
Overview
Basic Information
Country:
State:
City:
Date Published:
Job ID:
Travel:
Secondary locations:
Description and Requirements
"At BMC trust is not just a word - it's a way of life!"
Primary Roles and Responsibilities:
- Lead security assessments of applications and solutions deployed on IBM z/OS-based environments.
- Conduct penetration testing and red teaming exercises targeting mainframe environments and the surrounding application ecosystem.
- Perform code-assisted and black-box penetration testing against enterprise applications/systems interacting with RACF, DB2, CICS, MQ, and related subsystems.
- Identify risks in authentication, authorization, data handling, and communications within mainframe-integrated products.
- Create threat models and guide product teams in mitigating high-impact vulnerabilities early in the SDLC.
- Drive remediation efforts through hands-on collaboration and secure design guidance.
- Author technical reports and deliver executive summaries tailored to various audiences.
- Stay current on vulnerabilities, exploits, and testing techniques relevant to legacy enterprise technologies and mainframe ecosystems..
- Assess common integration patterns (SOA, REST/JSON, MQ) for security risks.
8+ years of experience in penetration testing, with a specialization in systems/applications integrating with mainframe environments.- Deep knowledge of mainframe communication protocols and security mechanisms.
- Demonstrated experience conducting red team-style assessments or advanced threat emulation on mainframe systems.
- Proficient in tools such as:
- Mainframe utilities: REXX, ISPF panels, NetView
- Security tools: Nmap, Burp Suite, Wireshark, custom scripts
- Strong scripting and automation skills (Python, REXX, Bash, or similar).
- Strong communication and leadership skills, with a proven ability to lead technical teams or projects.
- Experience producing board-level reports and presenting findings to senior stakeholders.
- Exposure to hybrid environments (mainframe to cloud integrations, modernization efforts).
- Familiarity with modern enterprise integration methods (REST, SOAP, MQ, FTP) that interface with mainframe services
Whilst these are nice to have, our team can help you develop in the following skills:
Industry certifications such as OSCP, OSCE, CRTP, GIAC GPEN, GXPN, or CISSP.
- Background in regulated industries such as banking, insurance, or government, where mainframes are core infrastructure.
- Knowledge of COBOL, PL/I, or other mainframe-centric programming languages.
- Experience with compliance standards like PCI-DSS, NIST, or SOX as they apply to mainframes.
Our commitment to you!
BMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!
If after reading the above, You’re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply! We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas!
BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.