Senior Devops Engineer
Summary
Senior DevSecOps Engineer embedding security into CI/CD pipelines, cloud infrastructure (AWS/Azure), and Kubernetes clusters for a restaurant technology leader.
For over four decades, PAR Technology Corporation (NYSE: PAR) has been a leader in restaurant technology, empowering brands worldwide to create lasting connections with their guests. Our innovative solutions and commitment to excellence provide comprehensive software and hardware that enable seamless experiences and drive growth for over 100,000 restaurants in more than 110 countries. Embracing our "Better Together" ethos, we offer Unified Customer Experience solutions, combining point-of-sale, digital ordering, loyalty and back-office software solutions as well as industry-leading hardware and drive-thru offerings. To learn more, visit or connect with us on LinkedIn, X (formerly Twitter), Facebook, and Instagram.
We are looking for a Senior DevOps Engineer to embed security into every stage of how PAR builds, ships, and operates software. You will sit at the intersection of platform engineering and security, owning the tooling, automation, and guardrails that let dozens of product teams move fast without compromising the trust of the brands and guests who rely on us. This is a hands-on senior role: you will design secure CI/CD and cloud infrastructure, hunt down risk before it reaches production, and raise the security bar for the entire engineering organization.
What You'll Do
Design, build, and operate secure CI/CD pipelines with integrated SAST, DAST, SCA, secrets scanning, and container image scanning — making the secure path the easy path for product teams.
Harden and automate cloud infrastructure (AWS and/or Azure) using infrastructure-as-code, with security policies enforced as code through tools such as OPA, Sentinel, or native policy engines.
Own container and orchestration security across Docker and Kubernetes: image provenance, runtime protection, network policies, and admission controls.
Implement and tune cloud security posture management, vulnerability management, and threat detection; drive findings to remediation with engineering teams.
Build and maintain secrets management, identity, and least-privilege access patterns (IAM, workload identity, service mesh mTLS).
Lead threat modeling and secure design reviews for new services and architectures; partner with product engineering early rather than auditing late.
Respond to and run post-incident analysis for security events; improve detection, alerting, and runbooks after every incident.
Design and manage cloud networking: VPC/VNet architecture, subnetting, routing, NAT, VPC peering and transit gateways, private endpoints/PrivateLink, and hybrid connectivity (site-to-site VPN, Direct Connect/ExpressRoute).
Operate edge and traffic-layer security: load balancers (ALB/NLB, NGINX, HAProxy), API gateways, WAF, DDoS protection, CDN configuration, DNS management, and TLS certificate lifecycle/PKI automation.
Implement GitOps-based delivery (ArgoCD or Flux) with Helm/Kustomize, and progressive delivery patterns such as blue-green and canary releases with automated rollback.
Build and run the observability stack — metrics, logging, tracing, and alerting (Prometheus, Grafana, ELK/OpenSearch, Datadog, or equivalents) — with SLOs and actionable, low-noise alerts.
Manage artifact repositories and software supply chain: image registries, SBOM generation, artifact signing and provenance (Sigstore/Cosign, SLSA).
Drive capacity, autoscaling, and cost optimization across compute, storage, and network layers without compromising the security posture.
Champion compliance-relevant engineering controls (e.g., PCI DSS, SOC 2) and automate evidence collection wherever possible.
Mentor engineers across teams on secure coding and operational security practices; act as a force multiplier, not a gatekeeper.
Unleash your Potential
6–10 years of experience across DevOps, platform, or security engineering, with at least 3 years focused on DevSecOps or application/cloud security in production environments.
Deep hands-on experience with CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins, Azure DevOps) and embedding security tooling into them.
Strong cloud engineering skills on AWS and/or Azure, including IAM, networking, encryption, and logging/monitoring services.
Production experience with Kubernetes and containers, including securing clusters and workloads at scale.
Proficiency with infrastructure-as-code (Terraform, CloudFormation, or similar) and at least one scripting/programming language (Python, Go, or Bash).
