Job Summary
L3 Mainframe Security Engineer (z/OS)
About the Role
We are seeking a highly skilled L3 Mainframe Security Engineer to join our Mainframe Security team. This role is responsible for securing enterprise‑scale IBM z/OS environments and acts as the final escalation point for complex security issues. You will design, implement, and operate robust security controls aligned with regulatory and enterprise security standards.
Key Responsibilities
Key Responsibilities
-
Design, implement, and maintain z/OS security controls using RACF/ACF2/Top Secret.
-
Act as L3 escalation for mainframe security incidents, access issues, and policy violations.
-
Lead security hardening, access governance, and privileged access management.
-
Monitor and analyze security events using IBM zSecure and enterprise SIEM tools.
-
Support audits and compliance activities (SOX, PCI‑DSS, ISO 27001).
-
Manage certificates, encryption, and cryptographic services (ICSF/TKE, TLS, AT‑TLS).
-
Drive automation for security administration and reporting (Rexx/JCL/USS).
-
Collaborate with application, IAM, and infrastructure teams.
Skill Requirements
Required Skills & Experience
-
8+ years of IT experience with 5+ years in z/OS security.
-
Strong hands‑on experience with RACF/ACF2 / Top Secret).
-
Experience with IBM zSecure Admin/Audit/Alert.
-
Deep understanding of SAF, SMF
-
Knowledge of mainframe cryptography, certificates, and encryption.
-
Strong troubleshooting, incident response, and communication skills.
-
Automate with REXX/JCL.
-
Maintain runbooks and standards.
Nice to Have
-
IBM MFA for z/OS, PAM integrations
-
Experience with SIEM tools (QRadar, Splunk)
-
Knowledge of Db2, CICS, IMS security
-
Rexx / Python automation skills