FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Conduct black box, grey box, and assumed breach penetration tests of enterprise z/OS environments
- Assess USS, RACF, ACF2, Top Secret, CICS, IMS, Db2, MQ, JCL, JES2, TSO/ISPF, TN3270, FTP, z/OS Connect, REST APIs, and NJE
- Use manual techniques, custom scripting, and offensive tooling to enumerate users and resources, map datasets, access unprotected spool and job output, and exploit misconfigured CICS transactions and insecure interfaces
- Evaluate exploitability and business impact and determine finding severity and risk
- Document findings with reproduction steps, evidence, impact statements, and remediation recommendations
- Present and defend technical findings to application teams, mainframe engineers, technology leaders, risk partners, and stakeholders
- Perform validation and retesting to confirm remediation and risk reduction
- Maintain testing evidence for audit, regulatory, and compliance requirements including PCI DSS and SOX
- Partner with internal and external testing teams to improve coverage, methodologies, playbooks, tooling, automation, and repeatable processes
- Perform peer reviews of penetration testing reports and provide technical guidance and mentorship
- Maintain current knowledge of mainframe attack techniques, security controls, platform changes, offensive security practices, and industry threats
Requirements
What you’ll need- Bachelor’s degree or equivalent education, training, and work-related experience
- Minimum of 7 years of experience in security engineering or related cybersecurity roles
- Deep specialized knowledge in cybersecurity principles, theories, and concepts
- Proven experience in software development lifecycle security practices
- Deep knowledge of threat modeling, security testing, and penetration testing
- Experience implementing and managing complex information security technologies
- Five or more years of penetration testing, red team, offensive security, vulnerability research, or related cybersecurity experience
- Hands-on experience assessing mainframe environments, including z/OS and RACF, ACF2, or Top Secret
- Knowledge of mainframe architecture, identity and access management, privileged access, JCL, TSO/ISPF, CICS, Db2, network services, system configuration, and security hardening
- Experience identifying and validating mainframe vulnerabilities, misconfigurations, excessive access, insecure interfaces, and attack paths
- Strong technical writing and communication skills
- Ability to independently manage multiple testing engagements and drive work to completion
- Experience developing scripts, automation, or AI-enabled tooling
- Experience in banking, financial services, or another highly regulated industry
- Relevant offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, or equivalent credentials
- English language fluency required
- Must not require employer sponsorship for work visa status or employment authorization
Benefits
Comp & perks- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- Disability insurance
- Accidental death and dismemberment coverage
- Tax-preferred savings accounts
- 401k plan
- At least 10 days of vacation during the first year of employment, prorated as applicable
- 10 sick days, prorated as applicable
- Paid holidays
- Defined benefit pension plan (depending on position and division)
- Restricted stock units (depending on position and division)
- Deferred compensation plan (depending on position and division)
