Cybersecurity Engineer

Tillster
  • San Diego, California
    6 days ago

    Job Description

    Role: Cybersecurity Engineer
    Hybrid Role, MUST BE BASED IN SAN DIEGO, CA- MUST LIVE IN SAN DIEGO; IN OFFICE 3-4 DAYS A WEEK!!!!


    About Tillster
    Tillster, headquartered in the USA, is the global leader in digital ordering and customer engagement solutions. For over a decade, we have developed revolutionary self-service ordering and payment solutions – for mobile, tablet, online, kiosk, call center, and more – creating personalized interactions based on consumer preferences, language, and currency. Our platform is compatible with 15+ unique POS systems, representing over 90% coverage in multi-unit restaurants. We offer one platform; one scalable, enterprise-class solution – to create world-class digital engagement solutions.

    Our mission and passion are one in the same: Empower restaurants and consumers to engage and transact anywhere, anytime, and from any device - one consumer at a time, one order at a time, billions of times over. In doing so, together we are transforming e-commerce in restaurants and making the till grow for Tillster and our customers.

    Job Summary

    The Cybersecurity Engineer designs, implements, and operates the security controls that protect the organization's systems, networks, applications, and data. This is a hands-on, technical role that partners closely with IT, DevOps, and engineering teams to identify risk, respond to incidents, and continuously strengthen the company's security posture. The ideal candidate combines deep technical expertise with strong communication skills, translating complex security concepts into practical guidance that enables the business to move fast without compromising security.

    Key Responsibilities

    Security Engineering & Operations

    • Design, implement, and maintain security controls across cloud, on-premises, and SaaS environments

    • Deploy, configure, and manage security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and DLP platforms

    • Monitor security alerts and telemetry, investigate suspicious activity, and respond to incidents in accordance with defined SLAs

    • Tune detection rules and correlation logic to reduce false positives and improve signal quality

    • Perform root-cause analysis on security events and implement corrective, preventative actions

    • Maintain and continuously improve security architecture diagrams, network segmentation, and control documentation

    Incident Response

    • Participate in, and where appropriate lead, incident response efforts across the full lifecycle: detection, containment, eradication, and recovery

    • Triage alerts, contain active threats, and coordinate cross-functional recovery activities

    • Develop, test, and maintain incident response playbooks, runbooks, and communication procedures

    • Conduct post-incident reviews and blameless retrospectives, and drive follow-through on recommended improvements

    • Serve in an on-call rotation to support after-hours security incidents as needed

    Vulnerability & Risk Management

    • Perform recurring vulnerability scanning, penetration test coordination, and risk assessments across infrastructure and applications

    • Validate findings, assess business risk and exploitability, and prioritize remediation with asset owners

    • Conduct threat modeling and security architecture reviews for new systems and major changes

    • Track remediation through to closure and report on residual risk to stakeholders

    Cloud & Application Security

    • Secure cloud infrastructure (AWS, Azure, and/or GCP) and containerized/orchestrated environments (Docker, Kubernetes)

    • Implement and maintain IAM policies, secrets management, and least-privilege access models

    • Partner with engineering teams to embed security scanning (SAST, DAST, SCA, container scanning) into CI/CD pipelines

    • Review application designs, architecture, and code for security risks; provide actionable remediation guidance

    • Deploy, configure, and tune Web Application Firewalls (WAF) to protect public-facing applications and APIs

    • Develop and maintain WAF rule sets and policies to mitigate OWASP Top 10 risks, bot traffic, and DDoS attempts

    • Analyze WAF logs and blocked/allowed traffic to identify attack patterns and reduce false positives/negatives

    • Partner with application teams to onboard new services behind the WAF and validate rule coverage before go-live

    Compliance & Governance Support

    • Assist with audits and compliance initiatives

    • Collect and organize audit evidence, and help maintain security policies, standards, and documentation

    • Support vendor risk assessments and third-party security reviews

    • Help maintain the organization's risk register and control mapping

    Collaboration & Enablement

    • Work closely with IT, DevOps, and product teams to design and implement secure solutions

    • Provide practical, risk-based security guidance that enables delivery rather than blocking it

    • Contribute to security awareness and training initiatives, including phishing simulations and onboarding content

    • Act as a security point of contact and subject-matter resource for engineering and business teams

    Required Qualifications

    • 3–5+ years of experience in a cybersecurity, security engineering, or related technical IT role

