Information Security Analyst
Core
SOC analyst and incident responder owning day-to-day security monitoring, alert triage, and investigation for a real estate platform.
Role type
mid-level IC information security analyst (SOC/IR)
Builds
security operations and incident response capabilities for Zillow's cloud, endpoint, and identity environments
Domain
cybersecurity, cloud security, incident response
Required skills
security operations (SOC), incident response, AWS security services (GuardDuty, CloudTrail, IAM), SIEM platforms (Exabeam, Splunk), EDR tools (CrowdStrike), attacker TTPs, MITRE ATT&CK, identity attack investigation, forensic analysis, scripting (Python, Bash, PowerShell)
Preferred skills
SOAR platforms, automation workflows, IT systems administration background, software engineering background, relevant certifications (Security+, CySA+, GCIH, GCFR, AWS SSA)
Technologies
AWS, Exabeam, Splunk, CrowdStrike, Okta, Active Directory, Windows, macOS, Linux
Responsibilities
Monitor, triage, and resolve tier-1 and tier-2 SOC tickets across endpoints, identity, cloud, network, and application sources; Investigate security alerts from SIEM, EDR, and cloud security platforms; Execute incident response playbooks for phishing, account compromise, endpoint alerts, and cloud alerts; Lead response on low-to-moderate complexity security incidents from detection through containment and remediation; Conduct forensic analysis of compromised systems across Windows, macOS, Linux, and cloud environments; Analyze threat intelligence and monitor for indicators of compromise; Contribute to detection logic refinement and playbook updates based on investigation findings
Seniority
Mid-level, hands-on IC
