Direct Security Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are looking for an experienced IBM Connect: Direct Security Consultant to support a security assessment engagement for a large US enterprise mainframe environment.
The consultant will lead the security review of approximately 15 z/OS LPARs, focusing on the security posture, configuration, and governance of IBM Connect: Direct. The engagement will identify security risks, validate existing configurations, and provide actionable recommendations to improve the client’s security posture.
This is a consulting-focused role requiring deep expertise in IBM Connect: Direct on z/OS, enterprise security controls, and mainframe security best practices.
Perform a comprehensive security assessment of IBM Connect: Direct environments across approximately 15 z/OS LPARs.
Validate Connect: Direct node inventory, versions, configurations, connectivity models, and operational roles.
Review security integration with Enterprise Security Managers (RACF, ACF2, or Top Secret), including:
Started Task security
Administrative authorities
Process submission permissions
Dataset access controls
Privileged operations
Assess authentication mechanisms and secure communications, including:
TLS/SSL implementation
Digital certificate management
Secure protocol configuration
Remote node definitions
Trusted relationships
Credential management practices
Review Connect: Direct configuration datasets and operational settings.
Evaluate logging, audit capabilities, monitoring, and operational security procedures.
Identify:
Excessive privileges
Weak access controls
Insecure file transfer paths
Weak or outdated cryptographic configurations
Configuration inconsistencies
Security misconfigurations
Analyze findings against IBM and industry security best practices.
Develop a prioritized assessment report including findings, risk ratings, remediation recommendations, and implementation guidance.
Present findings and recommendations to client technical stakeholders.
Requirements
Technical Expertise
8+ years of experience administering or securing IBM Connect: Direct for z/OS
Strong knowledge of:
IBM Connect: Direct architecture
Secure File Transfer (Managed File Transfer)
Connect: Direct configuration and administration
Node definitions and process management
Deep understanding of z/OS security.
Mainframe Security
Experience with one or more Enterprise Security Managers:
RACF (Preferred)
CA Top Secret (TSS)
CA ACF2
Strong understanding of:
Started Task security
Dataset security
Resource profiles
User provisioning
Least-privilege access models
Security auditing
Security Technologies
Experience assessing:
TLS/SSL
Digital certificates
Cryptographic configurations
Secure communications
Authentication mechanisms
Authorization models
Security monitoring and audit logging
Preferred Qualifications
Experience performing security assessments or security audits in enterprise mainframe environments.
Familiarity with IBM z/OS infrastructure and enterprise networking.
Knowledge of IBM security best practices for Connect: Direct.
Experience in regulated industries such as banking, insurance, healthcare, or government.
Security certifications (CISSP, CISA, or equivalent) are advantageous., The ideal candidate is a senior mainframe security consultant with extensive hands-on experience securing IBM Connect: Direct environments. They should have a strong understanding of z/OS security architecture, Enterprise Security Managers (RACF/ACF2/TSS), secure file transfer technologies, and enterprise security governance, with the ability to translate technical findings into clear, actionable recommendations for both technical and management stakeholders.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Walking Into The Era of Supply Chain Risks
What Are The Top Skills Required For Azure Developers?
9 Ways to Make Money Hacking