Hiring.Camp

Information Security Analyst

Zillow

·

Today

Location
Bengaluru, India
Workplace
Onsite
Type
Full-time
Department
Security
Experience
5+ years
Education
Master
Source
Workday

Description

About the team

About the team
Zillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe.

Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India.

About the role

About the Role
We're looking for an Information Security Analyst to be a core contributor to our security operations and incident response capabilities. In this role, you'll own the day-to-day SOC workload — triaging and resolving security alerts, investigating incidents, and executing response playbooks — while also taking on moderate-complexity incident response investigations with increasing independence.

You bring enough experience to work independently on most security events, make sound triage decisions, and know when to escalate. You contribute to playbook improvements, support other analysts, and partner with other teams during incident response.
 

You Will Get To

Security Operations

  • Monitor, triage, and resolve tier-1 and tier-2 SOC tickets across endpoints, identity, cloud, network, and application sources.

  • Investigate security alerts from SIEM, EDR, and cloud security platforms, accurately assessing severity and scope.

  • Execute incident response playbooks for scenarios such as phishing, account compromise, endpoint alerts, and cloud alerts.

  • Serve as an escalation point for other analysts, helping guide triage and investigation decisions.

  • Maintain accurate documentation of all investigations, response actions, and outcomes.

Incident Response

  • Lead response on low-to-moderate complexity security incidents, owning investigation from detection through containment, remediation, and post-mortem documentation.

  • Investigate a broad range of incident types including identity attacks, phishing, SaaS events, cloud attacks, supply chain alerts, and endpoint compromises.

  • Conduct forensic analysis of compromised systems across Windows, macOS, Linux, and cloud environments, preserving evidence and documenting findings.

  • Participate in on-call rotation for after-hours security incidents, escalating to senior responders when appropriate.

  • Contribute to post-incident reports and root cause analyses, capturing lessons learned and recommending improvements.

Cloud Security

  • Investigate AWS security alerts such as GuardDuty findings, CloudTrail anomalies, IAM events, and compute events.

  • Apply cloud security knowledge to scope and contain incidents in AWS environments, partnering with senior responders  and engineers on complex cloud investigations.

Detection and Continuous Improvement

  • Analyze threat intelligence and monitor for indicators of compromise relevant to Zillow's environment.

  • Contribute to detection logic refinement and playbook updates based on investigation findings and emerging threats.

  • Participate in tabletop exercises and help identify gaps in the team's response capabilities.

  • Collaborate with detection engineering to tune out false positives and improve alert fidelity.

  • Drive continuous improvement to the cyber defense program through lessons learned, process automation, tooling enhancements, post-incident follow-through and other duties as required.

  • Partner with cloud and platform engineering on containment actions and long-term security hardening recommendations.

This role has been categorized as an Office position. “Office” employees regularly work at the Zillow India office for approximately 80 to 100 percent of their time each month. Employees must live within a reasonable commuting distance of the office. Zillow has not defined a reasonable distance, and expects employees will use judgment in determining this for themselves and understand the implications re: time commitment and cost of daily commute.

In addition to a competitive base pay, employees in this role are eligible for incentive compensation subject to applicable laws and relevant Zillow policies. Actual amounts will vary depending on experience, performance and location.

Who you are

  • 5+ years of experience in cybersecurity, with hands-on experience in security operations, SOC, or incident response.

  • Proven ability to independently investigate and resolve moderate-complexity security incidents — you don't need step-by-step guidance on standard event types.

  • Working knowledge of AWS security services (GuardDuty, CloudTrail, IAM, S3, EC2) and experience investigating cloud-based security events.

  • Proficiency with SIEM platforms (e.g., Exabeam, Splunk) and EDR tools (e.g., CrowdStrike).

  • Solid understanding of attacker TTPs and the MITRE ATT&CK framework, with the ability to apply them during active investigations.

  • Experience investigating identity-based attacks including Okta and AD attacks, phishing, account compromise, and MFA abuse.

  • Understanding of Windows, macOS, and Linux environments and common forensic artifacts — logs, process activity, and persistence mechanisms.

  • Familiarity with scripting (Python, Bash, or PowerShell) for basic automation and investigation tasks.

  • Clear written and verbal communication — you document thoroughly and keep stakeholders informed during incidents.

  • Sound judgment on when to drive to resolution independently versus when to escalate to senior responders.

