Find Jobs
Find Jobs Near You – Available Work in Your Location
IBM i Administrator/Consultant
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Illinois data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$115,132 / year median in Illinois
+3% projected growth
Job Description
- Audit Log Forwarding
- Implement native IBM i CL program to collect QAUDJRN and QHST events in RFC5424 syslog format and forward to the bank's internal Filebeat collector (port 514 TCP ), which ships to Logz.
Deliverables:
compiled and scheduled CL program (5-min interval); least-privilege service account; verified end-to-end log flow confirmed in Logz.io; Mermaid architecture diagram; troubleshooting and maintenance guide. WS2- Assure Security Remediation
- Remediate 25 HIGH risk findings from a Precisely Assure Security review.
Deliverables:
all 25 findings remediated and tested on test partition; formal risk acceptance documentation for any finding not resolvable within engagement scope; remediation status report suitable for Precisely and FFIEC examination. WS3- Service Monitoring & Auto-Restart
- Implement native IBM i monitoring for up to 10 critical services agreed at kickoff.
Deliverables:
monitoring for each agreed service using native IBM i mechanisms; automated CL restart logic where safe; alerting via message queue or email for services needing human intervention; per-service documentation covering detection, recovery behavior, and escalation path. WS4- Morning & Night Ops Automation
- Automate existing manual morning and night ops checklists.
Deliverables:
documented and approved current-state checklists; automated CL job streams with sequential validation and descriptive failure alerts; morning and night ops runbook covering automated flow, manual override, and step-level restart. WS5- Network Traffic Logging
- Assess IBM i 7.
Deliverables:
written assessment of native capabilities; approved recommended approach; implemented logging solution (subject to Bank approval of approach); suggested Logz.io alert rule definitions for anomalous traffic patterns. WS6- User Roles & Access Review
- Create least-privilege service accounts for all automated workstreams.
Deliverables:
service accounts forWS1, WS3, WS4
; findings report covering all profiles with special authorities (- ALLOBJ,
- SECADM,
- JOBCTL,
- SERVICE,
- SAVSYS); implemented approved access changes; user and role documentation package suitable for FFIEC examination.
To learn more about how we collect, keep, and process your private information, please review
Insight Global's Workforce Privacy Policy:
https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements- IBM i
CL Programming:
CRTCLPGM , SBMJOB , ADDJOBSCDE , RUNSQL
; job stream design with sequential dependencies, conditional execution, and failure handling; sub-hourly scheduling patterns- IBM i Db2
SQL Services:
QSYS2.DISPLAY
_JOURNAL withGENERATE
_SYSLOG;QSYS2.HISTORY
_LOG_INFO;QSYS2.ACTIVE
_JOB_INFO; time-bounded queries; CCSID casting between 1200 and 37- IBM i
Security:
Least-privilege service account design;GRTOBJAUT
;RVKOBJAUT
;CRTUSRPRF
; special authority review;- EXCLUDE authority
- IBM i
Audit Journaling:
QAUDJRN configuration and authority; QAUDCTL and QAUDLVL system values; PTF Group SF99704 level verification- IBM i
Networking:
Outbound TCP ; syslog RFC5424; port 514; CFGTCP ; NETSTAT- IBM i
Ops Automation:
Message queue monitoring; RCVMSG ; SNDMSG ; SNDDST ; subsystem and job status checking; automated CL restart logicSecurity Assessment:
Assure Security (Precisely), Powertech, or IBM i Security Scan remediation experience- HIGH risk finding categories: system values, default passwords, excessive special authorities, exit point security, network security
- Highly preferred to have someone with experience working in regulated industries (banking, finance, healthcare etc) To view full details and how to apply, please login or create a Job Seeker account
Benefits
- Dental Insurance