Scott Baker
Mainframe developer (COBOL · JCL · VSAM · DB2 · CICS) · IBM i · Security & compliance
Phoenix, Arizona · Remote only
Summary
IBM platform and security engineer moving into mainframe COBOL development. I administered IBM i (AS/400) user access for a 24/7 retail account at Cognizant, and bring 12+ years of security and compliance work: I drove the remediation program that took a healthcare organization to HITRUST certification and ran its security stack. I'm building a core banking system in COBOL and JCL, Big Iron Bank, and I write code the way auditors need it written: controlled, documented and restartable.
Skills
- Mainframe & IBM i: IBM i (AS/400) administration; z/OS: TSO/ISPF, JCL, Enterprise COBOL, VSAM, DB2 (embedded SQL), CICS, DFSORT/IDCAMS, SDSF; VS Code with Zowe and IBM Z Open Editor; MVS 3.8j on Hercules.
- Security & compliance: HITRUST CSF, HIPAA, CIS Benchmarks, security policy, LogRhythm SIEM, CrowdStrike EDR, CyberArk PAM, Qualys and OpenVAS, firewall policy, audit evidence and remediation.
- Systems: Windows Server, Active Directory, Group Policy, SCCM, Hyper-V, Linux (RHEL, Ubuntu).
- Scripting: PowerShell (since 2006), REXX (learning), SQL, Bash, Python.
- Certifications: AWS Certified Solutions Architect – Associate; Databricks Certified Associate Developer for Apache Spark. IBM Z Xplore badges in progress.
Experience
Security & Software Engineer, independent projects
- Designed, built and ran a post-quantum audit-trail service on GCP: ML-DSA-65 (FIPS-204) signatures verified against NIST's test vectors, Merkle transparency log, least-privilege IAM, secrets management.
- Now building Big Iron Bank in COBOL and JCL on MVS and z/OS.
Senior IT Analyst & Security Administrator · Ultra Clean Technologies
- Ran CrowdStrike EDR across a global fleet: alert triage, containment, policy tuning.
- Administered CyberArk privileged access management.
- Engineered SCCM imaging and patch management with baseline-configuration audits.
Systems Support Engineer & IBM i (AS/400) Administrator · Cognizant (TJ Maxx / HomeGoods account)
- Administered IBM i user access for the account: user profiles, password resets and access provisioning for every employee who needed the system, supporting its COBOL and RPG business applications.
- Led remediation during down-store outages (network, Hyper-V), restoring 24/7 retail operations.
Information Security & Compliance Analyst · ECS (acquired by CIOX Health, now Datavant)
- Drove the remediation program and co-authored the security-policy framework that earned HITRUST certification and continuous HIPAA compliance.
- Wrote the SOPs for the security and compliance program.
- Hardened the Windows fleet to CIS Benchmarks in place.
- Owned the security stack: LogRhythm SIEM, antivirus, perimeter firewall, Active Directory, Group Policy.
- Managed IronKey FIPS 140-2 encrypted drives for field staff, keeping PHI chain of custody.
Level 3 Linux Systems Engineer · Endurance International Group
- Escalations for 120+ enterprise hosting accounts; server hardening and security on Ubuntu and RHEL.
Education
Western Governors University: coursework toward a B.S. in Information Technology, 2008 – 2011.