Information Security Analyst
Zillow
- Location
- Bengaluru
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 96 approvals (FY2023)
- Posted
- Aug 12, 2026
Skills
About this role
About the team
About the team Zillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe. Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India.
About the role
About the Role We're looking for an Information Security Analyst to be a core contributor to our security operations and incident response capabilities. In this role, you'll own the day-to-day SOC workload — triaging and resolving security alerts, investigating incidents, and executing response playbooks — while also taking on moderate-complexity incident response investigations with increasing independence. You bring enough experience to work independently on most security events, make sound triage decisions, and know when to escalate. You contribute to playbook improvements, support other analysts, and partner with other teams during incident response. You Will Get To Security Operations Monitor, triage, and resolve tier-1 and tier-2 SOC tickets across endpoints, identity, cloud, network, and application sources. Investigate security alerts from SIEM, EDR, and cloud security platforms, accurately assessing severity and scope. Execute incident response playbooks for scenarios such as phishing, account compromise, endpoint alerts, and cloud alerts. Serve as an escalation point for other analysts, helping guide triage and investigation decisions. Maintain accurate documentation of all investigations, response actions, and outcomes. Incident Response Lead response on low-to-moderate complexity security incidents, owning investigation from detection through containment, remediation, and post-mortem documentation. Investigate a broad range of incident types including identity attacks, phishing, SaaS events, cloud attacks, supply chain alerts, and endpoint compromises. Conduct forensic analysis of compromised systems across Windows, macOS, Linux, and cloud environments, preserving evidence and documenting findings. Participate in on-call rotation for after-hours security incidents, escalating to senior responders when appropriate. Contribute to post-incident reports and root cause analyses, capturing lessons learned and recommending improvements. Cloud Security Investigate AWS security alerts such as GuardDuty findings, CloudTrail anomalies, IAM events, and compute events. Apply cloud security knowledge to scope and contain incidents in AWS environments, partnering with senior responders and engineers on complex cloud investigations. Detection and Continuous Improvement Analyze threat intelligence and monitor for indicators of compromise relevant to Zillow's environment. Contribute to detection logic refinement and playbook updates based on investigation findings and emerging threats. Participate in tabletop exercises and help identify gaps in the team's response capabilities. Collaborate with detection engineering to tune out false positives and improve alert fidelity. Drive continuous improvement to the cyber defense program through lessons learned, process automation, tooling enhancements, post-incident follow-through and other duties as required. Partner with cloud and platform engineering on containment actions and long-term security hardening recommendations. This role has been categorized as an Office position. “Office” employees regularly work at the Zillow India