Cyber Defense SOC Analyst
Core
Monitor, triage, and resolve security alerts across endpoints, identity, cloud, and network sources; investigate incidents using forensics and threat intelligence to protect digital assets.
Role type
SOC Security Analyst (Incident Response & Detection)
Builds
Security monitoring, detection engineering, and incident response capabilities for Zillow's environment
Domain
Cybersecurity / Cloud Security (AWS)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response, forensic analysis, threat intelligence, SIEM operations, cloud security, scripting (Python/PowerShell), MITRE ATT&CK framework knowledge, multi-platform forensics (Windows/macOS/Linux)
Preferred skills
Security+, CySA+, GCIH, AWS SAA certifications
Technologies
SIEM (Exabeam), EDR (CrowdStrike), AWS (GuardDuty, CloudTrail, IAM)
Responsibilities
Monitor and triage SOC tickets from various sources; Investigate security alerts and determine malicious vs benign; Execute incident response playbooks for phishing, account compromise, and cloud alerts; Collect and preserve evidence from compromised systems; Participate in on-call rotation for security alerts; Contribute to post-incident reports and process improvements
Seniority
Mid-level, hands-on IC