    • Hands-on experience with SIEM, EDR, and vulnerability management tooling

    • Working knowledge of cloud platforms (AWS, Azure, or GCP) and cloud security best practices

    • Experience configuring and managing Web Application Firewalls

    • Solid understanding of networking fundamentals, TCP/IP, firewalls, and network segmentation

    • Familiarity with common frameworks and standards such as NIST CSF, MITRE ATT&CK, CIS Benchmarks, or ISO 27001

    • Experience scripting or automating tasks in Python, Bash, or PowerShell

    • Strong analytical and problem-solving skills, with the ability to work calmly under pressure during incidents

    • Excellent written and verbal communication skills, with the ability to explain technical risk to non-technical stakeholders

    Preferred Qualifications

    • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience

    • Industry certifications such as CompTIA Security+, CompTIA CySA+, CISSP, CISM, GSEC, GCIH, OSCP, or AWS/Azure security certifications

    • Experience integrating security tooling into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins)

    • Prior experience supporting compliance audits (PCI DSS)

    • Background in threat intelligence, digital forensics, or red team/blue team exercises

    Pay and Benefits (USA)

    • Salary is $80,000-$110,000

    • Health Benefits: All full-time, regular employees and their dependents are eligible for medical, dental, vision and FSA benefits. Additional health benefits include Healthcare and Dependent Care reimbursement programs, Employee Assistance Program (“EAP”) and Optum Care 24-hour confidential medical counseling services.

    • Holidays: The company observes ten (10) paid holidays per calendar year.

    • Paid Time Off (PTO): Full-time, regular employees earn 15 days of PTO in the first 12-months of continuous service, and 22 days in subsequent years. Eligible part-time employees earn pro-rated PTO.

    • Retirement: Effective with your employment start date, you will be eligible to participate in the 401(k) Plan.

    • Education, Learning & Development: We offer college tuition and education assistance programs; Udemy Learning courses; and ongoing learning and development opportunities.

     

    Thriving at Tillster
    As a member of Tillster, you will embody our core values:
    · Put Customers First:Prioritize the needs and satisfaction of our customers in all decisions and actions appropriate to Tillster’s stage of development, resources, and stated goals.
    · Collaborate: Work together effectively, leveraging diverse perspectives to achieve common goals.
    · Innovate: Embrace creativity and pursue new ideas to drive progress and improvement.
    · Operate from Data: Use strong critical thinking skills to make informed decisions based on accurate and relevant data.
    · Drive Results: Focus on achieving tangible outcomes and delivering high performance.
    · Own It: Take responsibility for your actions and the success of your work.
    · Be Passionate and Have Fun: Bring enthusiasm to your work and enjoy the journey.

    Tillster cares about the safety of all our employees—even those we’ve yet to hire

     

    Local Candidates Only
    No Visa Sponsorship
    Principals only – no Agencies or calls please

    Numbers & Facts

    LocationSan Diego, California
    Websitehttps://www.tillster.com

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Architectural Designunmatched
    • Bash Scriptingunmatched
    • Benchmarkingunmatched
    • Best Practicesunmatched
    • Business Analysisunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Call Centersunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA - Computing Technology Industry Associationunmatched
    • CompTIA Security+unmatched
    • Computer Forensicsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Improvementunmatched
    • Continuous Integrationunmatched
    • Corrective Actionunmatched
    • Cross-Functionalunmatched
    • Customer Satisfactionunmatched
    • DevOpsunmatched
    • Document Managementunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • Firewallsunmatched
    • Follow Throughunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GCP (Good Clinical Practices)unmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • GitHubunmatched
    • ISO (International Organization for Standardization)unmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Jenkinsunmatched
    • Machine Toolunmatched
    • Maintain Complianceunmatched
    • Microsoft Windows Azureunmatched
    • Network Architecture/Engineeringunmatched
    • On Callunmatched
    • PCI-DSSunmatched
    • Penetration Testingunmatched
    • Point of Sale (POS) Systemsunmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Process Improvementunmatched
    • Product Designunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Managementunmatched
    • Regulatory Complianceunmatched
    • Restaurantunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Root Cause Analysisunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Service Level Agreement (SLA)unmatched
    • Software Designunmatched
    • Software as a Service (SaaS)unmatched
    • Storage Area Network (SAN)unmatched
    • System Architectureunmatched
    • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
    • Technical/Engineering Designunmatched
    • Telemetryunmatched
    • Test Plan/Scheduleunmatched
    • Threat Modelingunmatched
    • Tuition Feesunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched
    • eCommerceunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder