Mainframe security architect / RACF Architect Consultant -Remote

Zealogics.com

$124K — $135K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of experience in mainframe security architecture or engineering, with track record in leading enterprise RACF and USS security solutions.
  • Expertise in IBM RACF and zSecure, covering configuration, reporting, and complete security architecture.
  • Deep knowledge of z/OS UNIX System Services security and least-privilege access models.
  • Proven ability to lead solution architecture, including assessments, scope definition, and documentation for security projects.
  • Proficiency in JCL, REXX, and CARLa for automating security tooling and reporting.
  • Familiarity with z/OS utilities like TSO, ISPF, and operational tooling.
  • Solid understanding of database technologies, including DB2 and SQL.

Responsibilities

  • Lead architectural design and scoping of RACF and USS security projects, focusing on authentication and data protection.
  • Define and document target-state architectures and guide teams through implementation processes.
  • Support deployment by providing training for security operations teams and ensuring operational handoff.
  • Evaluate technical feasibility of solutions, recommending approaches that meet security and audit needs.
  • Collaborate across teams to gather requirements and implement security solutions effectively.
  • Create security monitoring and reporting solutions using tools like IBM zSecure and multifactor authentication platforms.
  • Monitor and analyze operational trends and recommend improvements based on performance indicators.

Benefits

  • Collaborative and inclusive work culture promoting team success.
  • Opportunities for professional growth and skill enhancement through diverse projects.
  • Access to advanced security tools and technologies within a mainframe environment.
Full Job Description
Requirements:
  • 12+ years of related experience, with demonstrated experience as a mainframe security architect or senior engineer leading the design and delivery of enterprise RACF and USS security solutions.
  • Expert-level, hands-on knowledge of IBM RACF and IBM zSecure, including configuration, internals, reporting, administration, and the ability to architect and design end-to-end security solutions.
  • Deep expertise in z/OS UNIX System Services (USS) security, including UNIXPRIV, file/directory permissions, BPX resources, and the design of least-privilege USS access models.
  • Proven ability to lead solution architecture activities-assessing current state, defining scope, producing target-state designs, and creating architecture and design documentation for RACF and USS security projects.
  • Proficiency with JCL, REXX, and CARLa for automation, reporting, utilities, and security tooling development.
  • Experience with core z/OS utilities and facilities, including TSO, ISPF, SDSF, and related operational tooling.
  • Working knowledge of database technologies and query tools such as DB2, Sybase, and SQL.
  • Experience implementing and supporting mainframe authentication and encryption capabilities, including digital certificates, key management, multifactor authentication, and related controls.
  • Broad understanding of z/OS infrastructure disciplines, including systems programming, storage, networking, UNIX System Services, CICS, DB2, performance, and enterprise tooling.
  • Strong understanding of Identity and Access Management best practices, including least privilege, privileged access management, access certification, segregation of duties, and vulnerability management principles.
  • Ability to work independently, manage competing priorities, and deliver results with limited oversight.
  • Strong project planning, organization, time management, and multitasking skills.
  • Proficiency with Microsoft Office business applications, including Excel, Word, Access, and PowerPoint.
  • Excellent verbal and written communication skills, with the ability to explain technical concepts to both technical and non-technical stakeholders.
  • Collaborative team player who promotes a team-first mindset and contributes to an inclusive, respectful culture.


Key Activities

Duties and responsibilities will include but are not limited to the following:

  • Lead the assessment, scoping, and architectural design of strategic RACF and USS security project solutions, covering authentication, authorization, encryption, privileged access, and sensitive data protection.
  • Define target-state architectures and technical designs, produce solution and design documentation, and guide engineering teams through build, validation, testing, and implementation.
  • Support deployment of security solutions, including process changes, operational handoff, documentation, and training for security operations teams.
  • Assess technical feasibility and trade-offs of proposed solutions, and recommend strategic approaches that meet security, operational, audit, and resiliency requirements.
  • Collaborate with application development, security product owners, systems programming, database, CICS/MQ, business, and audit teams to gather requirements and implement effective security solutions.
  • Create and maintain security monitoring, automation, and reporting solutions using tools such as IBM zSecure, Compliance Manager, Admin Express, multifactor authentication platforms, and key management capabilities.
  • Monitor, analyze, and report on key performance indicators, control health, and operational trends; recommend preventative actions and process improvements as needed.
  • Serve as the architectural subject matter expert on RACF, USS, and z/OS security controls, setting standards and guiding teams on mainframe security best practices for questions, issues, audit inquiries, and project requirements.
Rate range -$60-$65

Similar Jobs

More Jobs at Zealogics.com

More Information Technology Jobs

Find similar Mainframe security architect / RACF Architect Consultant -Remote jobs: