Senior RACF Engineering - Director
Morgan Stanley
- Location
- Remote, Georgia, United States of America
- Work model
- Remote
- Level
- Staff
- H-1B history
- 39 approvals (FY2023)
- Posted
- Aug 14, 2026
Skills
About this role
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Infrastructure Production Management & Reliability Engineering position at the Director level, which is part of the job family responsible for maintaining the stability and reliability of the organization's infrastructure systems, ensuring optimal performance and availability to support business operations. Since 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. The Mainframe Security team is seeking a senior RACF engineer to support mainframe security engineering, tooling, automation, and project execution. The ideal candidate will have deep hands-on experience with IBM RACF, IBM zSecure, and the broader IBM Z security ecosystem, with the ability to design, implement, and support security solutions across complex mainframe environments. This role requires strong analytical, organizational, and communication skills, as well as the ability to work independently with infrastructure, security, application development, and operations teams. The position may require occasional off-hours support for project implementations, production changes, and critical security initiatives. What you'll be doing in the role: Design, engineer, and support mainframe security initiatives related to authentication, authorization, encryption, privileged access, sensitive data protection, automation, reporting, utilities, and batch processes. Partner with Mainframe Security Architecture and Engineering teams to develop technical solutions, validate designs, perform testing, and support implementation. Support deployment of security solutions, including process changes, operational handoff, documentation, and training for security operations teams. Assess technical feasibility of proposed solutions and recommend approaches that meet security, operational, audit, and resiliency requirements. Collaborate with application development, security product owners, systems programming, database, CICS/MQ, business, and audit teams to gather requirements and implement effective security solutions. Create and maintain security monitoring, automation, and reporting solutions using tools such as IBM zSecure, Compliance Manager, Admin Express, multifactor authentication platforms, and key management capabilities. Monitor, analyze, and report on key performance indicators, control health, and operational trends; recommend preventative actions and process improvements as needed. Provide subject matter expertise on RACF, z/OS security controls, and mainframe security best practices to address questions, issues, audit inquiries, and project requirements. What you'll bring to the role: 10+ years of related experience as a RACF engineer, security engineer, or senior mainframe security administrator. Advanced hands-on knowledge of IBM RACF and IBM zSecure, including configuration, internals, reporting, administration, and engineering support. Proficiency with JCL, REXX, and CARLa for automation, reporting, utilities, and security tooling development. Experience with core z/OS utilities and facilities, including TSO, ISPF, SDSF, and related operational tooling. Working knowledge of database technologies and query tools such as DB2, Sybase, and SQL. Experience implementing and supporting mainframe authentication and encryption capabilities, including digital certificates, key management, multifactor authentication, and related controls. Broad understanding of z/OS infrastructure disciplines, including systems programming, storage, networking, UNIX System Services, CICS, DB2, performance, and enterprise tooling. Strong understanding of Identity and Access Management best practices, including least