Jobs and Careers
TI

Cybersecurity Engineer

Tillster
San Diego, United StatesRemotefull_timeVerifiedPosted 18 Aug 2026
💰 $110,000/yr($80,000/yr$110,000/yr)

About the role

Role: Cybersecurity Engineer
Hybrid Role, MUST BE BASED IN SAN DIEGO, CA


About Tillster
Tillster, headquartered in the USA, is the global leader in digital ordering and customer engagement solutions. For over a decade, we have developed revolutionary self-service ordering and payment solutions – for mobile, tablet, online, kiosk, call center, and more – creating personalized interactions based on consumer preferences, language, and currency. Our platform is compatible with 15+ unique POS systems, representing over 90% coverage in multi-unit restaurants. We offer one platform; one scalable, enterprise-class solution – to create world-class digital engagement solutions.

Our mission and passion are one in the same: Empower restaurants and consumers to engage and transact anywhere, anytime, and from any device - one consumer at a time, one order at a time, billions of times over. In doing so, together we are transforming e-commerce in restaurants and making the till grow for Tillster and our customers.

Job Summary

The Cybersecurity Engineer designs, implements, and operates the security controls that protect the organization's systems, networks, applications, and data. This is a hands-on, technical role that partners closely with IT, DevOps, and engineering teams to identify risk, respond to incidents, and continuously strengthen the company's security posture. The ideal candidate combines deep technical expertise with strong communication skills, translating complex security concepts into practical guidance that enables the business to move fast without compromising security.

Key Responsibilities

Security Engineering & Operations

• Design, implement, and maintain security controls across cloud, on-premises, and SaaS environments

• Deploy, configure, and manage security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and DLP platforms

• Monitor security alerts and telemetry, investigate suspicious activity, and respond to incidents in accordance with defined SLAs

• Tune detection rules and correlation logic to reduce false positives and improve signal quality

• Perform root-cause analysis on security events and implement corrective, preventative actions

• Maintain and continuously improve security architecture diagrams, network segmentation, and control documentation

Incident Response

• Participate in, and where appropriate lead, incident response efforts across the full lifecycle: detection, containment, eradication, and recovery

• Triage alerts, contain active threats, and coordinate cross-functional recovery activities

• Develop, test, and maintain incident response playbooks, runbooks, and communication procedures

• Conduct post-incident reviews and blameless retrospectives, and drive follow-through on recommended improvements

• Serve in an on-call rotation to support after-hours security incidents as needed

Vulnerability & Risk Management

• Perform recurring vulnerability scanning, penetration test coordination, and risk assessments across infrastructure and applications

• Validate findings, assess business risk and exploitability, and prioritize remediation with asset owners

• Conduct threat modeling and security architecture reviews for new systems and major changes

• Track remediation through to closure and report on residual risk to stakeholders

Cloud & Application Security

• Secure cloud infrastructure (AWS, Azure, and/or GCP) and containerized/orchestrated environments (Docker, Kubernetes)

• Implement and maintain IAM policies, secrets management, and least-privilege access models

• Partner with engineering teams to embed security scanning (SAST, DAST, SCA, container scanning) into CI/CD pipelines

• Review application designs, architecture, and code for security risks; provide actionable remediation guidance

• Deploy, configure, and tune Web Application Firewalls (WAF) to protect public-facing applications and APIs

• Develop and maintain WAF rule sets and policies to mitigate OWASP Top 10 risks, bot traffic, and DDoS attempts

• Analyze WAF logs and blocked/allowed traffic to identify attack patterns and reduce false positives/negatives

• Partner with application teams to onboard new services behind the WAF and validate rule coverage before go-live

Compliance & Governance Support

• Assist with audits and compliance initiatives

• Collect and organize audit evidence, and help maintain security policies, standards, and documentation

• Support vendor risk assessments and third-party security reviews

• Help maintain the organi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Tillster

View company profile →