Description
Ready to be part of something extraordinary? At Cooper’s Hawk, connection is at the heart of everything we do, and we’re looking for passionate people to join us.
When you become part of our team, you step into a collaborative, supportive culture built on Uncompromising Hospitality, where standards and genuine care come together to create something truly unforgettable.
As we continue our exciting journey, you’ll help us deliver unforgettable experiences to our Wine Club Members and the entire Cooper’s Hawk community.
Join us, and let’s turn moments into lasting memories.
As a member of the Cooper’s Hawk Information Security Team, the Information Security Engineer – Application, Cloud, and Infrastructure Security will be responsible for protecting our enterprise systems and hybrid infrastructure including Azure, Oracle Cloud, Salesforce, and our on-premises environments.
This role focuses on securing systems, applications and services that support our business from the wine club, restaurant, website, mobile apps and the point-of-sale (POS).
You’ll help implement security best practices across cloud and on-prem platforms, ensuring data protection, regulatory compliance, and resilience against modern threats.
You’ll collaborate with teams across Applications, Data & Digital and infrastructure & Operations to embed security into the fabric of our technology ecosystem.
What You’ll Do:
Assist in designing, implementing, and maintaining security controls across Cooper’s Hawk’s hybrid infrastructure, with a strong focus on Microsoft Azure, Oracle Cloud (ERP, Simphony POS), and Salesforce Commerce Cloud, ensuring secure configurations and minimal attack surface.
Assist in developing and maintaining secure configuration standards for cloud services, with a focus on Azure.
Engineer and manage security tooling across cloud and on-prem environments, including Microsoft Defender for Endpoint, Defender for Identity, Cisco VPN, Meraki firewalls, and Cloudflare WAF.
Integrate security into the SDLC by embedding SAST, DAST, and SCA tools into GitHub and CI/CD pipelines, promoting secure coding through threat modeling and code reviews.
Strengthen APIs and customer-facing applications, including those on Salesforce Commerce Cloud, using best practices.
Administer and fine-tune Cloudflare WAF policies, bot mitigation, and access rules to protect against OWASP Top 10 threats, credential stuffing, and scraping attempts.
Support identity and access controls across Azure Entra ID and on-prem Active Directory, including Conditional Access Policies, Role-Based Access Control (RBAC), Just-In-Time (JIT) access, and MFA enforcement.
Monitor and respond to security threats by tuning detections, supporting investigations, and coordinating incident containment and recovery in collaboration with MDR and SOC teams.
Perform and support regular vulnerability assessments and penetration testing, ensuring remediation is prioritized based on risk and tracked to closure.
Assist in security projects, including PCI-DSS audits, NIST CSF 2.0 alignment and cloud security posture improvements.
Continuously research emerging threats, CVEs, and TTPs, maintaining defenses and detection rules accordingly to stay ahead of the threat landscape.
What You’ll Need:
Bachelor’s degree in information security, Computer Science, or a related field – or equivalent practical experience.
3+ years of progressive experience in infrastructure and application security within hybrid (on-prem and cloud) environments.
Technical expertise with Windows Server and Desktop platforms, including Active Directory and Entra ID; solid understanding of core networking concepts such as DNS, TCP/IP, VLANs, and VPNs.
Experience with enterprise security tools, including EDR, IPS, IAM, DLP, and vulnerability management platforms.
Knowledge of cloud security best practices, with hands-on experience securing services in Azure and/or AWS.
Understanding of application security principles, including the OWASP Top 10, secure SDLC practices, and securing APIs and web applicationsKnowledge of integrating security into DevOps pipelines and managing cloud-native security controls, WAFs, API gateways, and bot protection solutions.
Familiarity with Salesforce security configurations and securing SaaS platforms.
Experience with SIEM, IDS/IPS, endpoint protection, firewalls, and security monitoring tools.
Knowledge of key compliance and risk frameworks, including PCI-DSS, NIST CSF, and SOX/ITGC.
Strong communication, collaboration, and problem-solving skills with the ability to work across technical and business teams.
Preferred Qualifications
Industry-recognized security certifications (e.g., CISSP, CISM, CRISC, CCSK, or relevant cloud/security certifications).
Experience in the hospitality, restaurant, or retail industry.
Familiarity with DevSecOps principles and secure CI/CD integration.
Compensation Range: $105,000 - $120,000.
The final offered salary will be based on several factors, including but not limited to the candidate’s depth of experience, skill set, qualifications, and internal pay equity.
What You’ll Get:
Incredible Discounts:Monthly Dining Allowance50% Dining and Carryout40% Retail Wine20% Retail and Private EventsMonthly Complimentary Wine Tasting for Two Medical, Prescription, Dental, Vision Insurance plus Telemedicine and Wellness ProgramCompany Matching 401(k) Retirement Savings PlanSupplemental Health Coverage (Voluntary Accident, Hospital Indemnity and Critical Illness)Flexible Savings Accounts- Health and Dependent CareHealth Savings Account Long-Term Disability; Voluntary Short-Term DisabilityBasic Life and AD&D Insurance (with option to purchase additional coverage)Paid Parental LeaveHighly Competitive Pay plus Team Member Incentives & Rewards Paid Time Off Tenure Recognition ProgramComplimentary Gym Membership in RSC BuildingHybrid Work Week (3 days in office, 2 days remote, depending on role)
Cooper’s Hawk is an equal opportunity employer. All qualified applicants are considered for employment without regard to the person’s race, color, religion, national origin, sex, sexual orientation, age, marital status, veteran status, disability, or any other characteristic protected by applicable law.
Cooper’s Hawk makes reasonable accommodations during all aspects of the employment process, including during the interview process.
The information provided above indicates the general nature and level of work required of the position and is not a comprehensive list of all responsibilities or qualifications.
The Benefits list is only a highlight of some of the benefits offered to team members; eligibility for certain benefits apply.
About Us
Cooper's Hawk features a Napa-style tasting room with wine-inspired retail for entertaining and a full-service restaurant, bar and private event space, offering a modern-yet-casual dining experience.
Each scratch-kitchen menu item is designed to pair with our wines.
Speaking of wine...the Cooper's Hawk Wine Club is perhaps the largest in the world, offering not only top-notch award-winning wines but also exclusive Wine Club membership benefits, including curated dining and travel experiences.
Since 2005, we've brought the Napa Valley experience to our guests and Wine Club members, and now, with Piccolo Buco by Cooper’s Hawk, we’re bringing the vibrant flavors of Rome to them as well.
Together, we’re creating a lifestyle brand like no other.