> Markdown version of [/jobs/ext/2934966-senior-mainframe-security-engineer-acf2](https://www.wearedevelopers.com/jobs/ext/2934966-senior-mainframe-security-engineer-acf2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Mainframe Security Engineer (ACF2) - **Company:** Brilliant - **Location:** Buffalo, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $80,900.0 - $101,100.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), COBOL (Programming Language), Cyber Security, Computer Engineering, Disaster Recovery, Rexx (Programming Language), Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Key Management, Mainframes, Scrum Methodology, IBM Resource Access Control Facility, Role-Based Access Control, Zero Trust Network Access, SAS (Software), Security Information and Event Management, System Programming, Systems Integration, Data Logging, Cyberark, QRadar, Information Technology, Easytrieve, SailPoint, Splunk, Programming Languages - **Published:** September 16, 2026 - **Apply:** https://www.careerjet.com/jobad/us3034ca9fb33f96eff00d8c4f6c1bdce9 ## About the Role * Combined minimum of 8 years' higher education and/or work experience in mainframe security administration, mainframe infrastructure, systems management and/or mainframe architecture * Ability to lead technical initiatives spanning multiple teams and organizations * Ability to influence technical decisions without direct authority * Ability to govern service accounts, batch logon IDs, privileged IDs, and other non-human identities throughout their lifecycle. * Demonstrated ability to translate technical risks into business impact for leadership audiences * Strong analytical and problem solving skills with focus on root cause analysis and remediation * Experience with Zero Trust, privileged access governance, and security monitoring concepts * Experience managing SSL/TLS digital certificates for internal and external mainframe services. Education and Experience Preferred: * Bachelor's degree in Computer Science or Computer Engineering * Minimum 10 years' professional experience in a Systems Programming, Security Engineering or Security Administration position. * Experience coding in multiple programming languages (EasyTrieve, Rexx, COBOL, EARL, SAS, Assembler, CA Utility) to support reports * Experience with report writing for ACF2 * Experience working in Financial Services * Experience with multiple ESM products * Highly adaptable, logical and creative personality * Excellent written and verbal communication skills * Ability to communicate complex technical methods/processes to various stakeholders in understandable terms * Critical understanding of service delivery and client needs * Ability to work independently and collaboratively with others in team environment * Understanding of how supported technologies interact with other systems and services * Effective influencing skills * Experience supporting Mainframe MFA solutions * Experience with privileged access management platforms such as CyberArk * Experience integrating mainframe security platforms with enterprise IAM solutions such as SailPoint * Experience with Splunk, QRadar, Elastic, or other SIEM technologies * Experience with API based identity integrations ## Description * Collaborate with Scrum Masters, Project Managers, Application Developers, and Systems Technology teams to design, implement, and validate security solutions for new and existing applications. * Participate in Mainframe Security strategy, roadmap development, and continuous improvement initiatives. * Develop and maintain security procedures, standards, documentation, and operational runbooks. * Support audits, regulatory examinations, and remediation activities related to access management and security controls. * Review, maintain, and distribute Mainframe Security recertification, compliance, and audit reports. * Serve as a subject matter expert for ACF2 security architecture, rule administration, CPF propagation, identity governance, privileged access management, and access controls. * Design and support role based access control (RBAC), entitlement governance, and access recertification processes. * Design, implement, and maintain security controls supporting compliance with corporate policies, regulatory requirements, and industry standards. * Support security monitoring, threat detection, incident response, and logging integration efforts in partnership with Cybersecurity teams. * Implement and maintain data protection controls, including encryption, key management, digital certificates, and secure communications. * Analyze and document application dependencies, resource ownership, and security mappings to support governance and auditability. * Facilitate technical engagements with vendors and business partners to deliver secure and effective solutions. * Provide Level 2 support for Identity and Access Management and Mainframe Security services. * Troubleshoot SailPoint IIQ and related identity governance solutions for complex provisioning and access issues. * Utilize security administration and recovery utilities to manage and recover access control data and security configurations. * Maintain expertise in Bank applications, development environments, vendor products, and emerging security technologies. * Collaborate with Cybersecurity, Infrastructure, and Identity teams to integrate mainframe security capabilities with enterprise security services. * Identify security risks, vulnerabilities, and control gaps and develop appropriate mitigation strategies. * Support disaster recovery planning, cyber recovery testing, resiliency exercises, and security validation activities. * Mentor and coach less experienced engineers, administrators, technicians, and integrators. * Pursue continuous professional development in Financial Services, cybersecurity, identity governance, and mainframe technologies. * Adhere to the Company's risk and regulatory standards and escalate issues. * Promote an inclusive work environment that reflects M&T Bank's values. * Provide support for high severity production incidents during business and non-business hours as required. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Building with IBM Bob](https://www.wearedevelopers.com/videos/100275-building-with-ibm-bob) - [".Net is too slow" was not an option](https://www.wearedevelopers.com/videos/100176-net-is-too-slow-was-not-an-option) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)