Full Job Description
As a member of the Cooper's Hawk Information Security Team, the Information Security Engineer - Application, Cloud, and Infrastructure Security will be responsible for protecting our enterprise systems and hybrid infrastructure including Azure, Oracle Cloud, Salesforce, and our on-premises environments.
This role focuses on securing systems, applications and services that support our business from the wine club, restaurant, website, mobile apps and the point-of-sale (POS). You'll help implement security best practices across cloud and on-prem platforms, ensuring data protection, regulatory compliance, and resilience against modern threats.
You'll collaborate with teams across Applications, Data & Digital and infrastructure & Operations to embed security into the fabric of our technology ecosystem.
What You'll Do:
• Assist in designing, implementing, and maintaining security controls across Cooper's Hawk's hybrid infrastructure, with a strong focus on Microsoft Azure, Oracle Cloud (ERP, Simphony POS), and Salesforce Commerce Cloud, ensuring secure configurations and minimal attack surface.
• Assist in developing and maintaining secure configuration standards for cloud services, with a focus on Azure.
• Engineer and manage security tooling across cloud and on-prem environments, including Microsoft Defender for Endpoint, Defender for Identity, Cisco VPN, Meraki firewalls, and Cloudflare WAF.
• Integrate security into the SDLC by embedding SAST, DAST, and SCA tools into GitHub and CI/CD pipelines, promoting secure coding through threat modeling and code reviews. Strengthen APIs and customer-facing applications, including those on Salesforce Commerce Cloud, using best practices.
• Administer and fine-tune Cloudflare WAF policies, bot mitigation, and access rules to protect against OWASP Top 10 threats, credential stuffing, and scraping attempts.
• Support identity and access controls across Azure Entra ID and on-prem Active Directory, including Conditional Access Policies, Role-Based Access Control (RBAC), Just-In-Time (JIT) access, and MFA enforcement.
• Monitor and respond to security threats by tuning detections, supporting investigations, and coordinating incident containment and recovery in collaboration with MDR and SOC teams.
• Perform and support regular vulnerability assessments and penetration testing, ensuring remediation is prioritized based on risk and tracked to closure.
• Assist in security projects, including PCI-DSS audits, NIST CSF 2.0 alignment and cloud security posture improvements.
• Continuously research emerging threats, CVEs, and TTPs, maintaining defenses and detection rules accordingly to stay ahead of the threat landscape.
What You'll Need:
• Bachelor's degree in information security, Computer Science, or a related field - or equivalent practical experience.
• 3+ years of progressive experience in infrastructure and application security within hybrid (on-prem and cloud) environments.
• Technical expertise with Windows Server and Desktop platforms, including Active Directory and Entra ID; solid understanding of core networking concepts such as DNS, TCP/IP, VLANs, and VPNs.
• Experience with enterprise security tools, including EDR, IPS, IAM, DLP, and vulnerability management platforms.
• Knowledge of cloud security best practices, with hands-on experience securing services in Azure and/or AWS.
• Understanding of application security principles, including the OWASP Top 10, secure SDLC practices, and securing APIs and web applications
• Knowledge of integrating security into DevOps pipelines and managing cloud-native security controls, WAFs, API gateways, and bot protection solutions.
• Familiarity with Salesforce security configurations and securing SaaS platforms.
• Experience with SIEM, IDS/IPS, endpoint protection, firewalls, and security monitoring tools.
• Knowledge of key compliance and risk frameworks, including PCI-DSS, NIST CSF, and SOX/ITGC.
• Strong communication, collaboration, and problem-solving skills with the ability to work across technical and business teams.
Preferred Qualifications
• Industry-recognized security certifications (e.g., CISSP, CISM, CRISC, CCSK, or relevant cloud/security certifications).
• Experience in the hospitality, restaurant, or retail industry.
• Familiarity with DevSecOps principles and secure CI/CD integration.
Compensation Range: $105,000 - $120,000. The final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity.
What You'll Get:
• Incredible Discounts:
• Monthly Dining Allowance
• 50% Dining and Carryout
• 40% Retail Wine
• 20% Retail and Private Events
• Monthly Complimentary Wine Tasting for Two
• Medical, Prescription, Dental, Vision Insurance plus Telemedicine and Wellness Program
• Company Matching 401(k) Retirement Savings Plan
• Supplemental Health Coverage (Voluntary Accident, Hospital Indemnity and Critical Illness)
• Flexible Savings Accounts- Health and Dependent Care
• Health Savings Account
• Long-Term Disability; Voluntary Short-Term Disability
• Basic Life and AD&D Insurance (with option to purchase additional coverage)
• Paid Parental Leave
• Highly Competitive Pay plus Team Member Incentives & Rewards
• Paid Time Off
• Tenure Recognition Program
• Complimentary Gym Membership in RSC Building
• Hybrid Work Week (3 days in office, 2 days remote, depending on role)