Negotiable
Undetermined
Remote
Remote or Armonk, New York
Summary: We're seeking an experienced Mainframe Security Engineer to lead a significant migration from CA-ACF2 and RC/Secure to IBM Security Server (RACF) in a remote role. This position is crucial for enhancing enterprise security and access management across IBM Z environments, requiring collaboration with various teams to ensure a compliant and secure transition. The role involves planning, migrating, and validating security definitions to protect critical mainframe assets. The ideal candidate will have extensive experience in mainframe security administration and a strong understanding of related subsystems.
Key Responsibilities:
- Lead the migration of CA-ACF2 and RC/Secure for DB2 to IBM Security Server (RACF)
- Migrate and validate security definitions for user/system IDs, datasets, and subsystems (CICS, IMS, DB2)
- Work with teams to export and convert ACF2 security databases at designated cutover points
- Implement and test password propagation solutions to maintain user credentials during migration
- Collaborate across system, network, and application teams to test, document, and promote RACF-based access control
- Execute migration on a sysplex-by-sysplex basis, ensuring minimal disruption to production systems
Key Skills:
- 5+ years of experience with mainframe security administration on z/OS
- Hands-on expertise with CA-ACF2 and/or RACF (IBM Security Server)
- Strong knowledge of z/OS, CICS, IMS, and DB2 subsystems
- Understanding of security database migration, access control, and password management
- Excellent analytical and troubleshooting skills in large, complex mainframe environments
- Prior experience executing ACF2-to-RACF migrations or similar z/OS security conversions
- Familiarity with CA-RC/Secure, IMS interfaces, or other IBM Z security tools
- Knowledge of compliance frameworks (e.g., SOX, PCI, or NIST) within mainframe contexts
- Ability to script or automate security administration tasks (REXX, CLIST, or Python on z/OS)
Salary (Rate): £54.00 hourly
City: Armonk
Country: United States
Working Arrangements: remote
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
RESPONSIBILITIES:
Kforce has a client that is seeking a Mainframe Security Engineer - ACF2 to RACF Migration for a long-term contract remote role.
Summary:
We're looking for an experienced Mainframe Security Engineer to support a large-scale migration from CA-ACF2 and RC/Secure to IBM Security Server (RACF). This is a high-impact modernization initiative that enhances enterprise security and access management across IBM Z environments. You'll play a key role in planning, migrating, and validating security definitions that protect critical mainframe assets - collaborating with system administrators, application owners, and security teams to ensure a smooth, compliant, and secure transition.
Responsibilities:
* Lead the migration of CA-ACF2 and RC/Secure for DB2 to IBM Security Server (RACF)
* Migrate and validate security definitions for user/system IDs, datasets, and subsystems (CICS, IMS, DB2)
* Work with teams to export and convert ACF2 security databases at designated cutover points
* Implement and test password propagation solutions to maintain user credentials during migration
* Collaborate across system, network, and application teams to test, document, and promote RACF-based access control
* Execute migration on a sysplex-by-sysplex basis, ensuring minimal disruption to production systems
REQUIREMENTS:
* 5+ years of experience with mainframe security administration on z/OS
* Hands-on expertise with CA-ACF2 and/or RACF (IBM Security Server)
* Strong knowledge of z/OS, CICS, IMS, and DB2 subsystems
* Understanding of security database migration, access control, and password management
* Excellent analytical and troubleshooting skills in large, complex mainframe environments
Preferred Skills:
* Prior experience executing ACF2-to-RACF migrations or similar z/OS security conversions
* Familiarity with CA-RC/Secure, IMS interfaces, or other IBM Z security tools
* Knowledge of compliance frameworks (e.g., SOX, PCI, or NIST) within mainframe contexts
* Ability to script or automate security administration tasks (REXX, CLIST, or Python on z/OS)
Why Join Us:
* Contribute to a strategic Z security modernization program impacting thousands of enterprise users
* Work with leading-edge technologies in a large-scale transformation environment
* Collaborate with cross-functional mainframe experts across engineering, operations, and DevSecOps
* Competitive compensation, growth potential, and long-term project stability
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.