Skip to main content
Back to Jobs

Mainframe Security Architect

Lead mainframe security architecture for Kyndryl managed-services clients

Lead the architecture and operationalization of mainframe security solutions for Kyndryl managed-services clients. Translate consulting recommendations into practical designs, implementation approaches, runbooks, controls, and operational readiness plans. Provide architecture guidance across IBM Z security domains including authentication, authorization, privileged access, dataset protection, audit, monitoring, encryption, compliance, and cybe...

Why This Role?

Create reusable Kyndryl assets such as reference architectures, discovery questionnaires, and operational readiness criteria

Key Responsibilities

  • Lead the architecture and operationalization of mainframe security solutions for managed-services clients
  • Translate consulting recommendations into practical designs, implementation approaches, runbooks, controls, and operational readiness plans
  • Provide architecture guidance across IBM Z security domains including authentication, authorization, privileged access, dataset and resource
  • Support client environments using RACF, ACF2, and Top Secret/TSS for key mainframe access paths and workloads
  • Define practical operating models for user enrollment, identity correlation, access reviews, exception handling, break-glass access, fallbac
  • Engage with client security architects and technical stakeholders to confirm proposed controls are secure, practical, auditable, resilient,

Requirements

  • Experience with IBM Z security domains including authentication, authorization, privileged access, dataset and resource protection
  • Experience with RACF, ACF2, and Top Secret/TSS
  • Experience designing and validating security patterns for mainframe access paths and workloads such as TSO, TN3270, CICS, Db2, IMS, MQ, FTP/
  • Experience integrating with enterprise security capabilities including MFA, identity lifecycle intelligence and governance, privileged acces
  • Ability to define practical operating models for user enrollment, identity correlation, access reviews, exception handling, break-glass acce
  • Experience creating reusable assets such as reference architectures, discovery questionnaires, implementation checklists, SIEM mappings, exc

Required Skills

mainframe securityibm zarchitecturecybersecurityracfacf2top secretTop Secret/TSSEnterprise Security Integration

Indonesia Context

Working Hours Overlap:
Flexible — work your own hours
See remote (USD) vs local pay →

Keywords

mainframe security architectIBM Z securityRACF ACF2 Top Secretmanaged services securityenterprise security integrationKyndryl mainframe
View Original Description from The Muse

Original description from The Muse

Who We Are At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world's leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people-Kyndryls-that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive. The Role Key Responsibilities Lead the architecture and operationalization of mainframe security solutions for Kyndryl managed-services clients. Work with the Kyndryl mainframe consulting team to validate solutions being designed, proposed, and recommended to clients. Translate consulting recommendations into practical managed-services designs, implementation approaches, runbooks, controls, support procedures, and operational readiness plans. Provide architecture guidance across IBM Z security domains, including authentication, authorization, privileged access, dataset and resource protection, audit, monitoring, encryption, compliance, and cyber resilience. Support client environments using RACF, ACF2, and Top Secret/TSS . Design and validate security patterns for key mainframe access paths and workloads, including TSO, TN3270, CICS, Db2, IMS, MQ, FTP/SFTP, SSH, USS, batch, JES, SDSF, started tasks, service IDs, vendor IDs, automation IDs, and privileged users . Support integration with enterprise security capabilities, including MFA, identity lifecycle intelligence and governance, privileged access management, SIEM/SOC monitoring, incident and change management, resilience, and compliance processes. Define practical operating models for user enrollment, identity correlation, access reviews, exception handling, break-glass access, fallback, DR, password/passphrase impacts, monitoring, alerting, reporting, and steady-state support. Guide delivery teams through design, build, test, pilot, cutover, stabilization, and transition-to-run. Create reusable Kyndryl assets such as reference architectures, discovery questionnaires, implementation checklists, SIEM mappings, exception models, test plans, runbooks, and operational readiness criteria. Engage with client security architects and technical stakeholders to confirm that proposed controls are secure, practical, auditable, resilient, and supportable under managed-services SLAs. Who You Are Required Skills and Experience Strong experience with IBM Z / z/OS security architecture, engineering, or operations . Deep hands-on knowledge of at least one major mainframe External Security Manager: RACF, ACF2, or Top Secret/TSS . Working knowledge across mainframe security concepts, including SAF, ESM integration, dataset security, general resource protection, privileged access, started tasks, service accounts, digital certificates, SMF, audit controls, and security administration . 10 + years experience securing mainframe subsystems and access paths such as CICS, Db2, IMS, MQ, USS, FTP/SFTP, SSH, TSO, TN3270, batch, JES, and SDSF . Experience with mainframe MFA, enterprise IAM integration, identity lifecycle management, access certification, RBAC, least privilege, privileged access, and non-human identity governance. Experience integrating mainframe security with SIEM/SOC processes , including security event forwarding, alerting, monitoring, investigation, and audit reporting. Ability to design solutions that account for DR, high availability, fallback, exception handling, performance, password/passphrase policies, operational support, change management, and regulatory auditability . Experience in managed services, outsourcing, consulting, financial services, insurance, government, healthcare, or other regulated enterprise environments. Strong communication and documentation skills, including architecture diagrams, technical designs, implementation plans, runbooks, risk

Salary Context

Similar Operations roles on LokerDollar pay around $183.75k/yr (range $24k–999.999k/yr, n=195 active listings).

Hiring at Kyndryl

Kyndryl has 73 other active roles on LokerDollar and has been hiring here since May 7, 2026 — across Operations, Design, Data & Analytics.

View all Kyndryl openings →
ℹ️ We couldn't verify this apply link yet. You can still try applying — check back later if it doesn't open.

Openness not stated by employer — check the listing

Company
Kyndryl
Source
The Muse
Job Type
full time
Location
Remote · Open worldwide
Category
Seniority
senior
PostedFresh
Aug 5, 2026

Share this job

Help a friend find their next remote role.

Frequently asked questions

Is Mainframe Security Architect at Kyndryl a remote job?
Yes. Mainframe Security Architect at Kyndryl is a fully remote role open to candidates worldwide.
What type of employment is Mainframe Security Architect at Kyndryl?
This is a full time position.
How do I apply?
Click the "Apply" button on this page to go to the official application at Kyndryl.

Explore related

Market data & reports

Salary & skill-demand research built from our own listings data.

From the blog

This apply link is not verified yet.