T

Tillster

Digital ordering platforms for restaurants

Cybersecurity Engineer

Full-TimeUpdated on 10/4/2026
$80k - $110k/yr
Mid, Senior
Bachelor's
San Diego, CA, USA
HybridMust live in San Diego; in-office 3–4 days per week.
No H1B Sponsorship

About the job

Requirements
  • 3–5+ years of experience in a cybersecurity, security engineering, or related technical IT role.
  • Hands-on experience with SIEM, EDR, and vulnerability management tooling.
  • Working knowledge of cloud platforms (AWS, Azure, or GCP) and cloud security best practices.
  • Experience configuring and managing Web Application Firewalls.
  • Solid understanding of networking fundamentals, TCP/IP, firewalls, and network segmentation.
  • Familiarity with common frameworks and standards such as NIST CSF, MITRE ATT&CK, CIS Benchmarks, or ISO 27001.
  • Experience scripting or automating tasks in Python, Bash, or PowerShell.
  • Strong analytical and problem-solving skills, with the ability to work calmly under pressure during incidents.
  • Excellent written and verbal communication skills, with the ability to explain technical risk to non-technical stakeholders.
Responsibilities
  • Design, implement, and maintain security controls across cloud, on-premises, and SaaS environments.
  • Deploy, configure, and manage security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and DLP platforms.
  • Monitor security alerts and telemetry, investigate suspicious activity, and respond to incidents in accordance with defined SLAs.
  • Tune detection rules and correlation logic to reduce false positives and improve signal quality.
  • Perform root-cause analysis on security events and implement corrective, preventative actions.
  • Maintain and continuously improve security architecture diagrams, network segmentation, and control documentation.
  • Participate in, and where appropriate lead, incident response efforts across the full lifecycle: detection, containment, eradication, and recovery.
  • Triage alerts, contain active threats, and coordinate cross-functional recovery activities.
  • Develop, test, and maintain incident response playbooks, runbooks, and communication procedures.
  • Conduct post-incident reviews and blameless retrospectives, and drive follow-through on recommended improvements.
  • Serve in an on-call rotation to support after-hours security incidents as needed.
  • Perform recurring vulnerability scanning, penetration test coordination, and risk assessments across infrastructure and applications.
  • Validate findings, assess business risk and exploitability, and prioritize remediation with asset owners.
  • Conduct threat modeling and security architecture reviews for new systems and major changes.
  • Track remediation through to closure and report on residual risk to stakeholders.
  • Secure cloud infrastructure (AWS, Azure, and/or GCP) and containerized/orchestrated environments (Docker, Kubernetes).
  • Implement and maintain IAM policies, secrets management, and least-privilege access models.
  • Partner with engineering teams to embed security scanning (SAST, DAST, SCA, container scanning) into CI/CD pipelines.
  • Review application designs, architecture, and code for security risks; provide actionable remediation guidance.
  • Deploy, configure, and tune Web Application Firewalls (WAF) to protect public-facing applications and APIs.
  • Develop and maintain WAF rule sets and policies to mitigate OWASP Top 10 risks, bot traffic, and DDoS attempts.
  • Analyze WAF logs and blocked/allowed traffic to identify attack patterns and reduce false positives/negatives.
  • Partner with application teams to onboard new services behind the WAF and validate rule coverage before go-live.
  • Assist with audits and compliance initiatives.
  • Collect and organize audit evidence, and help maintain security policies, standards, and documentation.
  • Support vendor risk assessments and third-party security reviews.
  • Help maintain the organization's risk register and control mapping.
  • Work closely with IT, DevOps, and product teams to design and implement secure solutions.
  • Provide practical, risk-based security guidance that enables delivery rather than blocking it.
  • Contribute to security awareness and training initiatives, including phishing simulations and onboarding content.
  • Act as a security point of contact and subject-matter resource for engineering and business teams.
Desired Qualifications
  • A bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • Industry certifications such as CompTIA Security+, CompTIA CySA+, CISSP, CISM, GSEC, GCIH, OSCP, or AWS/Azure security certifications.
  • Experience integrating security tooling into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Prior experience supporting compliance audits (PCI DSS).
  • Background in threat intelligence, digital forensics, or red team/blue team exercises.

About the company

Tillster provides digital ordering and engagement tools for restaurants. Its SaaS platform enables online and mobile ordering, delivery management, in-store kiosks, and personalized marketing, all connected across channels. Data analytics helps predict customer behavior, optimize conversions, and tailor coupons and loyalty rewards. The platform differentiates itself with a global, multi-channel suite that combines ordering, marketing, and analytics in one system, aiming to help restaurants run operations smoothly and boost repeat business.

Company Size

201-500

Company Stage

Early VC

Total Funding

$33.8M

Headquarters

Los Angeles, California

Founded

2002

Get referred to Tillster

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Tillster expanded its Stripe partnership globally in 2025, widening payment coverage.
  • Porto’s Bakery partnered with Tillster in August 2024, adding a recognizable brand win.
  • Tillster’s 2026 Phygital Index and blog cadence keep it visible in QSR buying cycles.

What critics are saying

  • PAR, Olo, Toast, and NCR bundle ordering and payments more cheaply than Tillster.
  • Tillster’s public funding trail is dated; capital constraints limit product acceleration by 2027.
  • If chains standardize on in-house apps and POS-native kiosks, Tillster becomes replaceable.

What makes Tillster unique

  • Tillster unifies kiosks, apps, websites, and call centers across 40,000+ restaurants worldwide.
  • Its 2026 platform ties loyalty, ordering, and menu management into one system.
  • Christopher Sebes joined June 2025, signaling credible restaurant-tech operator depth.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Health Savings Account/Flexible Spending Account

Employee Assistance Program

401(k) Retirement Plan

Holidays

Paid Vacation

Home Office Stipend

Meal Benefits

Hybrid Work Options

Remote Work Options

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↓ -1%

2 year growth

↑ 0%
Bake Magazine
Aug 14th, 2024
Porto's Bakery & Café enhances digital experience with new partnership

Southern California-based Porto's Bakery & Café has announced a new partnership with Tillster, a leader in digital ordering technology, that aims to enhance the digital ordering experience for Porto's guests, further streamlining operations and expanding guest engagement.

VertMarkets, Inc.
Mar 7th, 2022
Tillster, Inc. launches ‘Digital Dish’

“We at Tillster are thrilled to launch ‘Digital Dish’ as a new collaborative community for brands to do just this.

Valdosta Daily Times
Jan 27th, 2022
Kudzu Interactive, Inc. launches Delivery Index

Tillster, the global leader in digital ordering and engagement solutions for restaurants, today releases its fourth Delivery Index, revealing how customer attitudes towards delivery programs from Quick Service (QSR) and Fast Casual restaurants have shifted since the pandemic struck in 2020.

Tillster
Oct 5th, 2021
Kudzu Interactive, Inc. launches promotional awareness campaign to gain traction

After three months, Tillster recommended taking it a step further and launched a promotional awareness campaign to gain traction on the original launch.