"For over four decades PAR Technology Corporation (NYSE PAR) has been a leader in restaurant technology empowering brands worldwide to create lasting connections with their guests. Our innovative solutions and commitment to excellence provide comprehensive software and hardware that enable seamless experiences and drive growth for over 100000 restaurants in more than 110 countries. Embracing our ""Better Together"" ethos we offer Unified Customer Experience solutions combining point-of-sale digital ordering loyalty and back-office software solutions as well as industry-leading hardware and drive-thru offerings. To learn more visit partech.com or connect with us on LinkedIn X (formerly Twitter) Facebook and Instagram.
PAR Technology is seeking a hands-on Senior DevOps Engineer to embed security into every stage of how we build ship and operate software. Sitting at the intersection of platform engineering and security this role owns the tooling automation and guardrails that enable product teams to move quickly without compromising the trust of the restaurant and retail brands that rely on PAR. You will design secure CI/CD pipelines and cloud infrastructure identify and remediate risk before it reaches production and help raise the security and reliability bar across the engineering organization. Position
Remote - New York Texas Philadelphia Florida North Carolina Minnesota Colorado Georgia Illinois Reports To Director DevOps
6-12 years of experience across DevOps platform engineering security engineering or a related field including at least 3 years focused on DevSecOps or application/cloud security in production environments. Deep hands-on experience with CI/CD platforms such as GitHub Actions GitLab CI Jenkins or Azure DevOps including embedding security tooling into delivery pipelines. Strong cloud engineering experience with AWS and/or Azure including IAM networking encryption logging and monitoring services. Production experience with Kubernetes and containers including securing clusters and workloads at scale. Proficiency with infrastructure-as-code tools such as Terraform or CloudFormation and at least one scripting or programming language such as Python Go or Bash. Solid networking fundamentals including TCP/IP DNS HTTP/HTTPS TLS routing firewalls security groups/NACLs segmentation and troubleshooting tools such as tcpdump dig and Wireshark. Hands-on cloud networking experience with VPC/VNet design load balancing ingress controllers private connectivity service mesh technologies and zero-trust network patterns. Experience operating observability platforms such as Prometheus Grafana ELK/OpenSearch or Datadog and using telemetry to improve reliability and security outcomes. Working knowledge of application security including the OWASP Top 10 dependency and software supply-chain risk secrets hygiene and secure SDLC practices. Experience with security scanning and monitoring tools such as Snyk Trivy SonarQube Wiz Prisma Cloud Falco or equivalent platforms. Clear pragmatic communication skills with the ability to explain risk and trade-offs to engineers and leaders and influence without direct authority. Additional
Security certifications such as CISSP CKS OSCP AWS Certified Security - Specialty Azure security certifications or GIAC networking certifications such as CCNA or AWS Certified Advanced Networking - Specialty. Experience with multi-region highly available architectures disaster recovery and chaos engineering practices. Experience in payments fintech retail or another PCI DSS-regulated environment. Exposure to zero-trust architectures SIEM/SOAR platforms or internal security platforms and paved-road tooling. Contributions to open-source security tooling or active participation in the security community. Unleash your potential What you will be doing and owning Design build and operate secure CI/CD pipelines with integrated SAST DAST SCA secrets scanning and container image scanning making the secure path the easy path for product teams. Harden and automate AWS and/or Azure infrastructure using infrastructure-as-code with security policies enforced through OPA Sentinel or native policy engines. Own container and orchestration security across Docker and Kubernetes including image provenance runtime protection network policies and admission controls. Implement and tune cloud security posture management vulnerability management and threat detection capabilities and partner with engineering teams to drive findings through remediation. Build and maintain secure secrets management identity workload identity service mesh mTLS and least-privilege access patterns. Lead threat modeling and secure design reviews for new services and architectures partnering with product engineering early in the development lifecycle. Respond to security events and lead post-incident analysis improving detection alerting and runbooks after each incident. Design and manage cloud networking including VPC/VNet architecture subnetting routing NAT peering transit gateways private endpoints and hybrid connectivity. Operate edge and traffic-layer security including load balancers API gateways WAF DDoS protection CDN configuration DNS management and TLS certificate lifecycle/PKI automation. Implement GitOps-based delivery using Argo CD or Flux with Helm/Kustomize and progressive delivery patterns such as blue-green and canary releases with automated rollback. Build and operate observability capabilities across metrics logging tracing and alerting with defined SLOs and actionable low-noise alerts. Manage artifact repositories and software supply-chain controls including image registries SBOM generation artifact signing and provenance using technologies such as Sigstore/Cosign and SLSA. Drive capacity planning autoscaling and cloud cost optimization across compute storage and network layers without compromising security. Champion compliance-relevant engineering controls including PCI DSS and SOC 2 and automate evidence collection wherever possible. Mentor engineers on secure coding and operational security practices acting as a force multiplier rather than a gatekeeper. Interview Process Interview 1 Video Screen with Talent Acquisition Team Interview 2 Video interview with the Hiring Manager (via MS Teams) Interview 3 Video interview with the Team (via MS Teams) PAR is proud to provide equal employment opportunities (EEO) to all employees and applicants for employment without regard to race color religion sex national origin age disability or genetics. We also provide reasonable accommodations to individuals with disabilities in accordance with applicable laws. If you require reasonable accommodation to complete a job application pre-employment testing a job interview or to otherwise participate in the hiring process or for your role at PAR please contact accommodations@partech.com. If you’d like more information about your EEO rights as an applicant please visit the US Department of Labor's website.
Range $135.5K - $175K"
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.