> Markdown version of [/jobs/ext/557597-senior-security-consultant-mainframe-penetration-tester](https://www.wearedevelopers.com/jobs/ext/557597-senior-security-consultant-mainframe-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Consultant (Mainframe Penetration Tester) - **Company:** NetSPI, LLC - **Location:** Minneapolis, MN, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Software System Penetration Testing, Podcasting, C++ (Programming Language), Customer Information Control System (CICS), Computer Programming, IBM DB2, Job Control Language (JCL), Rexx (Programming Language), Mobile Application Software, Job Entry Subsystem 2/3, Mainframes, IBM Resource Access Control Facility, Web Application Security, Z/OS, Information Technology - **Published:** June 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=89a327ae16d87fd4 ## About the Role Do you have experience in Web Application Security Testing?, Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting Mainframe testing, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices., * Bachelor's degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience * 3-5 years of experience in penetration testing, including network, web or mobile application testing * Experience with offensive toolkits used for network and application penetration testing * Strong communication skills, both verbal and written * Knowledge of z/OS fundamentals including, but not limited to: JCL, JES2, USS, Networking and at least one ESM (RACF, ACF2, Top Secret). Preferred Qualifications: * Programming experience in one or more of the following languages: Assembler, C, C++, REXX * Experience security or managing z/OS-based systems. * Experience with pentesting (PTAS) or other offensive security certifications. ## Description * Perform app, platform, CICS, Db2 or other z/OS-based penetration tests. * Create and deliver penetration test reports to clients * Collaborate with clients to create remediation strategies that will help improve their security posture * Research and develop innovative techniques, tools, and methodologies for penetration testing services * Participate in the ongoing development/enhancement of NetSPI services and processes, in addition to thought leadership (via blogs, presentations, white papers, webinars, podcast, vlogs and tweets) * Provide pre-sales support by assisting with scoping prospective engagements * Act as a resource for internal team members as it relates to in-depth technical questions or best practices * Responsible for QA activities in assigned service lines * Other duties as assigned ## Related Videos - [Data Fabric in Action - How to enhance a Stock Trading App with ML and Data Virtualization](https://www.wearedevelopers.com/videos/253-data-fabric-in-action-how-to-enhance-a-stock-trading-app-with-ml-and-data-virtualization) - [WeAreDevelopers LIVE - Local Transcriptions with Open-Source AI](https://www.wearedevelopers.com/videos/1905-wearedevelopers-live-local-transcriptions-with-open-source-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Why Developers Don't Care About Your Employer Brand and How to Fix it](https://www.wearedevelopers.com/videos/1724-why-developers-don-t-care-about-your-employer-brand-and-how-to-fix-it) - [Supercharge Your Developer Journey with Tiny Atomic Habits](https://www.wearedevelopers.com/videos/1071-supercharge-your-developer-journey-with-tiny-atomic-habits) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)