Identity & Access Management Engineer

Brenham Ready Mix Inc
United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$125,000.0 - $159,000.0
Working hours
Regular working hours
Job source

Tech stack

User Authentication Customer Information Control System (CICS) Cyber Security Information Systems Data Files IBM DB2 Job Control Language (JCL) Rexx (Programming Language) Identity and Access Management Interactive System Productivity Facility (ISPF) PCI Data Security Standards IBM Resource Access Control Facility
+7 more
Role-Based Access Control User Provisioning Software Z/OS Scripting Software Application Delivery Information Technology Servicenow

Job description

The ideal candidate will have extensive experience with RACF administration, IBM zSecure, and mainframe identity management practices. This individual will work closely with cybersecurity, infrastructure, application, audit, and compliance teams to ensure secure access to critical mainframe resources while supporting governance initiatives, access reviews, and operational excellence., * Administer and maintain the IBM RACF security environment for enterprise z/OS systems.

  • Manage the complete identity lifecycle, including user provisioning, modifications, role changes, transfers, and deprovisioning.
  • Configure and maintain RACF User, Group, Resource, Dataset, CICS, and DB2 security profiles.
  • Configure and maintain RACF SETROPTS parameters to ensure compliance with enterprise security standards.
  • Implement and enforce least privilege, role-based access control (RBAC), and segregation of duties (SoD) principles across the mainframe environment.
  • Review, evaluate, and approve user access requests in accordance with established IAM governance processes and security policies.
  • Partner with business units, application teams, and cybersecurity to design and implement secure access models for new and existing applications.
  • Provide Tier 3 support for complex identity, authentication, authorization, and RACF-related incidents and service requests.
  • Troubleshoot access failures, permission conflicts, RACF violations, and authorization issues across production and non-production environments.
  • Utilize IBM zSecure to perform security administration, reporting, compliance monitoring, and audit support.
  • Support periodic access certifications, entitlement reviews, privileged access reviews, and audit activities.
  • Monitor compliance with internal security standards, regulatory requirements, and corporate IAM policies.
  • Develop and maintain RACF standards, operational procedures, security documentation, and technical guidelines.
  • Identify opportunities to automate IAM administration and reporting using REXX, JCL, and other mainframe utilities.
  • Participate in security projects, system upgrades, application implementations, and IAM modernization initiatives.
  • Collaborate with enterprise IAM, cybersecurity, infrastructure, and governance teams to strengthen the organization’s overall security posture.
  • Recommend and implement process improvements that enhance operational efficiency, security, and compliance.
  • Perform other duties as assigned

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field, or equivalent combination of education and experience.
  • 5+ years of experience administering IBM z/OS mainframe security environments.
  • Extensive hands-on experience administering RACF within enterprise mainframe environments.
  • Strong understanding of Identity and Access Management (IAM) principles and lifecycle processes.
  • Experience administering:
  • RACF User Profiles
  • Group Profiles
  • Resource Profiles
  • Dataset Profiles
  • CICS Security
  • DB2 Security
  • SETROPTS configuration
  • Strong understanding of authentication, authorization, identity governance, privileged access management, least privilege, and role-based access control.
  • Experience using IBM z/OS utilities including TSO, ISPF, JCL, and REXX.
  • Strong analytical and troubleshooting skills with the ability to diagnose and resolve complex access and security issues.
  • Experience supporting audit activities and regulatory compliance initiatives.
  • Excellent written and verbal communication skills with the ability to communicate effectively across technical and business teams.

Desired:

  • Experience administering IBM zSecure Administration and Audit.
  • Experience using ServiceNow for access requests, incident management, and change management.
  • Experience supporting Identity Governance and Administration (IGA) processes.
  • Experience supporting SOX, PCI DSS, NIST, ISO 27001, FFIEC, or other regulatory frameworks.
  • Experience with privileged access management (PAM) concepts and enterprise IAM governance.
  • Experience developing automation using REXX or other scripting languages.
  • Knowledge of enterprise mainframe operations, CICS, DB2, and z/OS security architecture.

Benefits & conditions

Tuition reimbursement, Health insurance, Paid time off, Vision insurance, Dental insurance, Life insurance, Disability insurance, Paid holidays Full-time Virginia, * Comprehensive Medical, Dental, and Vision Insurance

  • Employer-Paid Life Insurance
  • Employer-Paid Short-Term and Long-Term Disability Insurance
  • 401(k)
  • Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
  • Educational Assistance

Salary: 125k-159k Can be 100% remote in TX, VA, MD, DC, or FL High Profile roles may require candidates to fly to customer HQ for in person interview (expenses paid)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

3:28 min

Recognizing vital enterprise stability in legacy software development roles

Gunnar Grosch · Coffee With Developers

4:30 min

Evaluating developer experience constraints in native scripts

Steve Shadders · LIVE

Videos

See all

Related articles

See all