8+ years of experience in penetration testing, with a specialization in systems/applications integrating with mainframe environments.
Deep knowledge of mainframe communication protocols and security mechanisms.
Demonstrated experience conducting red team-style assessments or advanced threat emulation on mainframe systems.
Proficient in tools such as:
Mainframe utilities: REXX, ISPF panels, NetView
Security tools: Nmap, Burp Suite, Wireshark, custom scripts
Strong scripting and automation skills (Python, REXX, Bash, or similar).
Strong communication and leadership skills, with a proven ability to lead technical teams or projects.
Experience producing board-level reports and presenting findings to senior stakeholders.
Exposure to hybrid environments (mainframe to cloud integrations, modernization efforts).
Familiarity with modern enterprise integration methods (REST, SOAP, MQ, FTP) that interface with mainframe services
Whilst these are nice to have, our team can help you develop in the following skills:
Industry certifications such as OSCP, OSCE, CRTP, GIAC GPEN, GXPN, or CISSP.
Background in regulated industries such as banking, insurance, or government, where mainframes are core infrastructure.
Knowledge of COBOL, PL/I, or other mainframe-centric programming languages.
Experience with compliance standards like PCI-DSS, NIST, or SOX as they apply to mainframes.