Remotery

Mainframe Security Architect

atKyndrylRemoteCA flagCanadaFull-timeCybersecurity / Security EngineerSeniorLeadC$138.3k – C$188.3k/year

Posted Aug 4

This is a fully remote position, open to applicants in Canada.

📋 Description

• Oversee the architecture and implementation of mainframe security solutions for clients utilizing Kyndryl managed services.

• Assess and validate solutions proposed and recommended by the Kyndryl mainframe consulting team.

• Convert consulting recommendations into designs for managed services, including implementation strategies, runbooks, controls, support procedures, and plans for operational readiness.

• Offer architectural guidance across various IBM Z security domains, encompassing authentication, authorization, privileged access, protection, audit, monitoring, encryption, compliance, and cyber resilience.

• Support client environments utilizing RACF, ACF2, and Top Secret/TSS.

• Design and verify security patterns for mainframe access paths and workloads.

• Integrate mainframe security with enterprise security capabilities and operational processes.

• Establish operating models for enrollment, identity correlation, access reviews, exception handling, break-glass access, fallback, disaster recovery, monitoring, alerting, reporting, and steady-state support.

• Direct delivery teams throughout the phases of design, build, test, pilot, cutover, stabilization, and transition to run.

• Develop reusable Kyndryl assets, including reference architectures, discovery questionnaires, implementation checklists, SIEM mappings, exception models, test plans, runbooks, and criteria for operational readiness.

• Collaborate with client security architects and technical stakeholders to ensure controls are secure, practical, auditable, resilient, and compliant with managed services SLAs.


⛳️ Requirements

• Extensive experience in IBM Z / z/OS security architecture, engineering, or operations.

• In-depth hands-on expertise with at least one major mainframe External Security Manager: RACF, ACF2, or Top Secret/TSS.

• Proficient understanding of SAF, ESM integration, dataset security, general resource protection, privileged access, started tasks, service accounts, digital certificates, SMF, audit controls, and security administration.

• Over 10 years of experience securing mainframe subsystems and access paths.

• Familiarity with mainframe MFA, enterprise IAM integration, identity lifecycle management, access certification, RBAC, least privilege, privileged access, and governance of non-human identities.

• Experience integrating mainframe security with SIEM/SOC processes.

• Capability to design solutions that consider disaster recovery, high availability, fallback, exception handling, performance, password/passphrase policies, operational support, change management, and regulatory auditability.

• Background in managed services, outsourcing, consulting, financial services, insurance, government, healthcare, or other regulated enterprise environments.

• Strong communication and documentation skills, including the ability to create architecture diagrams, technical designs, implementation plans, runbooks, risk summaries, and executive-level updates.

• Preferred: experience with IBM Z MFA / zMFA, Broadcom Advanced Authentication Mainframe, Rocket MFA, or similar products.

• Preferred: familiarity with SailPoint, IBM Security Identity Governance and Intelligence, IBM Verify Identity Governance, or comparable platforms.

• Preferred: experience with IBM zSecure, Broadcom ACF2, Broadcom Top Secret, Broadcom Compliance Event Manager, Broadcom Trusted Access Manager for Z, BMC AMI Defender, Rocket Secure Host Access, Rocket z/Assure VAP, or equivalent tools.

• Preferred: knowledge of RACDCERT, ICSF, AT-TLS, TLS certificates, dataset encryption, key labels, CKDS/PKDS/TKDS, certificate lifecycle management, and cryptographic controls.

• Preferred: experience with security assessments, audit remediation, CIS/STIG/NIST/SOX/PCI compliance, pervasive encryption, quantum-safe encryption readiness, immutable copies, cyber vault, or cyber recovery.

• Preferred: working knowledge of JCL, REXX, CLIST, CARLa, TSO/ISPF, SDSF, JES2/JES3, SMF reporting, automation, ServiceNow, Ansible, or Git-based workflows.

• Bilingual English/French is an asset for engagements with Canadian clients.


🏝️ Benefits

• A flexible and supportive environment that prioritizes well-being.

• Be Well programs that support financial, mental, physical, and social health.

• Personalized development goals and ongoing feedback.

• Opportunities for certifications with Microsoft, Google, and Amazon.

• Coaching and hands-on learning experiences.

• Access to cutting-edge learning opportunities.

• Tools for career path planning and support for professional development.

• Performance-based incentives, discretionary bonuses, and potential additional perks and rewards as part of total compensation.

People also viewed

Legacy Community Health2 days ago

IT Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NeoGuardian2 days ago

Cyber Security Engineer I – Blue Team

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fresh Consulting2 days ago

Staff Software Engineer – Security, Cryptography

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CrowdStrike2 days ago

Staff AI Security Scientist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$235k – $350k/year
ApplyView job
CrowdStrike2 days ago

Security Advisor, Falcon Complete

AU flagAustralia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Supply Chimp2 days ago

Cybersecurity Specialist

PH flagPhilippines OnlyFull-timeCybersecurity / Security EngineerPHP 62.5k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers