Senior Security Analyst
Job Description
Zoom’s Detection and Response team is hiring a Senior Security Analyst to triage and investigate cybersecurity events while building automation to improve detection and response workflows.
Responsibilities
- Triaging, investigating, and escalating cybersecurity events across Zoom’s environment, including identifying root causes and implementing preventive measures.
- Turning deep analysis into repeatable automation to scale team output and impact, as a core focus of the role.
- Partnering with the D&R team to support Incident Response service and enhance Zoom’s security posture.
- Providing investigative support during active cybersecurity incidents.
- Developing and implementing new processes, procedures, and automated workflows identified by D&R and SOC leadership to improve monitoring, detection, and mitigation capabilities.
- Responding to security events reported by internal and external teams, escalating incidents according to Zoom’s incident response plan.
- Assisting with threat containment and participating in remediation activities during and after incidents.
- Maintaining awareness of the global threat landscape through close partnership with the Zoom Threat Intelligence team.
Requirements
- 2 to 4 years of experience working in a Security Operations Center and/or Incident Response role.
- 2+ years of experience in a technical role (IT, Networking, Software Engineering, Systems Administration, etc.).
- Proven track record building effective automation solutions, including deterministic automation (if/then scripts) and an agentic, LLM-powered auto-triage framework.
- Good programming or scripting skills in Python, Go, PowerShell, Bash, or similar.
- Curiosity and a thoughtful investigative mindset with motivation to continuously learn and grow.
- Hands-on query-building experience with security data platforms such as SPL, KQL, Lucene, CQL, SQL, etc.
Technologies
- Python, Go, PowerShell, Bash
- SPL, KQL, Lucene, CQL, SQL
Shift and Working Hours
- Shift-based hours: 8:00 AM to 6:00 PM EST
- Schedule: Tuesday through Friday or Wednesday through Saturday
- Remote role
What You Can Expect
- Investigate cybersecurity events and incidents at Zoom.
- Combine hands-on security operations with automation engineering.
- Opportunity to transition into a full-time automation engineer role.
Team Overview
- Detection and Response (D&R) safeguards Zoom’s systems and information to protect customers, partners, and employees.
- D&R assesses business risk and counter potential threats through proactive and reactive measures.
- D&R includes Cyber Threat Intelligence, Security Logging, Detection Engineering, the Security Operations Center (SOC), and Incident Response.
Salary
- USD 87,600 - 186,000 per year
- Starting pay based on factors including qualifications and experience.
- Total Direct Compensation includes base salary, bonus, and equity value.
- Location-based compensation may differ by region.
Ways of Working
- Structured hybrid approach centered around Zoom offices and remote work environments.
- Work style (Hybrid, Remote, or In-Person) is indicated in the job description/posting.
Benefits
- Benefits program includes perks and options supporting physical, mental, emotional, and financial health.
- Support work-life balance and community involvement.
Our Commitment
- Fair hiring practices based on skills, experience, and potential.
- Accommodation available during the hiring process; assistance for interview navigation due to medical disability via an Accommodations Request Form.
- Inclusive hiring welcoming people of different backgrounds, experiences, abilities, and perspectives.
- Interviews supported by BrightHire, which helps create a consistent interview experience and may include recordings.