Mainframe Security Risk Manager - RACF Specialist

  • Genesis Corp
  • Grove City, Ohio
Genesis10 is seeking a Segment Risk Manager: IV (Lead) for a hybrid contract position with a leading client in Columbus, OH.

Compensation: $50-60 per hour W2.

Job Description:

The successful candidate will be responsible for comprehensive awareness centered around the configuring, maintaining, and monitoring RACF (Resource Access Control Facility) to ensure the secure management of user access, system resources, and data protection. A core focus of this role is identifying and mitigating security risks, ensuring regulatory compliance, and proactively addressing potential vulnerabilities. The ideal candidate will have deep technical knowledge of RACF and a strong understanding of risk management and information security practices in a z/OS mainframe environment.

Responsibilities:

Design, implement, and manage RACF security policies, including user profiles, group definitions, and resource access permissions, to minimize security risks.

Proactively identify vulnerabilities and security risks associated with RACF configurations and user access.

Conduct periodic audits of RACF settings to ensure compliance with internal security policies and industry regulations (e.g., GDPR, HIPAA).

Implement and monitor security controls to protect sensitive data and critical system resources.

Work closely with the cybersecurity team to align RACF policies with broader organizational security and risk management strategies.

Perform risk assessments on RACF access controls and configurations to identify potential threats or weaknesses in the system.

Respond to security incidents involving RACF, investigating root causes, and implementing corrective actions to prevent recurrence.

Collaborate with the Incident Response Team to ensure timely resolution of security breaches, unauthorized access, and other security incidents related to RACF.

Maintain documentation of security incidents, risk mitigation strategies, and post-incident reviews.

Ensure that RACF settings and policies comply with industry regulations, corporate security standards, and audit requirements.

Work with internal and external auditors to provide evidence of RACF security controls, processes, and audit trails.

Develop and maintain detailed documentation of RACF security policies, access controls, and incident response protocols.

Provide support during security audits by preparing reports on RACF compliance, user access reviews, and risk assessments.

Monitor and analyze RACF logs for suspicious activity, unauthorized access attempts, or policy violations.

Generate regular reports on RACF security status, including access control violations, policy exceptions, and risk analysis.

Present findings and recommendations for risk mitigation to senior management, security teams, and other stakeholders.

Stay current with developments in mainframe security and RACF best practices, and apply new techniques to improve risk management processes.

Develop and conduct training programs for technical staff on RACF security policies, access controls, and risk management strategies.

Lead efforts to automate risk management processes in RACF, including user access reviews and security policy enforcement.

Requirements:

5+ years of experience working with RACF in a z/OS mainframe environment.

Strong experience in risk management and security within a mainframe environment, particularly related to RACF access controls and policies.

Demonstrated expertise in conducting security audits, risk assessments, and implementing corrective actions.

Experience working in regulated industries (e.g., finance, healthcare) with a focus on compliance.

Technical Skills:

Deep understanding of RACF architecture, security policies, and risk management techniques.

Expertise in analyzing and managing security vuln
Job ID: 482624684
Originally Posted on: 6/25/2025

Want to find more Security opportunities?

Check out the 27,989 verified Security jobs on iHireSecurity