CybersecurityJobs.io
← Back to all jobs

Job Description

Zoom’s Detection and Response team is hiring a Senior Security Analyst to triage and investigate cybersecurity events while building automation to improve detection and response workflows.

Responsibilities

  • Triaging, investigating, and escalating cybersecurity events across Zoom’s environment, including identifying root causes and implementing preventive measures.
  • Turning deep analysis into repeatable automation to scale team output and impact, as a core focus of the role.
  • Partnering with the D&R team to support Incident Response service and enhance Zoom’s security posture.
  • Providing investigative support during active cybersecurity incidents.
  • Developing and implementing new processes, procedures, and automated workflows identified by D&R and SOC leadership to improve monitoring, detection, and mitigation capabilities.
  • Responding to security events reported by internal and external teams, escalating incidents according to Zoom’s incident response plan.
  • Assisting with threat containment and participating in remediation activities during and after incidents.
  • Maintaining awareness of the global threat landscape through close partnership with the Zoom Threat Intelligence team.

Requirements

  • 2 to 4 years of experience working in a Security Operations Center and/or Incident Response role.
  • 2+ years of experience in a technical role (IT, Networking, Software Engineering, Systems Administration, etc.).
  • Proven track record building effective automation solutions, including deterministic automation (if/then scripts) and an agentic, LLM-powered auto-triage framework.
  • Good programming or scripting skills in Python, Go, PowerShell, Bash, or similar.
  • Curiosity and a thoughtful investigative mindset with motivation to continuously learn and grow.
  • Hands-on query-building experience with security data platforms such as SPL, KQL, Lucene, CQL, SQL, etc.

Technologies

  • Python, Go, PowerShell, Bash
  • SPL, KQL, Lucene, CQL, SQL

Shift and Working Hours

  • Shift-based hours: 8:00 AM to 6:00 PM EST
  • Schedule: Tuesday through Friday or Wednesday through Saturday
  • Remote role

What You Can Expect

  • Investigate cybersecurity events and incidents at Zoom.
  • Combine hands-on security operations with automation engineering.
  • Opportunity to transition into a full-time automation engineer role.

Team Overview

  • Detection and Response (D&R) safeguards Zoom’s systems and information to protect customers, partners, and employees.
  • D&R assesses business risk and counter potential threats through proactive and reactive measures.
  • D&R includes Cyber Threat Intelligence, Security Logging, Detection Engineering, the Security Operations Center (SOC), and Incident Response.

Salary

  • USD 87,600 - 186,000 per year
  • Starting pay based on factors including qualifications and experience.
  • Total Direct Compensation includes base salary, bonus, and equity value.
  • Location-based compensation may differ by region.

Ways of Working

  • Structured hybrid approach centered around Zoom offices and remote work environments.
  • Work style (Hybrid, Remote, or In-Person) is indicated in the job description/posting.

Benefits

  • Benefits program includes perks and options supporting physical, mental, emotional, and financial health.
  • Support work-life balance and community involvement.

Our Commitment

  • Fair hiring practices based on skills, experience, and potential.
  • Accommodation available during the hiring process; assistance for interview navigation due to medical disability via an Accommodations Request Form.
  • Inclusive hiring welcoming people of different backgrounds, experiences, abilities, and perspectives.
  • Interviews supported by BrightHire, which helps create a consistent interview experience and may include recordings.

Similar Jobs