Cooper’s Hawk Winery & Restaurants is building secure enterprise platforms that support hybrid operations across Azure, Oracle Cloud, Salesforce, and on-prem environments. This Information Security Engineer role focuses on protecting applications, cloud services, identity and access, and the tooling that helps keep business-critical systems resilient. The position is hybrid based in Downers Grove, IL, with a compensation range of USD 105,000 to 120,000 per year.
You will help strengthen security across the stack, from secure configurations and defense tooling to DevSecOps integration and threat detection tuning, while collaborating with MDR and SOC teams during monitoring and incident response.
What you’ll do
- Support the design, implementation, and maintenance of security controls across Cooper’s Hawk hybrid infrastructure, with emphasis on Microsoft Azure, Oracle Cloud (ERP, Simphony POS), and Salesforce Commerce Cloud, ensuring secure configurations and reduced attack surface.
- Develop and maintain secure configuration standards for cloud services, with a focus on Azure.
- Engineer and manage security tooling across cloud and on-prem, including Microsoft Defender for Endpoint, Defender for Identity, Cisco VPN, Meraki firewalls, and Cloudflare WAF.
- Embed security into the SDLC by integrating SAST, DAST, and SCA into GitHub and CI/CD pipelines, supporting threat modeling and code reviews to improve secure coding and strengthen APIs and customer-facing applications.
- Administer and fine-tune Cloudflare WAF policies, bot mitigation, and access rules to help address OWASP Top 10 risks, credential stuffing, and scraping attempts.
- Support identity and access controls across Azure Entra ID and on-prem Active Directory, including Conditional Access Policies, RBAC, Just-In-Time (JIT) access, and MFA enforcement.
- Monitor and respond to threats by tuning detections, assisting investigations, and coordinating incident containment and recovery with MDR and SOC teams.
- Perform and support vulnerability assessments and penetration testing, prioritize remediation based on risk, and track findings to closure.
- Contribute to security programs such as PCI-DSS audits, NIST CSF 2.0 alignment, and cloud security posture improvements.
- Continuously research CVE activity and evolving TTPs to update defenses and detection rules.
What you bring
- Bachelor’s degree in information security, Computer Science, or a related field, or equivalent practical experience.
- 3+ years of progressive experience in infrastructure and application security across hybrid (on-prem and cloud) environments.
- Technical experience with Windows Server and desktop platforms, including Active Directory and Entra ID, plus core networking fundamentals such as DNS, TCP/IP, VLANs, and VPNs.
- Experience with enterprise security tools covering areas such as EDR, IPS, IAM, DLP, and vulnerability management platforms.
- Knowledge of cloud security best practices with hands-on experience securing services in Azure and/or AWS.
- Understanding of application security principles, including the OWASP Top 10, secure SDLC practices, and securing APIs and web applications.
- Familiarity with integrating security into DevOps pipelines and managing cloud-native security controls, including WAFs, API gateways, and bot protection.
- Familiarity with Salesforce security configurations and securing SaaS platforms.
- Experience with SIEM, IDS/IPS, endpoint protection, firewalls, and security monitoring.
- Knowledge of compliance and risk frameworks, including PCI-DSS, NIST CSF, and SOX/ITGC.
- Strong communication and collaboration skills across technical and business teams.
Preferred qualifications
- Industry-recognized security certifications (examples include CISSP, CISM, CRISC, CCSK, or relevant cloud/security certifications).
- Experience in hospitality, restaurant, or retail.
- Experience with DevSecOps and secure CI/CD integration.
Compensation and schedule
$105,000 - $120,000 per year. Final salary offer will depend on experience depth, skill set, qualifications, and internal pay equity. This role supports a hybrid work week model (3 days in office, 2 days remote, depending on role).
Benefits
- Monthly Dining Allowance
- 50% Dining and Carryout
- 40% Retail Wine
- 20% Retail and Private Events
- Monthly Complimentary Wine Tasting for Two
- Medical, Prescription, Dental, Vision insurance plus Telemedicine and a Wellness Program
- 401(k) with Company Matching Retirement Savings Plan
- Supplemental Health Coverage (Voluntary Accident, Hospital Indemnity and Critical Illness)
- Flexible Savings Accounts (Health and Dependent Care)
- Health Savings Account
- Long-Term Disability; Voluntary Short-Term Disability
- Basic Life and AD&D insurance (with option to purchase additional coverage)
- Paid Parental Leave
- Highly competitive pay plus Team Member Incentives & Rewards
- Paid Time Off
- Tenure Recognition Program
- Complimentary Gym Membership in the RSC Building