  • Plus: Background in IT systems administration, software engineering, or a technical field — helpful for cross-team collaboration and understanding the environments you're defending.

  • Plus: Experience with SOAR platforms or automated response workflows.

  • Plus: Relevant certifications: Security+, CySA+, GCIH, GCFR,  AWS SSA.

Get to know us

At Zillow, we’re reimagining how people move—through the real estate market and through their careers. 

As the most-visited real estate platform in the U.S., Zillow helps millions of customers navigate buying, selling, financing, and renting with greater ease and confidence. Our teams in India play a critical role in building and scaling the technology, products, and operations that power this experience.

Whether you’re working in tech, operations, or shared services, you’ll collaborate with global partners to solve meaningful problems and help more people make home a reality.

Zillow is honored to be recognized among the best workplaces in the U.S.. Zillow was named one of FORTUNE 100 Best Companies to Work For® in 2025, and included on the PEOPLE Companies That Care® 2025 list, reflecting our commitment to creating an innovative, inclusive, and engaging culture where employees are empowered to grow.

No matter where you sit in the organization, your work will help drive innovation, support our customers, and move the industry—and your career—forward, together.

Zillow Group is an equal opportunity employer committed to fostering an inclusive, innovative environment with the best employees. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, maternity status, HIV status, or veteran status. Reasonable accommodations will be provided to candidates with disabilities, in accordance with applicable policies.

Skills

PythonAWSLinuxCybersecuritySIEMSOCSplunk

Similar Jobs

30

Information Security Analyst

ONYX Insight · Nottingham, GB

Yesterday

Information Security Analyst

Bostonpartners · Boston, United States of America

2 days ago

Information Security Analyst

Global Payments · Pune, India · Onsite

5 days ago

Information Security Analyst

Omnissa · USA-GA, United States of America · Remote

1 week ago

Information Security Analyst

Yakimacounty · Technology Services, United States of America

1 week ago

Information Security Analyst

Yakimacounty · Technology Services, United States of America

1 week ago

Information Security Analyst

Corporate Careers · IAA Building B, United States of America +2 · Onsite

1 week ago

Information Security Analyst

Join the connected world of Assurant · Buenos Aires (Alem), Argentina

1 week ago

Information Security Analyst

NextGen Federal Systems · Washington, District of Columbia · Onsite

1 week ago

Analyst, Information Security

Melcoresorts · City of Dreams Manila, Philippines

1 week ago

Information Security Analyst

Eurofins Scientific · Bengaluru, KA, India

2 weeks ago

Information Security Analyst

Rockwellautomation · Mexico Mexico City +2 · Hybrid

2 weeks ago

Information Security Analyst

Rockwell Automation · Mexico Mexico City +2 · Hybrid

2 weeks ago

Information Security Analyst

Vesync · Tustin, CA · Onsite

2 weeks ago

Information Security Analyst

"NEPC, LLC" · Boston, MA

2 weeks ago

Information Security Analyst

Octanner · USA - Utah-Salt Lake City-Headquarters, United States of America

3 weeks ago

Information Security Analyst

Itron here · Budapest, Hungary (Local Office) · Hybrid

3 weeks ago

Information Security Analyst

Crown Agents Bank · London, England, United Kingdom

3 weeks ago

Information Security Analyst

Jadin Tech · Colorado Springs, CO

3 weeks ago

Information Security Analyst

Profound · Buenos Aires, Argentina · Onsite

4 weeks ago

Information Security Analyst

Didomi · Paris,France · Remote

1 month ago

Information Security Analyst

Southern First Bank · Greenville, SC

1 month ago

Information Security Analyst

Foresters Financial · Toronto, Canada

1 month ago

Information Security Analyst

Employees Swissportglobal · Cheshire-Runcorn, UK

1 month ago

Information Security Analyst

FBT Gibbons · Louisville, KY +4

1 month ago

Information Security Analyst

Sancorp Consulting LLC · Arlington, VA

1 month ago

Information Security Analyst

Toyota · Toyota Credit Canada Inc - Head Office

1 month ago

Information Security Analyst

Computershare · Bristol, United Kingdom, GB · Hybrid

1 month ago

Information Security Analyst

Erm · New Delhi, India +1

1 month ago

Information Security Analyst

Bdo · Toronto - Wellington St, Canada

1 month ago