> Markdown version of [/jobs/ext/2540378-mainframe-security-analyst](https://www.wearedevelopers.com/jobs/ext/2540378-mainframe-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mainframe Security Analyst - **Company:** The Bank of New York Mellon Corporation - **Location:** Pittsburgh, PA, United States - **Experience:** Expert - **Salary:** $136,448.0 - $170,560.0 - **Contract:** Temporary contract - **Skills:** Software System Penetration Testing, Confluence, JIRA, Cyber Security, Job Control Language (JCL), Rexx (Programming Language), Identity and Access Management, Mainframes, IBM Resource Access Control Facility, Microsoft SharePoint, Software Vulnerability Management, Z/OS, Syncsort, Information Technology - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a9b74726801e23f5 ## About the Role * 7-10+ years of experience with zSecure Audit * Strong hands-on experience with RACF required, with additional expertise in ACF2 and/or Top Secret (TSS) highly valued * Strong proficiency with REXX * Experience with JCL and IBM SyncSort * Experience leveraging z/OS RACF STIG and/or related hardening standards in security remediation efforts * Strong understanding of mainframe security frameworks, controls, and access management concepts * Demonstrated experience in vulnerability management, security remediation, or related mainframe security initiatives * Ability to analyze scan results, interpret audit findings, and translate technical issues into actionable remediation guidance * Strong written and verbal communication skills, including the ability to document processes and explain technical concepts clearly * Bachelor's degree in Computer Science or a related discipline required, or equivalent combination of education and significant relevant experience Preferred Experience * 10+ years of experience with ACF2 or Top Secret (TSS) * Experience with ICETOOL * Background in z/OS security consulting or penetration testing * Experience working in financial services or another regulated environment * Familiarity with JIRA, Confluence, and SharePoint * Experience partnering directly with data owners, business stakeholders, and client teams in security-focused initiatives ## Description BNY is seeking a Mainframe Security Analyst to support critical vulnerability management, hardening, and modernization initiatives across the bank's mainframe environment. This role will provide day-to-day tactical execution across security-focused projects, including detailed analysis of security-related data, documentation of project activities, and collaboration with engineering and information security teams to strengthen the control environment. This role is preferred to be based in Pittsburgh, PA, Lake Mary, FL, NYC or remote. The expectation is 4 days onsite per week for local candidates, with work hours aligned to 8:00 AM - 4:00 PM Eastern Time. Key Responsibilities * Mainframe Security Project Execution: Provide day-to-day tactical execution for mainframe security and vulnerability management projects, including detailed analytics, project tracking, asset modeling support, and required documentation updates. * Mainframe Security Subject Matter Expertise: Serve as a subject matter expert in z/OS mainframe security systems, including RACF, ACF2, and Top Secret (TSS), supporting teams with guidance on access control, security configuration, and remediation strategies. * Vulnerability Management Support: Partner with engineering, security, and data owner teams to identify, assess, and help remediate vulnerabilities affecting mainframe systems and data. * zSecure Audit Leadership: Leverage deep experience with zSecure Audit to perform scans, analyze reports, evaluate audit controls, and support hardening and compliance efforts across the environment. * z/OS Hardening & Security Standards: Determine and help implement security standards related to z/OS hardening, security controls, STIG-aligned remediation, and vulnerability reduction initiatives. * Automation & Modernization Enablement: Support automation and modernization efforts by developing or advising on solutions using REXX, JCL, IBM SyncSort, and ICETOOL where applicable. * Cross-Functional Collaboration: Act as a liaison between mainframe engineering teams, information security teams, and client/data owner stakeholders to ensure clear communication, effective risk remediation, and alignment on security priorities. * Training & User Support: Interface directly with client staff and data owners to answer day-to-day questions, provide training on home-grown vulnerability tooling and utility tools, and promote adoption of security processes. * Process Documentation & Governance: Create and maintain mainframe security processes, procedural documentation, and supporting materials to improve consistency, repeatability, and operational maturity. * Security Consulting & Assessment: Apply prior z/OS security consulting and/or penetration testing experience to help evaluate current-state controls and recommend improvements to strengthen mainframe security posture., This role offers the opportunity to play a meaningful part in strengthening BNY's mainframe security environment through vulnerability management, hardening, automation, and modernization efforts. You will work closely with engineering, information security, and business stakeholders to help protect critical data, improve control effectiveness, and build durable security processes across a complex enterprise environment. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [".Net is too slow" was not an option](https://www.wearedevelopers.com/videos/100176-net-is-too-slow-was-not-an-option) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)