empowered to grow.
No matter where you sit in the organization, your work will help drive innovation, support our customers, and move the industry—and your career—forward, together.
Zillow Group is an equal opportunity employer committed to fostering an inclusive, innovative environment with the best employees. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, maternity status, HIV status, or veteran status. Reasonable accommodations will be provided to candidates with disabilities, in accordance with applicable policies.