Logo for BRMi

Identity & Access Management Engineer

Role overview

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field, or equivalent combination of education and experience
  • 5+ years of experience administering IBM z/OS mainframe security environments
  • Extensive hands-on experience administering RACF within enterprise mainframe environments
  • Strong understanding of Identity and Access Management (IAM) principles and lifecycle processes

Responsibilities

  • Administer and maintain the IBM RACF security environment for enterprise z/OS systems
  • Manage the complete identity lifecycle, including user provisioning, modifications, role changes, transfers, and deprovisioning
  • Implement and enforce least privilege, role-based access control (RBAC), and segregation of duties (SoD) principles across the mainframe environment
  • Collaborate with enterprise IAM, cybersecurity, infrastructure, and governance teams to strengthen the organization's overall security posture

About the company

BRMi logo

BRMi

IT Services & IT Consulting

BRMi is an information technology services provider. Whether it’s a digital transformation, migration to the cloud, intelligent automation, visual analytics, or otherwise thriving in today’s e-world, BRMi has been Executing Change and Accelerating Outcomes for its clients since 2004, using critical business performance and process information to create and deliver timely, targeted, high-value solutions.While we’re known for our work with the federal government, we serve both public and private sectors—from the national security establishment to monetary and financial institutions, statistical and regulatory bodies, and many others. We have real-world experience and cross-domain expertise.BRMi aligns to its clients’ needs. We don’t push predetermined solutions; rather, we listen to the root issues and consider situations and goals. We affect simplicity through process automation, effective change management, actionable architecture, and holistic solutions.The industry and client service awards BRMi has received are reflective of and contribute to its reputation as a trusted source for talent and creativity and as a reliable, high-value service provider in current and emerging information technologies.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Overview:

BRMi is seeking a Identity & Access Management Engineer to support and maintain the enterprise Identity and Access Management (IAM) program for an IBM z/OS mainframe environment. This role is responsible for administering RACF security, managing the identity lifecycle, enforcing access controls, and ensuring compliance with enterprise security policies and regulatory requirements.

The ideal candidate will have extensive experience with RACF administration, IBM zSecure, and mainframe identity management practices. This individual will work closely with cybersecurity, infrastructure, application, audit, and compliance teams to ensure secure access to critical mainframe resources while supporting governance initiatives, access reviews, and operational excellence.

 

Benefits:
• Comprehensive Medical, Dental, and Vision Insurance
• Employer-Paid Life Insurance
• Employer-Paid Short-Term and Long-Term Disability Insurance
• 401(k) 
• Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
• Educational Assistance

 

Salary: 125k-159k

 

**Can be 100% remote in TX, VA, MD, DC, or FL**

**High Profile roles may require candidates to fly to customer HQ for in person interview (expenses paid)**

 

Click here to learn about BRMi's culture.

 

Click here to see BRMi’s Glassdoor reviews

Responsibilities:
  • Administer and maintain the IBM RACF security environment for enterprise z/OS systems.
  • Manage the complete identity lifecycle, including user provisioning, modifications, role changes, transfers, and deprovisioning.
  • Configure and maintain RACF User, Group, Resource, Dataset, CICS, and DB2 security profiles.
  • Configure and maintain RACF SETROPTS parameters to ensure compliance with enterprise security standards.
  • Implement and enforce least privilege, role-based access control (RBAC), and segregation of duties (SoD) principles across the mainframe environment.
  • Review, evaluate, and approve user access requests in accordance with established IAM governance processes and security policies.
  • Partner with business units, application teams, and cybersecurity to design and implement secure access models for new and existing applications.
  • Provide Tier 3 support for complex identity, authentication, authorization, and RACF-related incidents and service requests.
  • Troubleshoot access failures, permission conflicts, RACF violations, and authorization issues across production and non-production environments.
  • Utilize IBM zSecure to perform security administration, reporting, compliance monitoring, and audit support.
  • Support periodic access certifications, entitlement reviews, privileged access reviews, and audit activities.
  • Monitor compliance with internal security standards, regulatory requirements, and corporate IAM policies.
  • Develop and maintain RACF standards, operational procedures, security documentation, and technical guidelines.
  • Identify opportunities to automate IAM administration and reporting using REXX, JCL, and other mainframe utilities.
  • Participate in security projects, system upgrades, application implementations, and IAM modernization initiatives.
  • Collaborate with enterprise IAM, cybersecurity, infrastructure, and governance teams to strengthen the organization's overall security posture.
  • Recommend and implement process improvements that enhance operational efficiency, security, and compliance.
  • Perform other duties as assigned 
Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field, or equivalent combination of education and experience.
  • 5+ years of experience administering IBM z/OS mainframe security environments.
  • Extensive hands-on experience administering RACF within enterprise mainframe environments.
  • Strong understanding of Identity and Access Management (IAM) principles and lifecycle processes.
  • Experience administering:
    • RACF User Profiles
    • Group Profiles
    • Resource Profiles
    • Dataset Profiles
    • CICS Security
    • DB2 Security
    • SETROPTS configuration
  • Strong understanding of authentication, authorization, identity governance, privileged access management, least privilege, and role-based access control.
  • Experience using IBM z/OS utilities including TSO, ISPF, JCL, and REXX.
  • Strong analytical and troubleshooting skills with the ability to diagnose and resolve complex access and security issues.
  • Experience supporting audit activities and regulatory compliance initiatives.
  • Excellent written and verbal communication skills with the ability to communicate effectively across technical and business teams.

Desired:

  • Experience administering IBM zSecure Administration and Audit.
  • Experience using ServiceNow for access requests, incident management, and change management.
  • Experience supporting Identity Governance and Administration (IGA) processes.
  • Experience supporting SOX, PCI DSS, NIST, ISO 27001, FFIEC, or other regulatory frameworks.
  • Experience with privileged access management (PAM) concepts and enterprise IAM governance.
  • Experience developing automation using REXX or other scripting languages.
  • Knowledge of enterprise mainframe operations, CICS, DB2, and z/OS security architecture.

** BRMi will not sponsor applicants for work visas for this position.**

**This is a W2 opportunity only**

 

EOE/Minorities/Females/Vet/Disabled 

We are an equal opportunity employer that values diversity and commitment at all levels. All individuals, regardless of personal characteristics, are encouraged to apply. Employment policies and decisions on employment and promotion are based on merit, qualifications, performance, and business needs. The decisions and criteria governing the employment relationship with all employees are made in a nondiscriminatory manner, without regard to race, religion, color, national origin, sex, age, marital status, physical or mental disability, medical condition, veteran status, or any other factor determined to be unlawful by federal, state, or local statutes. 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Other jobs at BRMi

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.