> Markdown version of [/jobs/ext/2722981-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2722981-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Tillster, Inc. - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Application Firewall, Software System Penetration Testing, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, System Configuration, DevOps, Digital Forensics, Github, Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Key Management, Networking Basics, Network Segmentation, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Phishing, Red Team (Cyber Security), Security Information and Event Management, Systems Integration, TCP/IP, Software Vulnerability Management, Scripting, Software Security, Mitre Att&ck, Firewalls (Computer Science), Gitlab-ci, Kubernetes, Information Technology, CIS Benchmarks, Ddos, Blue Team (Cyber Security), Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/cybersecurity-engineer-tillster-9441285 ## About the Role * 3-5+ years of experience in a cybersecurity, security engineering, or related technical IT role * Hands-on experience with SIEM, EDR, and vulnerability management tooling * Working knowledge of cloud platforms (AWS, Azure, or GCP) and cloud security best practices * Experience configuring and managing Web Application Firewalls * Solid understanding of networking fundamentals, TCP/IP, firewalls, and network segmentation * Familiarity with common frameworks and standards such as NIST CSF, MITRE ATT&CK, CIS Benchmarks, or ISO 27001 * Experience scripting or automating tasks in Python, Bash, or PowerShell * Strong analytical and problem-solving skills, with the ability to work calmly under pressure during incidents * Excellent written and verbal communication skills, with the ability to explain technical risk to non-technical stakeholders, * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience * Industry certifications such as CompTIA Security+, CompTIA CySA+, CISSP, CISM, GSEC, GCIH, OSCP, or AWS/Azure security certifications * Experience integrating security tooling into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins) * Prior experience supporting compliance audits (PCI DSS) * Background in threat intelligence, digital forensics, or red team/blue team exercises ## Description The Cybersecurity Engineer designs, implements, and operates the security controls that protect the organization's systems, networks, applications, and data. This is a hands-on, technical role that partners closely with IT, DevOps, and engineering teams to identify risk, respond to incidents, and continuously strengthen the company's security posture. The ideal candidate combines deep technical expertise with strong communication skills, translating complex security concepts into practical guidance that enables the business to move fast without compromising security., Security Engineering & Operations * Design, implement, and maintain security controls across cloud, on-premises, and SaaS environments * Deploy, configure, and manage security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and DLP platforms * Monitor security alerts and telemetry, investigate suspicious activity, and respond to incidents in accordance with defined SLAs * Tune detection rules and correlation logic to reduce false positives and improve signal quality * Perform root-cause analysis on security events and implement corrective, preventative actions * Maintain and continuously improve security architecture diagrams, network segmentation, and control documentation Incident Response * Participate in, and where appropriate lead, incident response efforts across the full lifecycle: detection, containment, eradication, and recovery * Triage alerts, contain active threats, and coordinate cross-functional recovery activities * Develop, test, and maintain incident response playbooks, runbooks, and communication procedures * Conduct post-incident reviews and blameless retrospectives, and drive follow-through on recommended improvements * Serve in an on-call rotation to support after-hours security incidents as needed Vulnerability & Risk Management * Perform recurring vulnerability scanning, penetration test coordination, and risk assessments across infrastructure and applications * Validate findings, assess business risk and exploitability, and prioritize remediation with asset owners * Conduct threat modeling and security architecture reviews for new systems and major changes * Track remediation through to closure and report on residual risk to stakeholders Cloud & Application Security * Secure cloud infrastructure (AWS, Azure, and/or GCP) and containerized/orchestrated environments (Docker, Kubernetes) * Implement and maintain IAM policies, secrets management, and least-privilege access models * Partner with engineering teams to embed security scanning (SAST, DAST, SCA, container scanning) into CI/CD pipelines * Review application designs, architecture, and code for security risks; provide actionable remediation guidance * Deploy, configure, and tune Web Application Firewalls (WAF) to protect public-facing applications and APIs * Develop and maintain WAF rule sets and policies to mitigate OWASP Top 10 risks, bot traffic, and DDoS attempts * Analyze WAF logs and blocked/allowed traffic to identify attack patterns and reduce false positives/negatives * Partner with application teams to onboard new services behind the WAF and validate rule coverage before go-live Compliance & Governance Support * Assist with audits and compliance initiatives * Collect and organize audit evidence, and help maintain security policies, standards, and documentation * Support vendor risk assessments and third-party security reviews * Help maintain the organization's risk register and control mapping Collaboration & Enablement * Work closely with IT, DevOps, and product teams to design and implement secure solutions * Provide practical, risk-based security guidance that enables delivery rather than blocking it * Contribute to security awareness and training initiatives, including phishing simulations and onboarding content * Act as a security point of contact and subject-matter resource for engineering and business teams ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)