← all jobs

Mainframe Security Engineer - ACF2 to RACF

Work from home Full-time role Hiring

Responsibilities

Kforce's client is seeking a Mainframe Security Engineer for a Remote or Hybrid (U.S.-based) role. This role will be Long-Term Contract or Full-Time. About the Role: We're looking for an experienced Mainframe Security Engineer to support a large-scale migration from CA-ACF2 and RC/Secure to IBM Security Server (RACF). This is a high-impact modernization initiative that enhances enterprise security and access management across IBM Z environments. You'll play a key role in planning, migrating, and validating security definitions that protect critical mainframe assets - collaborating with system administrators, application owners, and security teams to ensure a smooth, compliant, and secure transition. What You'll Do:

  • Lead the migration of CA-ACF2 and RC/Secure for DB2 to IBM Security Server (RACF)
  • Migrate and validate security definitions for user/system IDs, datasets, and subsystems (CICS, IMS, DB2)
  • Work with teams to export and convert ACF2 security databases at designated cutover points
  • Implement and test password propagation solutions to maintain user credentials during migration
  • Collaborate across system, network, and application teams to test, document, and promote RACF-based access control
  • Execute migration on a sysplex-by-sysplex basis, ensuring minimal disruption to production systems

Requirements

  • 5+ years of experience with mainframe security administration on z/OS
  • Hands-on expertise with CA-ACF2 and/or RACF (IBM Security Server)
  • Strong knowledge of z/OS, CICS, IMS, and DB2 subsystems
  • Understanding of security database migration, access control, and password management
  • Excellent analytical and troubleshooting skills in large, complex mainframe environments

Preferred Skills

  • Prior experience executing ACF2-to-RACF migrations or similar z/OS security conversions
  • Familiarity with CA-RC/Secure, IMS interfaces, or other IBM Z security tools
  • Knowledge of compliance frameworks (e.g., SOX, PCI, or NIST) within mainframe contexts
  • Ability to script or automate security administration tasks (REXX, CLIST, or Python on z/OS)

Why Join Us

  • Contribute to a strategic IBM Z security modernization program impacting thousands of enterprise users
  • Work with leading-edge IBM technologies in a large-scale transformation environment
  • Collaborate with cross-functional mainframe experts across engineering, operations, and DevSecOps
  • Competitive compensation, growth potential, and long-term project stability

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future. We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave. Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law. This job is not eligible for bonuses, incentives or commissions. Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.

More open positions

Cyber Fraud Fusion Center SME

Work from home Full-time role

Vendor Security Analyst

Work from home Full-time role

Manager - Penetration Tester

Work from home Full-time role

W2 Cybersecurity OT security Engineer - 40% Travel

Work from home Full-time role

Penetration Tester

Work from home Full-time role

Organiza experiencias de viajes grupales | Actividad independiente

Work from home Full-time role

Business Travel Consultant (Berlin or Remote) (Geschäftsreiseexperte)

Work from home Full-time role

PROFESSIONAL SERVICES FRANCHISE OPPORTUNITY, fractional C-Suite execs and part-time Directors

Work from home Full-time role

Experienced Data Entry Specialist – Content Management and Quality Assurance

Work from home Full-time role

Inbound Sales Development Representative

Work from home Full-time role

Junior Accountant

Work from home Full-time role

Inside Sales Professional - Remote (Base + Commission)

Work from home Full-time role

Director of Cyber Security Architecture and Engineering Services

Work from home Full-time role

Principal Hydrogeologist

Work from home Full-time role

Immediate Hiring: Experienced Customer Service Agent - Remote/Hybrid Opportunity at careerzynith

Work from home Full-time role

Special Project Coordinator

Work from home Full-time role

Workday Lead- Absence, & Time Tracking

Work from home Full-time role

Join Us Early — Fractional SDR Role at an Ecommerce Tech Startup Led by Industry Veterans

Work from home Full-time role

Clinical Consultant

Work from home Full-time role

Machine Learning Scientist, Multimodal AI

Work from home Full-time role

Sr Construction Manager - Site Development

Work from home Full-time role