Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Mainframe Security Architect image - Rise Careers
Job details

Mainframe Security Architect

KyndrylAt Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.The RoleAre you passionate about security architecture and driven to protect against the latest threats? We are seeking a Security Architect who will join our team and take the lead on developing, implementing, and maintaining our security strategy within our Service Provider organization.As our Security Architect, you will work closely with our leadership team to design and implement effective security solutions that not only protect our business objectives and regulatory requirements, but also provide innovative solutions to stay ahead of emerging threats. You will conduct risk assessments and threat modeling to identify and prioritize risks to our business and IT assets, using your extensive experience in security architecture design and implementation within a Service Provider environment to create a cutting-edge security architecture framework.Your role will also involve conducting security reviews of vendors and third-party partners to ensure they meet our rigorous security standards, as well as performing regular security and risk reviews of our Service Provider environment to identify vulnerabilities and recommend remediation activities.At the forefront of security trends and technologies, you will advise our senior leadership team on the latest security best practices, and stay ahead of emerging security threats, always keeping our organization one step ahead.Who You AreYou’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.Required Technical and Professional Expertise• Experience in working on Mainframe services delivery or consulting• Experience in working with global teams, including presentation and client-facing roles• Experience on the Z platform, with a focus on z/OS, and knowledge/experience on other domains such as database, middleware, storage, network, and performance• Working knowledge of Mainframe ESM such as RACF/ACF2/TopSecret, including the basics, commands, operations, capabilities, and integrations• Knowledge on Z security concepts, such as PR/SM Virtualization, Common Criteria, HMC/SE Security, SAF, APF, Problem State vs. Supervisor State, Supervisor Calls, ACEE, SMF, Role-based Access, Principle of Least Privilege, Privileged Access Management, Database/Middleware/Network Security• Good English communication skill to handle meetings with clients, partners and co-workersTheoretical or Practical knowledge on some (if not all) of the following Mainframe Security concepts/technologies:• ESM Management - ESM DB Sharing/Clustering/Plex, ESM Migrations, DB2 ESM Security Management, Failure Recovery, Disaster Recovery, Reporting, Auditing, Exits• Mainframe IAM - Passphrases, MFA, Digital Certificate Management, Password Tokens (including JWT), Single Sign-on, and Enterprise Integrations (LDAP)• Encryption Management - Symmetric/Asymmetric Encryption (methods and algorithms), Key Management aspects (including KMS such as UKO, SKLM), Data-at-rest/Data-in-transit/Data-in-memory encryption methods, Pervasive Encryption Features, z/OS Dataset Encryption, zERT, Database Encryption, Secure Key Operations, ICSF, Key Datasets (PKDS/CKDS/TKDS), CPACF, Crypto Adapters, TKE, Data Compression (zEDC), and awareness of Advanced Z Encryption Capabilities (such as Quantum-safe Encryption, Secure Boot, Fully Homomorphic Encryption, Data Privacy Passports)• Mainframe Security Intelligence/Monitoring - Security Healthchecks, Monitoring Solutions (such as IBM zSecure, Broadcom CEM, or BMC AMI), SIEM Integration• Mainframe Security Patch Management - IBM Security/Integrity APAR Confidentiality, z/OS System Integrity Statement, Z Security Portal, Major Vulnerability Handling, and ISV/OEM Software security patch management.• Mainframe Security Compliance/Privacy Management concepts - Regulatory Standards/Policies (NIST/PCI/HIPAA/GDPR/DORA), Vulnerability scanning, Penetration testing, Solutions such as zSCC/DPfD/zCT• Other security concepts - Zero Trust Framework, DevSecOps on Z, Threat Analytics, Fraud detection, Ransomware protection, Breakglass Logon, AI adoption in Z Security, Hyperscaler Integrations, API Security, Network Security (Intrusion Detection/Prevention, IPSec, IP Filtering, SSL/AT-TLS, Port Control), Solutions such as zACS/zACM/VAP• Data Resiliency concepts - Security vs. Resiliency, File Integrity Monitoring, Immutable Copies, Disaster Recovery, Data Replication, RTO/RPO, Replication/Resiliency Solutions (GDPS/Safeguarded Copy/Cyber Vault/LWORM)Diversity is a whole lot more than what we look like or where we come from, it’s how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we’re not doing it single-handedly: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you – and everyone next to you – the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That’s the Kyndryl Way.What You Can ExpectWith state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter – wherever you are in your life journey.#J-18808-Ljbffr

