Live opening · Posted 13 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About the Role
L1: We are seeking a ACF2 to RACF Migration & RBAC Architect to lead the enterprise
security architecture for ACF2 to RACF migration and subsequent RBAC conversion
across the IBM Z estate. You will act as the overall design authority for the target RACF
model, conversion principles, role strategy, access governance, privileged access
approach, security risk decisions, and migration acceptance gates. The role includes
coordination with Vendors, execution partners, mainframe subsystem SMEs, cyber, risk,
audit, and application stakeholders to ensure the conversion is technically sound,
controlled, auditable, and operationally sustainable.
Key Skills and Expertise
L2: Key skills include ACF2, RACF, RBAC, SAF, RACROUTE, ACF2 LogonIDs, UID
strings, dataset rules, resource rules, RACF groups, connects, permits, class strategy,
privileged access, SURROGAT, STARTED, OPERCMDS, FACILITY, USS, certificates,
SMF, audit evidence, SoD, access certification, Vendors tooling, conversion
governance, and regulated banking controls.
Key Responsibilities
Lead the overall ACF2 to RACF migration architecture and RBAC conversion
strategy across production, DR, and test environments.
Define the target RACF security model including group hierarchy, profile
ownership, class activation strategy, access naming standards, and logging
expectations.
Approve ACF2-to-RACF mapping principles for LogonIDs, UID strings, dataset
rules, resource rules, privileged IDs, service IDs, generic IDs, and exceptions.
Own the RBAC target-state architecture covering business roles, technical roles,
infrastructure support roles, application roles, service roles, and emergency
access roles.
Govern the use of Vendors conversion tooling, compare outputs, exception
reports, password propagation, certificate migration support, and RBAC
collection methodology.
Chair security design decisions across RACF engineering, infrastructure,
CICS/MQ, Db2, IMS, testing, cutover, and governance workstreams.
Define security acceptance criteria for migration waves, mock cutovers,
production cutover, fallback, and post-migration hypercare.
Own risk and exception decisions related to over-permissioning, orphan access,
wildcard access, privileged attributes, SoD conflicts, and residual control gaps.
Provide technical direction to execution partners and review MSP/vendor
designs, runbooks, conversion outputs, issue logs, and evidence packs.
Prepare senior stakeholder updates on migration readiness, security risk, design
decisions, conversion progress, and RBAC maturity.
Experience and Qualifications
15+ years of IBM Z security, RACF/ACF2 architecture, or mainframe
infrastructure security experience.
Proven experience leading security transformations, RACF redesign, ACF2-to-
RACF migration, or large-scale access governance programs.
Strong understanding of mainframe subsystem security across z/OS, CICS, Db2,
MQ, IMS, USS, batch, network, storage, GDPS, and automation.
Experience operating in regulated banking or financial services environments
with audit, risk, SoD, and privileged access controls.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.