
Mainframe Security Architect
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Canada.
• Oversee the architecture and implementation of mainframe security solutions for clients utilizing Kyndryl managed services.
• Assess and validate solutions proposed and recommended by the Kyndryl mainframe consulting team.
• Convert consulting recommendations into designs for managed services, including implementation strategies, runbooks, controls, support procedures, and plans for operational readiness.
• Offer architectural guidance across various IBM Z security domains, encompassing authentication, authorization, privileged access, protection, audit, monitoring, encryption, compliance, and cyber resilience.
• Support client environments utilizing RACF, ACF2, and Top Secret/TSS.
• Design and verify security patterns for mainframe access paths and workloads.
• Integrate mainframe security with enterprise security capabilities and operational processes.
• Establish operating models for enrollment, identity correlation, access reviews, exception handling, break-glass access, fallback, disaster recovery, monitoring, alerting, reporting, and steady-state support.
• Direct delivery teams throughout the phases of design, build, test, pilot, cutover, stabilization, and transition to run.
• Develop reusable Kyndryl assets, including reference architectures, discovery questionnaires, implementation checklists, SIEM mappings, exception models, test plans, runbooks, and criteria for operational readiness.
• Collaborate with client security architects and technical stakeholders to ensure controls are secure, practical, auditable, resilient, and compliant with managed services SLAs.
• Extensive experience in IBM Z / z/OS security architecture, engineering, or operations.
• In-depth hands-on expertise with at least one major mainframe External Security Manager: RACF, ACF2, or Top Secret/TSS.
• Proficient understanding of SAF, ESM integration, dataset security, general resource protection, privileged access, started tasks, service accounts, digital certificates, SMF, audit controls, and security administration.
• Over 10 years of experience securing mainframe subsystems and access paths.
• Familiarity with mainframe MFA, enterprise IAM integration, identity lifecycle management, access certification, RBAC, least privilege, privileged access, and governance of non-human identities.
• Experience integrating mainframe security with SIEM/SOC processes.
• Capability to design solutions that consider disaster recovery, high availability, fallback, exception handling, performance, password/passphrase policies, operational support, change management, and regulatory auditability.
• Background in managed services, outsourcing, consulting, financial services, insurance, government, healthcare, or other regulated enterprise environments.
• Strong communication and documentation skills, including the ability to create architecture diagrams, technical designs, implementation plans, runbooks, risk summaries, and executive-level updates.
• Preferred: experience with IBM Z MFA / zMFA, Broadcom Advanced Authentication Mainframe, Rocket MFA, or similar products.
• Preferred: familiarity with SailPoint, IBM Security Identity Governance and Intelligence, IBM Verify Identity Governance, or comparable platforms.
• Preferred: experience with IBM zSecure, Broadcom ACF2, Broadcom Top Secret, Broadcom Compliance Event Manager, Broadcom Trusted Access Manager for Z, BMC AMI Defender, Rocket Secure Host Access, Rocket z/Assure VAP, or equivalent tools.
• Preferred: knowledge of RACDCERT, ICSF, AT-TLS, TLS certificates, dataset encryption, key labels, CKDS/PKDS/TKDS, certificate lifecycle management, and cryptographic controls.
• Preferred: experience with security assessments, audit remediation, CIS/STIG/NIST/SOX/PCI compliance, pervasive encryption, quantum-safe encryption readiness, immutable copies, cyber vault, or cyber recovery.
• Preferred: working knowledge of JCL, REXX, CLIST, CARLa, TSO/ISPF, SDSF, JES2/JES3, SMF reporting, automation, ServiceNow, Ansible, or Git-based workflows.
• Bilingual English/French is an asset for engagements with Canadian clients.
• A flexible and supportive environment that prioritizes well-being.
• Be Well programs that support financial, mental, physical, and social health.
• Personalized development goals and ongoing feedback.
• Opportunities for certifications with Microsoft, Google, and Amazon.
• Coaching and hands-on learning experiences.
• Access to cutting-edge learning opportunities.
• Tools for career path planning and support for professional development.
• Performance-based incentives, discretionary bonuses, and potential additional perks and rewards as part of total compensation.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.