Solid networking fundamentals: TCP/IP, DNS, HTTP/HTTPS, TLS, routing and switching concepts, firewalls, security groups/NACLs, network segmentation, and troubleshooting with tools like tcpdump, dig, and Wireshark.
Hands-on cloud networking experience: VPC/VNet design, load balancing, ingress controllers, service mesh (Istio/Linkerd), private connectivity, and zero-trust network patterns.
Experience running observability tooling (Prometheus, Grafana, ELK, Datadog, or similar) and using it to drive reliability and security outcomes.
Working knowledge of application security: OWASP Top 10, dependency and supply-chain risk, secrets hygiene, and secure SDLC practices.
Experience with security scanning and monitoring tooling (e.g., Snyk, Trivy, SonarQube, Wiz, Prisma Cloud, Falco, or equivalents).
Clear, pragmatic communication — able to explain risk and trade-offs to both engineers and leadership, and to influence without authority.
Nice to Have
Security certifications such as CISSP, CKS, OSCP, AWS/Azure security specialty, or GIAC; networking certifications such as CCNA or AWS Advanced Networking.
Experience with multi-region, high-availability architectures, disaster recovery, and chaos engineering practices.
Experience in payments, fintech, retail, or other PCI DSS-regulated environments.
Exposure to zero-trust architectures, SIEM/SOAR platforms, or building internal security platforms and paved-road tooling.
Contributions to open-source security tooling or active participation in the security community.
Interview Process:
Interview #1: Phone Screen with Talent Acquisition Team
Interview #2: Video interview with the Technical Teams (via MS Teams/F2F)
Interview #3: Video interview with the Technical Teams (via MS Teams/F2F)
Interview #4: Video interview with the Hiring Manager (via MS Teams/F2F)
PAR is proud to provide equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. We also provide reasonable accommodations to individuals with disabilities in accordance with applicable laws. If you require reasonable accommodation to complete a job application, pre-employment testing, a job interview or to otherwise participate in the hiring process, or for your role at PAR, please contact accommodations@partech.com. If you’d like more information about your EEO rights as an applicant, please visit the US Department of Labor's website.
As published by ashby · 10 questions · 1 written answer
Basics
Name, Email, Resume, Current Location
Short answers (5)
- Phone Number
- LinkedIn Profile:
- Do you know anyone who works for us? optional
- What is your notice period?
- What is your total years of relevant experience? optional
Pick from a list (4)
- Are you fine working at Gurugram/Jaipur work location?
- Gender Identification
- Applicant Non-Disclosure Agreement In anticipation of my discussions with employees of PAR,[1] including certain members of PAR management, concerning employment opportunities with PAR, I acknowledge, agree, and confirm that: During the course of the interview process, I may receive information that is not known to the general public (“Confidential Information”) relating to PAR. Confidential Information may concern, among other things, PAR’s business plans, strategies and prospects, financial information, technology, product plans and developments, customers, vendors and other information, which should be reasonably considered as confidential (whether or not specifically labeled or designated). Confidential Information may be contained in tangible materials such as data, specifications, reports, and computer programs or may be in the nature of unwritten knowledge. Confidential Information may also include information of third-parties; I will not share any Confidential Information with anyone for any reason or purpose whatsoever; and I will not use any such Confidential Information for my own purposes or benefit or for the purposes or benefit of any person in any way; and I will treat Confidential Information provided to me prior to the date of this Non-Disclosure Agreement the same as Confidential Information provided to me on or after the date of this Nondisclosure Agreement. [1] PAR refers to PAR Technology Corporation (NYSE: PAR), together with its affiliates, including ParTech, Inc., Punchh Inc., AccSys LLC (f/k/a Restaurant Magic), and MENU Technologies A.G., as applicable, together with each of its parent, subsidiaries, and affiliates. Please click Yes below to confirm that you have read, understand, and will abide by the non-disclosure agreement above:
- Will you now or in the future require visa sponsorship for employment at PAR?
Written answers (1)
- Why do you want to work at PAR?