Gigsouk
Zillow logo
Zillow

Information Security Cyber Defense Incident Responder

On-siteBengaluruFull-timeSenior

About the team

Zillow Group's Cyber Defense team owns security monitoring, detection engineering, incident response, and vulnerability management across our environment. We partner closely with Engineering, IT, Legal, Privacy, and business stakeholders to keep Zillow's customers, employees, and data safe.

Zillow Group is a strategic, mission-driven organization focused on delivering exceptional experiences and measurable outcomes. Our work spans cross-functional partnership, scalable programs and operational excellence in support of Zillow’s mission. We bring deep experience working across diverse teams in a dynamic, high-growth environment, balancing strategic thinking with hands-on execution to drive meaningful business impact. We are seeking an experienced professional to support our workforce expansion in India.

About the role

We're looking for a Senior Security Incident Responder to be our lead technical responder on the most complex, high-severity security events — such as supply chain attacks, identity attacks, SaaS intrusions, and cloud security events. You'll command cross-functional response efforts, lead investigations with a team from detection through post-mortem, and mentor other analysts. This role is expected to investigate, validate, remediate and communicate known details about the incident and work closely with cybersecurity leadership.

This is a senior individual contributor role. You make smart decisions under pressure without waiting for direction, and you communicate early and clearly to both technical peers and leadership stakeholders.

You Will Get To

Incident Response Leadership

  • Serve as the primary technical lead on complex, high-severity security incidents, owning investigations from initial detection through containment, remediation, and post-mortem.
  • Command cross-functional incident response efforts — establishing clear ownership, priorities, and next steps across Engineering, IT, Legal, Privacy, and other stakeholders.
  • Independently or with a team scope and investigate security events including supply chain attacks, identity attacks, SaaS platform attacks, cloud intrusions, and other threats as needed.
  • Lead incident response in cloud environments— scoping attacker access, driving containment across multi-account infrastructure, and investigating EC2, IAM, S3, and supply chain events.
  • Participate in on-call response for critical security incidents, making timely and sound decisions without requiring escalation for direction.
  • Conduct forensic analysis of compromised systems across Linux, macOS, Windows, and cloud environments, preserving evidence and documenting decisions.
  • Author thorough post-incident reports and root cause analyses, translating technical findings into clear, actionable insights for both technical and non-technical audiences.

Investigation and Detection

  • Handle SOC alert queue and routine tickets as needed, providing senior-level judgment on triage and escalation decisions.
  • Investigate security alerts from SIEM, EDR, cloud security platforms, and threat intelligence feeds, applying expert judgment to triage, prioritize, and escalate.
  • Perform deep-dive investigations across host, network, identity, and cloud evidence sources.
  • Conduct proactive threat hunting based on threat intelligence, behavioral anomalies, and emerging attacker tactics, techniques, and procedures (TTPs).
  • Develop and refine detection logic in collaboration with detection engineering, converting incident learnings into improved coverage and reduced false positive rates.

Program and Team Development

  • Mentor and upskill junior and mid-level analysts through coaching, tabletop exercises, and collaborative incident response work.
  • Own and maintain incident response playbooks, runbooks, and response procedures, keeping them current with the evolving threat landscape.
  • Drive continuous improvement to the cyber defense program through lessons learned, process automation, tooling enhancements, post-incident follow-through and other duties as required.
  • Partner with cloud and platform engineering on containment actions and long-term security hardening recommendations.
  • Represent Cyber Defense in cross-functional discussions, helping partner teams understand security risk and prioritize effective remediation.
  • This role has been categorized as an Office position. “Office” employees regularly work at the Zillow India office for approximately 80 to 100 percent of their time each month. Employees must live within a reasonable commuting distance of the office. Zillow has not defined a reasonable distance, and expects employees will use judgment in determining this for themselves and understand the implications re: time commitment and cost of daily commute.

Who you are

  • 7+ years of professional experience in cybersecurity, with at least 4 years focused on security incident response — or equivalent depth in hands-on security operations.
  • Demonstrated history of independently leading complex, multi-day security investigations. You have been the person others called during the most difficult incidents and you drove them to resolution.
  • Deep knowledge of attacker TTPs and proven ability to apply the MITRE ATT&CK framework to real-world investigations across the full attack lifecycle.
  • Strong hands-on AWS security investigation expertise — including CloudTrail, GuardDuty, VPC Flow Logs, S3 access logs, IAM, and Lambda — with experience containing and remediating cloud-based incidents.
  • Proficiency with EDR tools (e.g., CrowdStrike), SIEM platforms (e.g., Exabeam, Splunk), and cloud security tooling (e.g., Wiz, AWS Security Hub).
  • Advanced understanding of Windows, macOS, and Linux operating systems and their forensic artifacts — process trees, registry, logs, memory, and disk.
  • Experience investigating identity-based attacks including Okta and AD attacks, OAuth abuse, SSO attacks, and MFA bypass techniques.
  • Scripting skills in Python, Bash, or PowerShell for investigative automation, tooling, and rapid response workflows.
  • Exceptional written and verbal communication skills — you can write a clear executive summary of a complex incident and present findings confidently to non-technical leadership.
  • Demonstrated ability to make sound, independent decisions in high-pressure, ambiguous, and time-sensitive situations without requiring escalation for direction.
  • Plus: Background in IT systems administration, software engineering, or DevOps — this foundation strengthens cloud-native investigation and cross-team collaboration.
  • Plus: Experience with SOAR platforms, threat intelligence tooling, or automated response workflows.
  • Plus: Relevant certifications: GCIH, GCFE, GCFA, CISSP, GCFR, AWS SAA or AWS Security.

Get to know us

At Zillow, we’re reimagining how people move—through the real estate market and through their careers. As the most-visited real estate platform in the U.S., we help people navigate buying, selling, financing and renting with greater ease and confidence. Whether you're working in tech, sales, operations, or design, you’ll be part of a company reshaping an industry and helping more people make home a reality.

Zillow is honored to be recognized among the best workplaces in the U.S. Zillow was named one of FORTUNE 100 Best Companies to Work For® in 2026, and included on TIME’s America’s Best Companies 2026 list, reflecting our commitment to creating an innovative, inclusive, and engaging culture where employees are empowered to grow.

No matter where you sit in the organization, your work will help drive innovation, support our customers, and move the industry—and your career—forward, together.

Zillow Group is committed to fostering an inclusive, innovative environment and to providing equal employment opportunities. We comply with applicable laws that prohibit discrimination in employment and recruitment.

If you have a disability or special need that requires accommodation during the recruitment process, please contact your recruiter directly.

Qualified applicants will be considered for employment in accordance with applicable law.

Similar jobs