Average salary estimate

Estimate provided by employer
$183500 / ANNUAL (est.)
min
max
$107K
$260K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Mainframe Security Architect, Kyndryl

Are you ready to take the lead as a Mainframe Security Architect at Kyndryl in Bee Ridge, IN? This is more than just a role; it's an opportunity to be at the forefront of security architecture, protecting mission-critical technology systems for clients worldwide. At Kyndryl, we believe in innovation and pushing the boundaries of what’s possible. As a Mainframe Security Architect, you'll be integral in developing and maintaining a cutting-edge security strategy within our Service Provider organization. You will evaluate risks, conduct threat modeling, and design effective security solutions that satisfy both business objectives and regulatory requirements. Your expertise will guide the team in identifying vulnerabilities, ensuring our security strategies are not only robust but also proactive against emerging threats. Collaborating with vendors and assessing their security compliance will be key to ensuring our standards are met across the board. You’ll also keep our leadership informed on the latest security trends and best practices, shaping the future of our operations. If you have experience working with Mainframe services, especially on the Z platform and a solid understanding of ESM and IAM management, we want you! Being customer-focused and embracing a growth mindset are vital traits that will help elevate the collaborative environment we cherish at Kyndryl. Excited to join a company that values inclusion, innovation, and your personal development? Then Kyndryl is the place for you!

Frequently Asked Questions (FAQs) for Mainframe Security Architect Role at Kyndryl
What are the key responsibilities of a Mainframe Security Architect at Kyndryl?

As a Mainframe Security Architect at Kyndryl, you will lead the design and implementation of security strategies within our Service Provider environment. Your core responsibilities will include conducting risk assessments, threat modeling, security reviews of third-party vendors, and advising senior leadership on security best practices. You'll also develop effective security solutions to protect critical business assets and ensure alignment with regulatory requirements.

Join Rise to see the full answer
What qualifications are required for the Mainframe Security Architect position at Kyndryl?

To qualify for the Mainframe Security Architect role at Kyndryl, candidates should possess extensive experience in Mainframe services delivery, particularly on the Z platform and z/OS. Knowledge of security concepts related to Mainframe ESM, IAM, and encryption methods is crucial. Strong communication skills for client-facing roles and a collaborative mindset are also essential for this position.

Join Rise to see the full answer
How does Kyndryl support the professional development of Mainframe Security Architects?

At Kyndryl, we are committed to supporting the professional development of our Mainframe Security Architects. We provide state-of-the-art resources and encourage our team members to pursue continuous learning opportunities, including training in emerging security trends and technologies. Our inclusive culture also fosters mentorship and collaboration, ensuring you can drive your professional growth.

Join Rise to see the full answer
What is the work culture like for a Mainframe Security Architect at Kyndryl?

The work culture for a Mainframe Security Architect at Kyndryl is dynamic, inclusive, and geared towards innovation. We emphasize collaboration across teams and encourage a growth mindset among employees. Our commitment to diversity ensures a range of perspectives and ideas, fostering an environment where everyone can thrive and contribute meaningfully to our client's success.

Join Rise to see the full answer
What types of technologies does a Mainframe Security Architect at Kyndryl work with?

