Principal Cyber Security Engineer - Senior Mainframe RACF Engineer (Remote)

First Citizens
Raleigh, NC, United States
27 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$130,000.0
Working hours
Regular working hours

Tech stack

Systems Engineering User Authentication Customer Information Control System (CICS) CLIST Cyber Security Computer Programming Databases Data Files IBM DB2 Database Storage Structures Multi-Factor Authentication Job Control Language (JCL)
+11 more
Rexx (Programming Language) Mainframes IBM Resource Access Control Facility SAS (Software) System Programming Z/OS Tso/ispf File Transfer Protocol (FTP) Enterprise Software Applications Enterprise Integration Splunk

Job description

The Senior Mainframe RACF Engineer leads the design, implementation, and governance of RACF security controls across complex z/OS environments. This role requires expert-level RACF engineering, strong programming skills (REXX, IBM Utilities and RACF utilities, SAS, JCL, Splunk), and hands-on experience with digital certificate rotation automation, Multi-Factor Authentication (MFA) implementation, and enterprise reporting. The engineer partners with engineering, security, audit, infrastructure, and application teams to ensure resilient, compliant, and scalable mainframe security., * RACF Engineering - Architect, configure, and maintain RACF profiles, classes, permissions, and database structures across multi-LPAR environments.

  • Multifactor Authentication - Support MFA for mainframe access, including integration with Enterprise Identity providers, enforcement of strong authentication policies, and modernization of legacy authentication flows.
  • Digital Certificate Lifecycle - Manage certificate creation, renewal, rotation, and ring assignments; ensure secure integration with SFTP, and cross-platform authentication.
  • REXX Automation - Develop automation and tooling using REXX, CLIST, and TSO/ISPF to streamline RACF administration, compliance evidence collection, and operational workflows.
  • SAS Reporting - Build and optimize SAS programs for compliance reporting, audit evidence generation, access analytics, and RACF database insights.
  • Security Integration - Integrate RACF with DB2, CICS, and enterprise applications to ensure end-to-end security coverage.
  • Incident Response - Diagnose and resolve RACF-related issues; perform root-cause analysis and lead remediation for security events.
  • Audit & Compliance - Produce SOX/HIPAA/PCI evidence, lead reviews, and maintain defensible documentation for internal and external audits.
  • Authentication & Encryption Modernization - Drive modernization of authentication and cryptographic controls, including MFA and certificate lifecycle automation.
  • Mentorship & Documentation - Train junior engineers; support processes, standards, and engineering design documentation.

This job posting is expected to remain active for 30 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

Requirements

Bachelor’s Degree and 8 years of experience in Systems Engineering, Network, or Information Security OR High School Diploma or GED and 12 years of experience in Systems Engineering, Network, or Information Security

Preferred Skills:

  • 10+ years of mainframe experience with expert RACF knowledge (profiles, classes, permissions, command set).
  • Advanced proficiency in REXX, SAS, JCL, TSO/ISPF, and IBM utilities.
  • Hands-on experience with Vanguard specific tools.
  • Hands-on experience with MFA for mainframe access, including integration with enterprise identity providers.
  • Experience with dataset encryption, and cryptographic modernization.
  • Strong background in digital certificates, rings, and cross-platform authentication.
  • Proven ability to troubleshoot complex RACF issues and differentiate RACF vs. non-RACF root causes.
  • Experience supporting SOX, HIPAA, PCI, and internal audit requirements.
  • Strong analytical, communication, and documentation skills.
  • Experience defining enterprise RACF standards and reference architectures.
  • Systems programming experience.
  • Financial industry experience.

Benefits & conditions

The base pay for this position is generally between $130,000 and $190,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.firstcitizens.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:28 min

Recognizing vital enterprise stability in legacy software development roles

Gunnar Grosch · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:48 min

Modernizing massive legacy mainframe and IBM i codebases

Maximilian Jesch Maximilian Jesch · WWC Europe 2026

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

2:25 min

Engineering career path from embedded systems to banking

John Woods John Woods · LIVE

Videos

See all

Related articles

See all