15 Sep
|
Vinovaai Private
|
Bengaluru
15 Sep
Vinovaai Private
Bengaluru
RACF Engineering & Security Conversion Lead
About the Role
L1: We are seeking a RACF Engineering & Security Conversion Lead to combine RACF engineering ownership with hands-on ACF2 security conversion analysis. The role will be the primary technical counterpart to Vendors for conversion cycles, RACF database build, generated RACF command validation, LogonID and UID mapping, dataset/resource rule conversion, exception remediation, and compare report analysis. You will ensure RACF build artifacts are accurate, controlled, repeatable, recoverable, and ready for production implementation.
Key Skills and Expertise
L2: Key skills include RACF database engineering, ACF2 rule analysis, ACF2 LogonIDs, UID strings, dataset rules, resource rules, RACF commands, RACF groups, connects, permits, SETROPTS, class activation, database backup/recovery, IRR utilities, password propagation, certificate conversion, compare reports, zSecure, SMF, REXX, JCL, and conversion defect remediation.
Key Responsibilities
- Own RACF database engineering, build standards, backup/restore validation, copy strategy, access build controls, and recovery procedures.
- Analyze ACF2 LogonIDs, UID strings, dataset rules, resource rules, scopes, privileged attributes, generic IDs, service IDs, and wildcard access for conversion readiness.
- Validate Vendors-generated RACF command streams for groups, users, profiles, permits, connects, ownership, and class-specific controls.
- Coordinate repeatable ACF2 extract cycles, cleansing inputs, conversion runs, compare reports, and exception remediation with Vendors and internal teams.
- Implement and validate RACF SETROPTS configuration, class activation, generic profile controls, warning mode approach, logging, and audit flag strategy.
- Reconcile baseline ACF2 access reports against converted RACF profiles, permits, and validation/compare outputs.
- Investigate conversion defects involving missing permits, excessive access, profile collisions, ownership gaps, incorrect UACC, class issues, or authority mismatches.
- Prepare RACF load plans, rollback procedures, implementation evidence, command execution controls, and post-load validation steps.
- Support mock cutovers, production migration, incident triage, and hypercare for RACF engineering defects.
- Document RACF build standards and transition the converted workplace to BAU RACF administration teams.
Experience and Qualifications
- 12+ years of hands-on RACF engineering, ACF2 administration, or mainframe security implementation experience.
- Strong experience with RACF commands, profiles, user/group administration, RACF class controls, and security database maintenance.
- Experience with ACF2-to-RACF conversion, security cleanup, access analysis, compare reporting, or large access remediation initiatives.
- Strong JCL, REXX, ISPF, SMF, and security reporting experience.
Technical Skills - Must Have
Domain
Required knowledge
RACF engineering
RACF database, SETROPTS, class activation, profiles, permits, connects, ownership
ACF2 analysis
LogonIDs, UID strings, dataset/resource rules, scopes, privileged IDs
Conversion execution
Extracts, command streams, compare reports, exception remediation
Security controls
UACC, audit flags, warning mode, generic profiles, class-specific controls
Technical tooling
JCL, REXX, ISPF, SMF, IRR utilities, zSecure or equivalent
Operational readiness
Backup/recovery, load controls, rollback, evidence, BAU handover
Technical Skills - Preferred
Domain
Preferred knowledge
Vendor tooling
Vendors ACF2-to-RACF conversion toolkit and validation software
Automation
REXX automation, batch reporting, Git-controlled command inventory
Certifications
IBM RACF, z/OS security, or equivalent mainframe security certification
📌 Racf Enginner (Bengaluru)
🏢 Vinovaai Private
📍 Bengaluru