About the team Join our team as a versatile and hardworking Senior Cloud Security Engineer. This role presents an excellent opportunity to contribute to the security and reliability of our cloud infrastructure and web applications. Your responsibilities will include implementing outstanding security measures, adhering to standard processes in secure code development, and optimizing the performance and scalability of our applications. Collaborate with development, operations, and security teams to successfully deploy solutions that safeguard our systems from threats and vulnerabilities.
About the roleOur team plays a crucial role in Zillow's security operations, responsible for protecting critical perimeter defense systems, including anti-bot technologies and AWS Shield. We coordinate the secure configuration of a wide range of web products, guaranteeing flawless performance and strong defense. Our goal is to strengthen the security of the CI/CD pipeline, finding the right balance between agility and resilience in a constantly changing tech environment. We value positive, collaborative relationships with collaborators, incorporating their input into our security standard methodologies to improve operational efficiency.This role has been categorized as a teleworker position. Teleworkers do not have a permanent corporate office workplace and, instead, work from a physical location of their choice which must be identified to the Company. Employees may live in any part of Mexico, but preferably in Mexico City, as we would encourage attendance for occasional in-office events.In addition to a competitive base salary and benefits, this position is also eligible for equity awards based on factors such as experience, performance and location.Who you areStrong understanding of AWS architecture and services, with hands-on experience in AWS WAF, Shield, CloudFront, IAM, VPC, GuardDuty, Kinesis, Cloud Trail, Security Hub, KMS, Athena, Lambda, Step Functions, etc.Proficient developer skills in Python, Java, Golang, and Bash, with experience writing and running SQL queries.Expertise in IaC using Terraform and AWS CloudFormation.Practical experience with bot detection and mitigation technologies, web security standard methodologies (SSL/TLS, HTTP security headers), and CDN/DNS security.Deep knowledge of the OWASP Top 10 vulnerabilities and experience mitigating threats like SQL injection, XSS, CSRF, and others.Proven experience securing CI/CD pipelines, integrating security testing tools, and managing secret management solutions.Strong experience with containerization orchestration tools (AWS ECR, Kubernetes, Docker, GKE or equivalent experience) and managing secure containerized environments.Familiarity with secure coding standards, static and multifaceted analysis tools, and role-based access control (RBAC) principles.Experience with secure version control practices and third-party library management.Familiarity with cloud security tools and platforms, particularly those used for monitoring, compliance, and threat detection within cloud environments.Preferred Qualifications:AWS certification (Solutions Architect, Security Specialty, or DevOps Engineer) is helpful.Experience with large-scale production environments with high security demands.Strong communication and teamwork skills with the ability to work cross-functionally to tackle sophisticated security challenges.Experience working in Agile or DevOps environments.Get to know usZillow is reimagining real estate to make it easier to unlock life's next chapter.As the most-visited real estate website in the United States, Zillow® and its affiliates help movers find and win their home through digital solutions, first class partners, and easier buying, selling, financing and renting experiences. Millions of people visit Zillow Group sites every month to start their home search, and now they can rely on Zillow to help make it easier to move. The work we do is helping people move from dreaming to transacting — and no matter what job you're in, you will play a critical role in making this vision a reality.Our efforts to streamline the real estate transaction are supported by a deep-rooted culture of innovation, our passion to redefine the employee experience, and afundamental commitment to Equity and Belonging. We're also setting the standard for work experiences of the future, where our employees are supported in doing their best work and living a flexible, well-balanced life. But don't just take our word for it. Read recent reviews on Glassdoor and recent recognition from multiple organizations, including: the 100 Best Companies to Work For in 2022 list, Glassdoor Employees' Choice Award, honoring the Best Places to Work in 2022, Bloomberg Gender-Equality Index 2022, Human Rights Campaign (HRC) Corporate Equity Index and Best Place to Work for LGBTQ Equality 2022, and TIME 100 Most Influential Companies list.Zillow Group is an equal opportunity employer committed to fostering an inclusive, innovative environment with the best employees. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, and gender identity. If you have a disability or special need that requires accommodation, please contact your recruiter directly.Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable state and local law.