About the role
Client is a global financial services firm that provides a wide range of investment banking, securities, wealth management, and investment management services. It is a prominent global financial services firm with a rich history and a strong presence in the financial industry.
The Client is committed to corporate responsibility and sustainability. It aims to make a positive impact on society through various initiatives, such as promoting environmental sustainability, supporting diversity and inclusion, and engaging in philanthropic activities.
Rate: $80.33/Hr
Job Description:
- The Mainframe Security team is seeking an experienced RACF Architect Consultant to join the team and lead strategic security solutioning and implementation across the IBM Z platform for a key security projects.
- As a consultant embedded within the Mainframe Security team, the ideal candidate will lead the assessment, scoping, and design of multiple RACF and z/OS UNIX System Services (USS) related security project solutions, translating security, audit, and business requirements into robust, forward-looking architectures. The consultant will have deep hands-on expertise with IBM RACF, IBM zSecure, and USS security, along with a strong command of the broader IBM Z security ecosystem, and the ability to define target-state designs, guide engineering teams through implementation, and ensure solutions are secure, resilient, and operationally sustainable.
- This engagement requires strong analytical, architectural, organizational, and communication skills, as well as the ability to work independently and influence infrastructure, security, application development, and operations teams.
- The role may require occasional off-hours support for project implementations, production changes, and critical security initiatives.
- 12 years of related experience, with demonstrated experience as a mainframe security architect or senior engineer leading the design and delivery of enterprise RACF and USS security solutions.
- Expert-level, hands-on knowledge of IBM RACF and IBM zSecure, including configuration, internals, reporting, administration, and the ability to architect and design end-to-end security solutions.
- Deep expertise in z/OS UNIX System Services (USS) security, including UNIXPRIV, file/directory permissions, BPX resources, and the design of least-privilege USS access models.
- Proven ability to lead solution architecture activities assessing current state, defining scope, producing target-state designs, and creating architecture and design documentation for RACF and USS security projects.
- Proficiency with JCL, REXX, and CARLa for automation, reporting, utilities, and security tooling development.
- Experience with core z/OS utilities and facilities, including TSO, ISPF, SDSF, and related operational tooling.
- Working knowledge of database technologies and query tools such as DB2, Sybase, and SQL.
- Experience implementing and supporting mainframe authentication and encryption capabilities, including digital certificates, key management, multifactor authentication, and related controls.
- Broad understanding of z/OS infrastructure disciplines, including systems programming, storage, networking, UNIX System Services, CICS, DB2, performance, and enterprise tooling.
- Strong understanding of Identity and Access Management best practices, including least privilege, privileged access management, access certification, segregation of duties, and vulnerability management principles.
- Ability to work independently, manage competing priorities, and deliver results with limited oversight.
- Strong project planning, organization, time management, and multitasking skills.
- Proficiency with Microsoft Office business applications, including Excel, Word, Access, and PowerPoint.
- Excellent verbal and written communication skills, with the ability to explain technical concepts to both technical and non-technical stakeholders.
- Collaborative team player who promotes a team-first mindset and contributes to an inclusive, respectful culture.
- Duties and responsibilities will include but are not limited to the following:
- Lead the assessment, scoping, and architectural design of strategic RACF and USS security project solutions, covering authentication, authorization, encryption, privileged access, and sensitive data protection.
- Define target-state architectures and technical designs, produce solution and design documentation, and guide engineering teams through build, validation, testing, and implementation.
- Support deployment of security solutions, including process changes, operational handoff, documentation, and training for security operations teams.
- Assess technical feasibility and trade-offs of proposed solutions, and recommend strategic approaches that meet security, operational, audit, and resiliency requirements.
- Collaborate with application development, security product owners, systems programming, database, CICS/MQ, business, and audit teams to gather requirements and implement effective security solutions.
- Create and maintain security monitoring, automation, and reporting solutions using tools such as IBM zSecure, Compliance Manager, Admin Express, multifactor authentication platforms, and key management capabilities.
- Monitor, analyze, and report on key performance indicators, control health, and operational trends; recommend preventative actions and process improvements as needed.
- Serve as the architectural subject matter expert on RACF, USS, and z/OS security controls, setting standards and guiding teams on mainframe security best practices for questions, issues, audit inquiries, and project requirements.
Non-benefitted (other than those mandated under state or federal law).Please note that this position does not include paid time off benefits. ApTask offers subsidized insurance coverage to our employees.
About ApTask:
ApTask is a leading global provider of workforce solutions and talent acquisition services, dedicated to shaping the future of work. As an African American-owned and Veteran-owned company, ApTask offers a comprehensive suite of services, including staffing and recruitment solutions, managed services, IT consulting, and project management. With a focus on excellence, collaboration, and innovation, ApTask provides unparalleled opportunities for professional growth and development. As a member of the ApTask team, you will have the chance to connect businesses with top-tier professionals, optimize workforce performance, and drive success across diverse industries. Join us at ApTask and be part of our mission to empower organizations to thrive while fostering a diverse and inclusive work environment.
Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.
Candidate Data Collection Disclaimer:
At ApTask, we prioritize safeguarding your privacy. As part of our recruitment process, certain Personally Identifiable Information (PII) may be requested by our clients for verification and application purposes. Rest assured, we strictly adhere to confidentiality standards and comply with all relevant data protection laws. Please note that we only collect the necessary information as specified by each client and do not request sensitive details during the initial stages of recruitment.
If you have any concerns or queries about your personal information, please feel free to contact our compliance team at [email protected].
Applicant Consent:
By submitting your application, you agree to ApTask's (www.aptask.com) Terms of Use and Privacy Policy, and provide your consent to receive SMS and voice call communications regarding employment opportunities that match your resume and qualifications. You understand that your personal information will be used solely for recruitment purposes and that you can withdraw your consent at any time by contacting us at 732-355-8000 or [email protected]. Message frequency may vary. Msg & data rates may apply.