> Markdown version of [/jobs/ext/1723577-mainframe-logical-security-engineer](https://www.wearedevelopers.com/jobs/ext/1723577-mainframe-logical-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mainframe Logical Security Engineer - **Company:** Kyndryl, Inc. - **Location:** Chicago, IL, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Data Analysis, Computer-Aided Audit Tools, Customer Information Control System (CICS), Cyber Security, Data Files, IBM DB2, Rexx (Programming Language), Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Key Management, Logical Security, Mainframes, IBM Resource Access Control Facility, Zero Trust Network Access, Security Information and Event Management, Single Sign-On, Systems Integration, TCP/IP, Z/OS, Transport Layer Security, Enterprise Software Applications, QRadar, Splunk - **Published:** July 1, 2026 - **Apply:** https://dejobs.org/x/x/3DD8E0B0404D4947BA82EA639E78CF89/job/ ## About the Role You're good at what you do and possess the required experience to prove it. However, equally as important - you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused - someone who prioritizes customer success in their work. And finally, you're open and borderless - naturally inclusive in how you work with others., * Strong hands-on experience with: * RACF administration on z/OS * Deep knowledge of: * RACF profiles, classes, and dataset security * User/group management and access control models * Experience with: * SMF data analysis * Security reporting and audit tools * Strong understanding of: * z/OS security concepts and system internals Preferred Experience: * Experience in banking or financial services environments * Exposure to: * ACF2 or Top Secret (nice to have) * SIEM tools (Splunk, QRadar, etc.) * Experience with: * Automation (REXX, Python) * Identity governance tools * Experience with enterprise-wide security transformations or IAM integration * Knowledge of Zero Trust or modern security frameworks * Experience supporting regulatory audits in large enterprises ## Description We are seeking a skilled Mainframe Logical Security Engineer to design, implement, and manage security controls across IBM z/OS environments. The role ensures the confidentiality, integrity, and availability of enterprise systems and data by enforcing robust access controls and complying with regulatory requirements. This role requires employees to live in or around the Plano, TX, Charlotte, NC, Richmond, VA, Jacksonville, FL, Pennington, NJ, Chicago, IL area. You will be responsible to be onsite 3 days a week. We will consider candidates who are willing to relocate to any of these areas. Responsibilities Include: * Administer and maintain RACF security environment across z/OS systems * Create, modify, and revoke: * User IDs * Groups * Resource profiles * Dataset and subsystem access permissions * Implement and maintain least-privilege access controls for: * Datasets * Applications (CICS, DB2, IMS, MQ) * System resources Security Controls & Compliance * Configure and maintain security policies aligned with enterprise standards * Perform periodic access reviews, audits, and compliance checks * Support regulatory compliance (e.g., SOX, PCI, HIPAA where applicable) * Implement data protection controls and access monitoring mechanisms Monitoring & Incident Response * Analyze security logs and reports: * SMF records * RACF reports * SIEM alerts * Investigate: * Access violations * Unauthorized access attempts * Security incidents * Troubleshoot and resolve: * Authorization failures * RACF-related abends or access issues Security Architecture & Integration * Secure mainframe subsystems and integrations: * CICS, DB2, IMS, MQ, TCP/IP, USS * Support integration with: * Enterprise IAM solutions * Single Sign-On (SSO) / MFA (where applicable) * Define and maintain RACF classes, profiles, and rules for system-wide protection Encryption & Advanced Security * Support: * Digital certificates * TLS/SSL configuration * ICSF (crypto services) at a high level Ensure secure key management and encryption practices ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)