Overview
Skills
Job Details
RACF (Resource Access Control Facility) and ACF2 (Access Control Facility 2) are both security products used on mainframe systems, specifically z/OS and z/VM. RACF is a product of IBM, while ACF2 is developed by Broadcom. They both provide access control, authentication, and auditing for protected resources
Job Description:
We are seeking a seasoned Mainframe Security Administrator with expertise in RACF (Resource Access Control Facility) and ACF2 (Access Control Facility 2) to manage and maintain security across z/OS and z/VM environments. The ideal candidate will play a critical role in ensuring access controls, enforcing security policies, and auditing compliance for protected resources within enterprise mainframe systems.
Key Responsibilities:
- Administer and manage RACF and ACF2 security tools across multiple IBM z/OS and z/VM systems.
- Define, implement, and maintain user profiles, permissions, roles, and group access settings.
- Develop and enforce security rules and policies for mainframe resources, datasets, applications, and terminals.
- Perform security audits and regular reviews to ensure compliance with internal and external regulatory requirements.
- Troubleshoot and resolve access issues and security violations.
- Support incident response and forensic investigations related to mainframe security.
- Collaborate with system administrators, application developers, and compliance teams to ensure secure and seamless operations.
- Maintain detailed documentation of all security configurations and changes.
- Participate in risk assessments and contribute to security best practices for mainframe environments.
Required Qualifications:
- 5+ years of experience in mainframe administration with a focus on security.
- Hands-on experience with both IBM RACF and Broadcom ACF2 security products.
- Strong knowledge of z/OS, z/VM, TSO/ISPF, JCL, and SDSF.
- Experience with user provisioning, access control, and role-based access models.
- Familiarity with compliance requirements such as SOX, PCI-DSS, HIPAA, etc.
- Proficient in writing and maintaining security rules and access control lists.
- Excellent analytical, communication, and documentation skills.