Enable job alerts via email!

Cloud Security Engineer (Mainframe Security Specialist)

NOVA Corporation

United States

Remote

USD 100,000 - 150,000

Full time

Today
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Cloud Security Engineer to ensure the security and compliance of IBM Z environments. The role entails configuring mainframe security systems, integrating DevSecOps practices, and ensuring adherence to DoD guidelines for operating at Secret level.

Qualifications

  • 8+ years in IT security engineering.
  • At least 3+ years in mainframe security administration.
  • Active DoD Secret clearance required.

Responsibilities

  • Configure and manage mainframe security subsystems.
  • Apply DoD security hardening guidelines to the mainframe.
  • Prepare and maintain documentation for the Risk Management Framework.

Skills

Security Configuration
Compliance
Cloud Security
DevSecOps
Risk Management Framework

Education

Bachelor's degree

Tools

z/OS compliance checker tools

Job description

Job Summary:

We are seeking a Cloud Security Engineer (Mainframe Security Specialist) who ensures the migrated IBM Z environment’s security and compliance posture is robust and meets DoD requirements. This role combines cloud security practices with mainframe security expertise. It involves configuring mainframe security (e.g. RACF/ACF2) and implementing continuous security controls and audits in line with DevSecOps principles. A key outcome is achieving the necessary accreditation (ATO) for the system to operate at Secret level.

Job Duties and Responsibilities:
  • Security Configuration: Configure and manage mainframe security subsystems – defining RACF/ACF2 profiles, user roles, dataset access rules, and system privileges to enforce least privilege access. Implement multi-factor authentication or integration with enterprise identity management as required.
  • Compliance & Hardening: Apply DoD security hardening guidelines (e.g. DISA STIGs for z/OS) to the mainframe environment. Remediate any findings from security scans. Ensure all mainframe and hybrid cloud connections meet Secret-level encryption and security standards.
  • DevSecOps Integration: Embed security checks into CI/CD and infrastructure automation pipelines. Set up automated vulnerability scanning of mainframe code (if applicable) and configuration compliance scanning for the system (for example, using z/OS compliance checker tools). Ensure that security gates (SAST/DAST, config checks) are part of the deployment process.
  • ATO Documentation & Monitoring: Prepare and maintain documentation for the Risk Management Framework (RMF) to obtain Authority to Operate. This includes security control implementation statements, network diagrams, and access control lists for auditors. Post-implementation, continuously monitor security logs and alerts on the mainframe and cloud interfaces, and conduct periodic audits to ensure compliance is maintained.
  • Other duties as assigned.
Job Requirements (Education/Skills/Experience):
  • Bachelor's degree
  • Certifications such as Security+, CISSP, CISM or vendor-specific security certs (e.g. GIAC Mainframe Security, Certified Information Systems Security Officer).
  • 8+ years in IT security engineering, with at least 3+ years in mainframe security administration (RACF, ACF2, or Top Secret administration on z/OS).
  • Familiarity with DoD cybersecurity requirements and processes (Security Technical Implementation Guides – STIGs, RMF/ATO process, NIST 800-53 controls).
  • Knowledge of cloud security concepts (network segmentation, encryption, zero-trust) and how to extend them to a mainframe environment.
  • Experience with DevSecOps tooling (CI/CD pipeline security scans, SIEM integration, automated compliance checks).
  • Clearance: Active DoD Secret clearance required (working with Secret data and security controls).

Preferred Qualifications:

  • Experience in hybrid environments (e.g. securing data flows between on-prem mainframes and cloud services).
  • Background in audit or security assessment roles, which helps in preparing thorough compliance documentation.

Diné Development Corporation (DDC) is a Navajo Nation owned family of companies that delivers IT, professional, and environmental solutions to advance the missions of federal, state, and tribal government agencies. As thought leaders and innovators, our team of specialists build client-centric solutions that solve critical challenges faced by defense, civilian, and healthcare organizations. Employing a mission-focused approach, we deliver value that not only enhances current operations, but also drives future change. Closely aligned with this approach is our commitment to advancing the Navajo Nation and its People. Through economic development and community empowerment, we elevate the Navajo Nation to provide lasting impact and sustainable growth for future generations. DDC’s ability to unite legacy-inspired technologies, industry best practices, and proven methodologies has contributed to our success for twenty years.

This contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, national origin, or for inquiring about, discussing, or disclosing information about compensation, or any other basis prohibited by law. We participate in E-Verify.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cloud Security Engineer

Altium

null null

Remote

Remote

USD 117,000 - 160,000

Full time

6 days ago
Be an early applicant

Remote: Oracle Cloud ERP and HCM Security Specialist

Visionary Innovative Technology Solutions LLC

null null

Remote

Remote

USD 100,000 - 140,000

Full time

5 days ago
Be an early applicant

Junior Network Security Engineer

Lensa

null null

Remote

Remote

USD 81,000 - 121,000

Full time

4 days ago
Be an early applicant

Junior Network Security Engineer

Lensa

null null

Remote

Remote

USD 70,000 - 110,000

Full time

4 days ago
Be an early applicant

Sr IT Security Engineer - Distributed Compute

Thermo Fisher Scientific

California null

Remote

Remote

USD 113,000 - 171,000

Full time

3 days ago
Be an early applicant

Remote Network Security Engineer

StopAHack.com

null null

Remote

Remote

USD 81,000 - 230,000

Full time

5 days ago
Be an early applicant

AWS Cloud Security Engineer

Swish Analytics

San Francisco null

Remote

Remote

USD 120,000 - 140,000

Full time

6 days ago
Be an early applicant

Network Security Engineer

Apex Systems

null null

Remote

Remote

USD 90,000 - 200,000

Full time

4 days ago
Be an early applicant

Mainframe Application Support Engineer – CMOD Specialist

DXC Technology Inc.

null null

Remote

Remote

USD 73,000 - 136,000

Full time

Today
Be an early applicant