IBM Administrator/Consultant
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection, Security Management & Operations
IBM I Programmer
Required Skills & Experience- IBM i CL Programming: CRTCLPGM, SBMJOB, ADDJOBSCDE, RUNSQL; job stream design with sequential dependencies, conditional execution, and failure handling; sub-hourly scheduling patterns
IBM i Db2 SQL Services: QSYS
2. with ; QSYS
2._INFO; QSYS
2._INFO; time-bounded queries; CCSID casting between 1200 and 37
IBM i Security:
Least-privilege service account design; GRTOBJAUT; RVKOBJAUT; CRTUSRPRF; special authority review;
* EXCLUDE authority
IBM i Audit Journaling: QAUDJRN configuration and authority; QAUDCTL and QAUDLVL system values; PTF Group SF99704 level verification
IBM i Networking:
Outbound TCP; syslog RFC
5424; port 514; CFGTCP; NETSTAT
IBM i Ops Automation:
Message queue monitoring; RCVMSG; SNDMSG; SNDDST; subsystem and job status checking; automated CL restart logic
Security Assessment:
Assure Security (Precisely), Powertech, or IBM i Security Scan remediation experience — HIGH risk finding categories: system values, default passwords, excessive special authorities, exit point security, network security
Highly preferred to have someone with experience working in regulated industries (banking, finance, healthcare etc)
Job DescriptionWS1 — Audit Log Forwarding
Implement native IBM i CL program to collect QAUDJRN and QHST events in RFC
5424 syslog format and forward to the bank's internal Filebeat collector (port 514 TCP), which ships to Logz.io. Deliverables: compiled and scheduled CL program (5-min interval); least-privilege service account; verified end-to-end log flow confirmed in Logz.io;
Mermaid architecture diagram; troubleshooting and maintenance guide.
WS2 — Assure Security Remediation
Remediate 25 HIGH risk findings from a Precisely Assure Security review. Full findings report provided at engagement start. Deliverables: all 25 findings remediated and tested on test partition; formal risk acceptance documentation for any finding not resolvable within engagement scope; remediation status report suitable for Precisely and FFIEC examination.
WS3 — Service Monitoring & Auto-Restart
Implement native IBM i monitoring for up to 10 critical services agreed iverables: monitoring for each agreed service using native IBM i mechanisms; automated CL restart logic where safe; alerting via message queue or email for services needing human intervention; per-service documentation covering detection, recovery behavior, and escalation path.
WS4 — Morning & Night Ops Automation
Automate existing manual morning and night ops checklists. No development begins until current-state checklists are documented and approved. Deliverables: documented and approved current-state checklists; automated CL job streams with sequential validation and descriptive failure alerts; morning and night ops runbook covering automated flow, manual override, and step-level restart.
WS5 — Network Traffic Logging
Assess IBM i 7.4 native capabilities for inbound/outbound traffic logging and implement a solution feeding into the Logz.io pipeline. Deliverables: written assessment of native capabilities; approved recommended approach; implemented logging solution (subject to Bank approval of approach); suggested Logz.io alert rule definitions for anomalous traffic patterns.
WS6 — User Roles & Access Review
Create least-privilege service accounts for all automated work streams. Review existing IBM i user profiles for excessive authorities and workflow improvements. Deliverables: service accounts for WS1, WS3, WS4; findings report covering all profiles with special authorities (
* ALLOBJ,
* SECADM,
* JOBCTL,
* SERVICE,
* SAVSYS); implemented approved access changes; user and role documentation package suitable for FFIEC examination.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).