> Markdown version of [/jobs/ext/2246587-direct-security-consultant](https://www.wearedevelopers.com/jobs/ext/2246587-direct-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Direct Security Consultant - **Company:** IBM - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Audit Trail, Authentication Protocols, Cyber Security, Data Files, File Transfer, Node.Js, IBM Resource Access Control Facility, Information Technology Security Auditing, User Provisioning Software, Z/OS, Data Logging, Transport Layer Security - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/0e0f7c0d-e7cf-4b6b-9b00-17ea2f02a1e7 ## About the Role Technical Expertise 8+ years of experience administering or securing IBM Connect: Direct for z/OS Strong knowledge of: IBM Connect: Direct architecture Secure File Transfer (Managed File Transfer) Connect: Direct configuration and administration Node definitions and process management Deep understanding of z/OS security. Mainframe Security Experience with one or more Enterprise Security Managers: RACF (Preferred) CA Top Secret (TSS) CA ACF2 Strong understanding of: Started Task security Dataset security Resource profiles User provisioning Least-privilege access models Security auditing Security Technologies Experience assessing: TLS/SSL Digital certificates Cryptographic configurations Secure communications Authentication mechanisms Authorization models Security monitoring and audit logging Preferred Qualifications Experience performing security assessments or security audits in enterprise mainframe environments. Familiarity with IBM z/OS infrastructure and enterprise networking. Knowledge of IBM security best practices for Connect: Direct. Experience in regulated industries such as banking, insurance, healthcare, or government. Security certifications (CISSP, CISA, or equivalent) are advantageous., The ideal candidate is a senior mainframe security consultant with extensive hands-on experience securing IBM Connect: Direct environments. They should have a strong understanding of z/OS security architecture, Enterprise Security Managers (RACF/ACF2/TSS), secure file transfer technologies, and enterprise security governance, with the ability to translate technical findings into clear, actionable recommendations for both technical and management stakeholders. ## Description We are looking for an experienced IBM Connect: Direct Security Consultant to support a security assessment engagement for a large US enterprise mainframe environment. The consultant will lead the security review of approximately 15 z/OS LPARs, focusing on the security posture, configuration, and governance of IBM Connect: Direct. The engagement will identify security risks, validate existing configurations, and provide actionable recommendations to improve the client's security posture. This is a consulting-focused role requiring deep expertise in IBM Connect: Direct on z/OS, enterprise security controls, and mainframe security best practices. Perform a comprehensive security assessment of IBM Connect: Direct environments across approximately 15 z/OS LPARs. Validate Connect: Direct node inventory, versions, configurations, connectivity models, and operational roles. Review security integration with Enterprise Security Managers (RACF, ACF2, or Top Secret), including: Started Task security Administrative authorities Process submission permissions Dataset access controls Privileged operations Assess authentication mechanisms and secure communications, including: TLS/SSL implementation Digital certificate management Secure protocol configuration Remote node definitions Trusted relationships Credential management practices Review Connect: Direct configuration datasets and operational settings. Evaluate logging, audit capabilities, monitoring, and operational security procedures. Identify: Excessive privileges Weak access controls Insecure file transfer paths Weak or outdated cryptographic configurations Configuration inconsistencies Security misconfigurations Analyze findings against IBM and industry security best practices. Develop a prioritized assessment report including findings, risk ratings, remediation recommendations, and implementation guidance. Present findings and recommendations to client technical stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introduction to TXT](https://www.wearedevelopers.com/videos/30-introduction-to-txt) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)