A Mainframe Security Architect at Kyndryl works with a variety of advanced technologies including Mainframe ESM tools like RACF, ACF2, and TopSecret. You'll also engage with IAM practices, encryption management tools, and security monitoring solutions like IBM zSecure. Familiarity with regulatory standards such as NIST and PCI is also valuable as you develop security strategies in a compliant manner.

Join Rise to see the full answer
Common Interview Questions for Mainframe Security Architect
Can you describe your experience with Mainframe security and how it relates to the role of a Security Architect?

When answering this question, highlight specific projects where you worked with Mainframe security technologies, mentioning tools and methodologies you used. Relate your experience to security best practices and how you've implemented secure solutions in previous roles, showing how this aligns with the Mainframe Security Architect position at Kyndryl.

Join Rise to see the full answer
What security frameworks are you familiar with and how would you apply them at Kyndryl?

Discuss your familiarity with recognized security frameworks like NIST, ISO 27001, or the Zero Trust Framework. Explain how these frameworks guide your security strategies and can be tailored to meet the specific challenges faced by a Mainframe Security Architect, and how you intend to leverage these frameworks at Kyndryl.

Join Rise to see the full answer
How do you approach risk assessments and threat modeling?

In your response, illustrate your structured approach to risk assessments, including identifying assets, assessing vulnerabilities, and determining potential impacts. Share examples of tools you use for threat modeling and how you've successfully implemented findings in previous roles to enhance security posture.

Join Rise to see the full answer
Can you give an example of a time you identified a security vulnerability and how you remediated it?

Provide a detailed scenario outlining the situation, your investigative process, and the steps you took to address the vulnerability. Highlight the collaboration involved with other team members or third-party vendors, and focus on the positive outcomes achieved through your actions.

Join Rise to see the full answer
What strategies do you use to stay updated on emerging security threats and technologies?

Discuss the resources you rely on to keep abreast of the latest cybersecurity trends, such as attending conferences, online courses, professional forums, or subscribing to cybersecurity publications. Emphasize your proactive approach to continuous learning and how it benefits your role as a Mainframe Security Architect.

Join Rise to see the full answer
Describe your experience in conducting security compliance audits.

When answering, talk about your direct experience with regulatory compliance standards relevant to the Mainframe sector, such as HIPAA or GDPR. Provide an example of an audit process you led or contributed to, including findings, recommendations, and outcomes.

Join Rise to see the full answer
How do you prioritize multiple security requests or issues at once?

Illustrate your time management skills and the methods you use for prioritizing security issues. This could include risk assessment metrics or frameworks that help you evaluate the severity and potential impact, guiding you in addressing the most critical issues first.

Join Rise to see the full answer
What techniques do you employ to ensure effective communication with non-technical stakeholders?

Emphasize your ability to translate complex security concepts into digestible language for non-technical audiences. Provide an example of a time when you successfully communicated security risks to stakeholders, resulting in awareness and proactive measures.

Join Rise to see the full answer
How do you manage third-party vendor security compliance?

Discuss your experience with assessing and monitoring third-party vendors' security practices. Provide specifics on the criteria you evaluate for compliance and how you collaborate with vendors to enhance their security measures according to Kyndryl’s standards.

Join Rise to see the full answer
What is your approach to integrating security into the software development lifecycle?

Explain your understanding of the DevSecOps model and how security can be integrated at every stage of the software development lifecycle. Share methods to ensure that security measures are proactive rather than reactive, including automation tools or regular security testing.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
ALTEN Remote Stuttgart, Bundesrepublik Deutschland
Posted 4 days ago
Photo of the Rise User
Posted 10 days ago
Photo of the Rise User
Garmin Cluj Remote No location specified
Posted 2 days ago
Photo of the Rise User
McDonald's Corporation Hybrid 110 N Carpenter St, Chicago, IL 60607, USA
Posted 8 days ago
Photo of the Rise User
Posted 8 days ago

committed to the health and continuous improvement of the vital systems at the heart of the digital economy.

17 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 13, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!