At Zillow Group, the attack surface is the American housing market. The company operates the most-visited real estate website in the United States, a platform that touches millions of users daily across buying, selling, renting, financing, and home improvement. That scale means defending high-volume transaction data, sensitive financial information, and the proprietary machine learning models behind products like Zestimate - the company's signature AI-powered home valuation tool. The threat model covers the full spectrum of a major consumer-facing tech platform: protecting vast user PII, securing complex financial workflows, and safeguarding the intellectual property of AI systems that process real estate data at a national scale.
The security team operates within a digital-first ecosystem where the technical domains are deeply integrated. Protecting AI-powered innovations is a concrete responsibility, not an abstraction; it means securing the data pipelines and model infrastructure that generate valuations and other automated insights. The work spans the infrastructure supporting a platform that has become foundational to how Americans interact with real estate, making the stakes about both data integrity and consumer trust in a heavily regulated vertical.
Security engineering at Zillow Group involves defending a system where real estate, financing, and home improvement services converge. That convergence creates dependencies - a breach in one domain could cascade across others. The team's focus is on securing this interconnected architecture, with an emphasis on the AI and machine learning components that differentiate the platform, all within the regulatory and privacy constraints of the U.S. market.






