You can secure the job scheduler by mapping users and groups to specific security roles.
If you use System Authorization Facility (SAF) EJBROLE
profiles on the z/OS® operating
system, define EJBROLE profiles for lradmin and lrsubmitter roles.
Permit these roles to the appropriate SAF user IDs. Do not control
permissions through the administration console as described in the
following procedure.
<install_root>/bin/lrcmd.[bat|sh] -cmd=<name_of_command> <command_arguments> [-host=<host> -port=<port>] -userid=<user_ID> -password=<password>
D:\IBM\WebSphere\AppServer\bin\lrcmd -cmd=submit -xJCL=D:\IBM\WebSphere\AppServer\longRunning\ postingSampleXJCL.xml -port=9445 -host=wasxd01.ibm.com -userid=mylradmin -password=w2g0u1tf