Mainframe Security Architect

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Kyndryl

Kyndryl

10,000+ employees

Founded 2021

💼 Consulting

📦 Logistics

🏥 Healthcare

Consulting • Logistics • Healthcare

Kyndryl is a leading IT infrastructure services provider, serving thousands of enterprise customers worldwide. The company specializes in designing, building, managing, and modernizing complex, mission-critical information systems. Kyndryl offers a range of services including IT consulting, cloud services, cybersecurity, data and AI solutions, and digital workplace transformation. With a strong focus on innovation, partnerships, and co-creation, Kyndryl helps businesses tackle IT complexity and drive operational excellence. The company operates across various industries such as automotive, healthcare, banking, and more, providing expertise and solutions to address industry-specific challenges. Kyndryl's global network and strategic alliances empower enterprises to adapt to the evolving technology landscape, ensuring their essential systems are reliable and efficient.

📋 Description

• Lead the architecture and operationalization of mainframe security solutions for Kyndryl managed-services clients • Validate solutions designed, proposed, and recommended by the Kyndryl mainframe consulting team • Translate consulting recommendations into managed-services designs, implementation approaches, runbooks, controls, support procedures, and operational readiness plans • Provide architecture guidance across IBM Z security domains, including authentication, authorization, privileged access, protection, audit, monitoring, encryption, compliance, and cyber resilience • Support client environments using RACF, ACF2, and Top Secret/TSS • Design and validate security patterns for mainframe access paths and workloads • Integrate mainframe security with enterprise security capabilities and operational processes • Define operating models for enrollment, identity correlation, access reviews, exception handling, break-glass access, fallback, disaster recovery, monitoring, alerting, reporting, and steady-state support • Guide delivery teams through design, build, test, pilot, cutover, stabilization, and transition-to-run • Create reusable Kyndryl assets including reference architectures, discovery questionnaires, implementation checklists, SIEM mappings, exception models, test plans, runbooks, and operational readiness criteria • Engage client security architects and technical stakeholders to ensure controls are secure, practical, auditable, resilient, and supportable under managed-services SLAs

🎯 Requirements

• Strong experience with IBM Z / z/OS security architecture, engineering, or operations • Deep hands-on knowledge of at least one major mainframe External Security Manager: RACF, ACF2, or Top Secret/TSS • Working knowledge of SAF, ESM integration, dataset security, general resource protection, privileged access, started tasks, service accounts, digital certificates, SMF, audit controls, and security administration • 10+ years of experience securing mainframe subsystems and access paths • Experience with mainframe MFA, enterprise IAM integration, identity lifecycle management, access certification, RBAC, least privilege, privileged access, and non-human identity governance • Experience integrating mainframe security with SIEM/SOC processes • Ability to design solutions accounting for disaster recovery, high availability, fallback, exception handling, performance, password/passphrase policies, operational support, change management, and regulatory auditability • Experience in managed services, outsourcing, consulting, financial services, insurance, government, healthcare, or other regulated enterprise environments • Strong communication and documentation skills, including architecture diagrams, technical designs, implementation plans, runbooks, risk summaries, and executive-level updates • Preferred: experience with IBM Z MFA / zMFA, Broadcom Advanced Authentication Mainframe, Rocket MFA, or equivalent • Preferred: familiarity with SailPoint, IBM Security Identity Governance and Intelligence, IBM Verify Identity Governance, or equivalent platforms • Preferred: experience with IBM zSecure, Broadcom ACF2, Broadcom Top Secret, Broadcom Compliance Event Manager, Broadcom Trusted Access Manager for Z, BMC AMI Defender, Rocket Secure Host Access, Rocket z/Assure VAP, or equivalent tools • Preferred: knowledge of RACDCERT, ICSF, AT-TLS, TLS certificates, dataset encryption, key labels, CKDS/PKDS/TKDS, certificate lifecycle management, and cryptographic controls • Preferred: experience with security assessments, audit remediation, CIS/STIG/NIST/SOX/PCI alignment, pervasive encryption, quantum-safe encryption readiness, immutable copies, cyber vault, or cyber recovery • Preferred: working knowledge of JCL, REXX, CLIST, CARLa, TSO/ISPF, SDSF, JES2/JES3, SMF reporting, automation, ServiceNow, Ansible, or Git-based workflows • Bilingual English/French is an asset for Canadian client engagements

🏖️ Benefits

• Flexible, supportive environment where well-being is prioritized • Be Well programs supporting financial, mental, physical, and social health • Personalized development goals and continuous feedback • Certifications with Microsoft, Google, and Amazon • Coaching and hands-on learning experiences • Cutting-edge learning opportunities • Career-path tools and professional development support • Performance-based incentives, discretionary bonuses, and other perks and rewards may be included in total compensation

Apply Now

Similar Jobs

🕒 Yesterday

NMI

201 - 500

💼 Consulting

📦 Logistics

📣 Marketing

Senior Staff Information Security Engineer helping shape security across AWS and on-premises infrastructure. Leading initiatives as a trusted technical authority for complex security architecture and engineering decisions.

🕒 Yesterday

LiveKit

11 - 50

🔌 API

🤖 Artificial Intelligence

📡 Telecommunications

🕒 2 days ago

EverCommerce

1001 - 5000

☁️ SaaS

🤝 B2B

📣 Marketing

Senior Security Engineer enhancing cybersecurity capabilities across multiple domains for EverCommerce. Collaborating with various teams to improve security posture in a growing environment.

🇨🇦 Canada – Remote

💵 $160k - $190k / year

💰 Private equity on 2019-08

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 4 days ago

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

Security Architect II managing security solutions for customers in Akamai's Professional Services team, integrating and optimizing security solutions for effective delivery lifecycles.

🇨🇦 Canada – Remote

💵 $92.9k - $167.1k / year

💰 Post-IPO Equity on 2001-07

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 5 days ago

Posh Technologies

51 - 200

🔌 API

🤖 Artificial Intelligence

🏦 Banking

Security Administrator handling security operations and compliance efforts for an AI-driven financial solutions company. Responsible for threat management and collaborating with a growing security team.