Cyber Defense SOC Analyst at Zillow in Bengaluru
- Company: Zillow
- Location: Bengaluru
- Job type: full time
- Workplace: onsite
- Posted: 2026-09-10
Job description
About the team Zillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe. Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India. About the role We are seeking a highly skilled and motivated SOC Security Analyst to join our cybersecurity team. In this role, you will be responsible for protecting our organization's digital assets through proactive investigation, detection, and response strategies. Utilizing your expertise in incident response, forensic analysis, and threat intelligence, you will drive efforts to safeguard our systems against malicious actors and security vulnerabilities. This role is pivotal in implementing advanced security measures, managing incident response playbooks, and ensuring the organization remains resilient against emerging threats. You Will Get To: Security Operations Monitor, triage, and resolve SOC tickets across endpoints, identity, cloud, network, and application sources. Investigate security alerts from SIEM, EDR, and cloud security platforms, assessing severity and scope with support from senior analysts on ambiguous cases. Execute established incident response playbooks for common scenarios such as phishing, account compromise, endpoint alerts, and cloud alerts. Reach a clear verdict — malicious, benign, or needs escalation — and get to root cause on the alerts you own. Maintain accurate, thorough documentation of every investigation, response action, and outcome. Incident Response Support Support incident response on security incidents, taking assigned investigative workstreams and reporting findings back to the incident lead. Gain exposure to a broad range of incident types including identity attacks, phishing, SaaS events, cloud alerts, and endpoint compromises. Collect and preserve evidence from compromised systems across Windows, macOS, Linux, and cloud environments under the guidance of senior responders. Participate in on-call rotation for security alerts, following documented escalation paths. Contribute investigation timelines and technical detail to post-incident reports. Cloud Security Triage AWS security alerts such as GuardDuty findings, CloudTrail anomalies, and IAM events using established playbooks. Build working knowledge of AWS security services and partner with senior responders and engineers on cloud investigations. Learning and Continuous Improvement Monitor threat intelligence for indicators of compromise relevant to Zillow's environment. Flag false positives, noisy alerts, and playbook gaps to detection engineering so we can improve alert fidelity. Participate in tabletop exercises and team training sessions to build investigation skills. Contribute to the cyber defense program through documentation improvements, process automation, post-incident follow-through, and other duties as required. Continuous improvement throughout Zillow’s security program as required This role has been categorized as an Office position. “Office” employees regularly work at the Zillow India office for approximately 80 to 100 percent of their time each month. Employees must live within a reasonable commuting distance of the office. Zillow has not defined a reasonable distance, and expects employees will use judgment in determining this for themselves and understand the implications re: time commitment and co
Cyber Defense SOC Analyst on JobPost.