Information Security Analyst
Core
SOC analyst and incident responder owning day-to-day security monitoring, alert triage, and investigation for a real estate platform.
Role type
mid-level IC information security analyst (SOC/IR)
Builds
security operations and incident response capabilities for Zillow's cloud, endpoint, and identity environments
Domain
cybersecurity, cloud security, incident response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
security operations (SOC), incident response, AWS security services (GuardDuty, CloudTrail, IAM), SIEM platforms (Exabeam, Splunk), EDR tools (CrowdStrike), attacker TTPs, MITRE ATT&CK, identity attack investigation, forensic analysis, scripting (Python, Bash, PowerShell)
Preferred skills
SOAR platforms, automation workflows, IT systems administration background, software engineering background, relevant certifications (Security+, CySA+, GCIH, GCFR, AWS SSA)
Technologies
AWS, Exabeam, Splunk, CrowdStrike, Okta, Active Directory, Windows, macOS, Linux
Responsibilities
Monitor, triage, and resolve tier-1 and tier-2 SOC tickets across endpoints, identity, cloud, network, and application sources; Investigate security alerts from SIEM, EDR, and cloud security platforms; Execute incident response playbooks for phishing, account compromise, endpoint alerts, and cloud alerts; Lead response on low-to-moderate complexity security incidents from detection through containment and remediation; Conduct forensic analysis of compromised systems across Windows, macOS, Linux, and cloud environments; Analyze threat intelligence and monitor for indicators of compromise; Contribute to detection logic refinement and playbook updates based on investigation findings
Seniority
Mid-level, hands-on IC
