Enable job alerts via email!

Cloud Security Engineer (Mainframe Security Specialist)

NOVA Corporation

United States

Remote

USD 90,000 - 150,000

Full time

30 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is on the lookout for a skilled Cloud Security Engineer specializing in mainframe security. This pivotal role ensures that the migrated IBM Z environment meets stringent DoD security and compliance standards. You will be responsible for configuring mainframe security, applying security hardening guidelines, and integrating security into DevSecOps practices. With a focus on achieving necessary accreditations, this position offers a unique opportunity to work at the intersection of cloud and mainframe security. If you are passionate about safeguarding sensitive data and have a knack for compliance, this role is perfect for you.

Qualifications

  • 8+ years in IT security engineering with mainframe security experience.
  • Active DoD Secret clearance required for handling sensitive data.

Responsibilities

  • Configure mainframe security subsystems and enforce least privilege access.
  • Apply DoD security hardening guidelines and ensure compliance.

Skills

IT Security Engineering
Mainframe Security Administration
DevSecOps Tooling
Cloud Security Concepts
DoD Cybersecurity Requirements

Education

8+ years in IT Security Engineering
Active DoD Secret Clearance

Tools

RACF
ACF2
z/OS Compliance Checker Tools

Job description

Job Summary:

We are seeking a Cloud Security Engineer (Mainframe Security Specialist) who ensures the migrated IBM Z environment’s security and compliance posture is robust and meets DoD requirements. This role combines cloud security practices with mainframe security expertise. It involves configuring mainframe security (e.g. RACF/ACF2) and implementing continuous security controls and audits in line with DevSecOps principles. A key outcome is achieving the necessary accreditation (ATO) for the system to operate at Secret level.

This position is contingent upon contract award.

Job Duties and Responsibilities:
  • Security Configuration: Configure and manage mainframe security subsystems – defining RACF/ACF2 profiles, user roles, dataset access rules, and system privileges to enforce least privilege access. Implement multi-factor authentication or integration with enterprise identity management as required.
  • Compliance & Hardening: Apply DoD security hardening guidelines (e.g. DISA STIGs for z/OS) to the mainframe environment. Remediate any findings from security scans. Ensure all mainframe and hybrid cloud connections meet Secret-level encryption and security standards.
  • DevSecOps Integration: Embed security checks into CI/CD and infrastructure automation pipelines. Set up automated vulnerability scanning of mainframe code (if applicable) and configuration compliance scanning for the system (for example, using z/OS compliance checker tools). Ensure that security gates (SAST/DAST, config checks) are part of the deployment process.
  • ATO Documentation & Monitoring: Prepare and maintain documentation for the Risk Management Framework (RMF) to obtain Authority to Operate. This includes security control implementation statements, network diagrams, and access control lists for auditors. Post-implementation, continuously monitor security logs and alerts on the mainframe and cloud interfaces, and conduct periodic audits to ensure compliance is maintained.
  • Other duties as assigned.
Job Requirements (Education/Skills/Experience):
  • 8+ years in IT security engineering, with at least 3+ years in mainframe security administration (RACF, ACF2, or Top Secret administration on z/OS).
  • Familiarity with DoD cybersecurity requirements and processes (Security Technical Implementation Guides – STIGs, RMF/ATO process, NIST 800-53 controls).
  • Knowledge of cloud security concepts (network segmentation, encryption, zero-trust) and how to extend them to a mainframe environment.
  • Experience with DevSecOps tooling (CI/CD pipeline security scans, SIEM integration, automated compliance checks).
  • Clearance: Active DoD Secret clearance required (working with Secret data and security controls).

Preferred Qualifications:

  • Certifications such as CISSP, CISM or vendor-specific security certs (e.g. GIAC Mainframe Security, Certified Information Systems Security Officer).
  • Experience in hybrid environments (e.g. securing data flows between on-prem mainframes and cloud services).
  • Background in audit or security assessment roles, which helps in preparing thorough compliance documentation.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Information Security Engineer – Cloud - Remote

Caris Life Sciences

Remote

USD 125,000 - 180,000

Today
Be an early applicant

Senior Information Security Consultant

Brooksource

Remote

USD 80,000 - 100,000

10 days ago

Senior IT Security Engineer Remote - United States

Logix Federal Credit Union

Colorado

Remote

USD 110,000 - 130,000

2 days ago
Be an early applicant

Lead Security Engineer - Digital Workspace

Enterprise Holdings

St. Louis

Remote

USD 90,000 - 130,000

Yesterday
Be an early applicant

Lead Security Engineer - Digital Workspace

Enterprise Holdings Inc.

Missouri

Remote

USD 80,000 - 120,000

2 days ago
Be an early applicant

Security DevSecOps Specialist

Akkodis

Remote

USD 90,000 - 110,000

Today
Be an early applicant

Offensive Security Engineer

Employers Holdings

Remote

USD 80,000 - 115,000

2 days ago
Be an early applicant

Offensive Security Engineer

Plurilock

Remote

USD 90,000 - 110,000

2 days ago
Be an early applicant

Senior Software Engineer

Bitesize

Remote

USD 100,000 - 120,000

2 days ago
Be an early applicant