Truist Bank logo

Cybersecurity RACF Senior Engineer

Truist Bank
Full-time
On-site
Wilson, North Carolina, United States

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency:  English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

***Open to a Remote Talent***

Senior RACF Engineer is responsible for designing and maintaining RACF profiles, groups, and resource classes to support both business operations and regulatory compliance.

This role leads RACF administration activities, including user provisioning, access reviews, and the cleanup of obsolete IDs and datasets. The engineer implements and manages advanced RACF features such as password phrases, digital certificates, and program control to enhance system security.

The engineer will monitor and audit RACF activity using SMF records, IRRDBU00 utilities, and zSecure tools to ensure accurate tracking and reporting. Collaboration with application, infrastructure, and compliance teams is essential to enforce least-privilege access across the organization.

The engineer develops and maintains automation scripts for RACF provisioning and reporting using REXX, CLIST, and JCL, and provides expert-level support for security incidents, access issues, and RACF-related outages.

This position participates in RACF migrations, system upgrades, and integration with external identity systems such as LDAP. The engineer documents RACF policies, procedures, and standards, and contributes to audit and compliance reporting efforts.

Candidates must have hands-on experience with RACF on IBM z/OS and possess a deep understanding of RACF classes including DATASET, GENERAL, FACILITY, OPERCMDS, and UNIXPRIV.

Proficiency with IRRDBU00, DSMON, and SMF record analysis is preferred, along with expertise in zSecure Admin, Audit, and Alert modules. Strong scripting skills in REXX, CLIST, and JCL is essential. Familiarity with USS environments, including OMVS segments, BPX.DAEMON, and program control, is expected.
The ideal candidate will have working knowledge of compliance frameworks such as SOX, HIPAA, and PCI-DSS, and demonstrate strong communication and documentation skills.

Experience integrating RACF into SIEM platforms like QRadar or Splunk is highly desirable and prior involvement in RACF migrations or enterprise-wide cleanup initiatives will be considered an asset.

Responsible for developing and maintaining the technical IT / cyber security capabilities necessary for safeguarding the firm's information systems and applications (software development lifecycle), including every phase of the SDLC and software stack. Design, plan, test and implement phases of cybersecurity technology projects.

This role seeks an experienced Cybersecurity Senior Engineer in the Mainframe Security team to ensure secure access control, across our mainframes including identity management, certificate administration, encryption controls.

This role is critical in ensuring secure and compliant access requiring the successful candidate to understand the complete user access lifecycle, privileged access administration, and risk management.

This role is responsible for implementing and supporting capabilities described by industry best practices such as NIST and CRI. This includes administering and maintaining policies and profiles, ensuring proper role-based access control (RBAC), segregation of duties, controls and auditing mechanisms.

The team member will collaborate across IAM, other cybersecurity, infrastructure, application development, risk and audit teams.

This position may lead related projects in this space, and you will build and maintain automation scripts and custom tools to streamline provisioning, monitoring and reporting of access controls. In addition, this senior position will mentor junior security engineers and server as a technical SME.

Following is a summary of the essential functions for this job.  Other duties may be performed, both major and minor, which are not mentioned below.  Specific activities may change from time to time. 

  • Develop and maintain the technical IT/cyber capabilities including all phases of the software development lifecycle and software stack which includes threat modeling of application designs, static application security testing (SAST), software composition analysis (SCA), dynamic application security testing (DAST), and penetration testing.

  • Lead efforts related to designing, planning, enhancing, and testing all cybersecurity technologies used throughout the enterprise including base-lining current systems, trend analysis, and capacity planning as required for future systems requirements and new technologies.

  • Analyze information to determine, recommend, and plan the use of new information security technologies, or modifications to existing equipment and systems that will provide capability for proposed project or work load, efficient operation and effective use of allotted resources

  • Lead the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff

  • Use sophisticated analytical thought through models, testing, and experience to exercise judgment and identify innovative solutions.

  • Responsible for technical support of information security technologies providing expert problem analysis and resolution in a timely manner  

  • Leads teams or projects with moderate resource requirements, risk, and complexity.

Qualifications

Required Qualifications:

The requirements listed below are representative of the knowledge, skill and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Bachelor’s degree and eight years of experience in systems engineering or administration or an equivalent combination of education and work experience

  • Deep specialized and/or broad functional knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security

  • Previous experience in leading complex IT projects

Preferred Qualifications:

  • Bachelor’s degree and ten years of experience or an equivalent combination of education and work experience.

  • Banking or financial services experience.

  • Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.)

  • Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.)

  • Certification in Information Security Management (e.g. Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) or Certified Information Security Manager (CISM)), or related security certification(s)

  • Understanding of regulatory frameworks for financial institutions

  • Ability to collaborate across teams and influence people

  • Excellent communications skills

  • Experience in waterfall and agile project management methodologies

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law   Pay Transparency Nondiscrimination Provision   E-Verify