1,011,843open jobs
60,160companies
168,355added this week
Browse all
Salary
≈ $61k – $161k per year (Estimated)
Location
Hybrid (São Paulo, Brazil)
Seniority
Staff
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 30, 2026. Nubank scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Nubank is a Brazilian digital bank founded in 2013 that began by issuing a no-fee purple credit card to customers frustrated by the branch banking oligopoly, and it has grown into one of the largest financial institutions in Latin America by customer count. It now serves well over a hundred million customers across Brazil, Mexico and Colombia with accounts, cards, lending, investments and insurance, operating entirely without branches. Headquartered in São Paulo and listed on the New York Stock Exchange, it was an early Berkshire Hathaway investment and is unusual among digital banks for being consistently profitable at scale.

About Nu

Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.

Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability.

Visit ourInstitutional Page

About the role

As a Lead Security Engineer, you will operate as a technical leader within Vulnerability Management, owning complex and ambiguous problems that span multiple teams and business areas.

You will help evolve Nubank’s vulnerability management capabilities into a scalable, auditable and risk-driven program. This includes improving detection and asset coverage, strengthening ownership and remediation workflows, increasing automation, supporting regulatory and audit readiness, and enabling engineering teams to resolve vulnerabilities efficiently.

This role requires strong autonomy, deep security engineering expertise, sound judgment and the ability to influence stakeholders without relying on formal authority. The role is aligned with IC6 expectations: leading complex cross-functional initiatives, setting standards, making technical decisions and acting as a multiplier for the broader organization.

You can find more about Nubank Infosec here: https://blog.nubank.com.br/infosec-nubank-protecao-dados/

You will be responsible for

  • Lead initiatives that improve the end-to-end vulnerability management lifecycle, from discovery and prioritization through remediation, verification and closure.

  • Design and evolve scalable processes, controls, workflows and automations for vulnerability intake, enrichment, ownership resolution, prioritization and SLA tracking.

  • Drive improvements across vulnerability identification sources, including cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments and threat intelligence.

  • Partner with Engineering, AppSec, Cloud Security, Offensive Security, Risks and other stakeholders to remove blockers and drive timely remediation.

  • Provide technical guidance on complex vulnerabilities, including risk context, remediation options, compensating controls and residual risk.

  • Lead root-cause analysis for recurring findings, data-quality problems, ownership gaps and workflow failures.

  • Define and improve metrics, dashboards and reporting that enable risk-based prioritization and executive decision-making.

  • Support regulatory, audit and compliance activities by ensuring that processes, evidence and remediation records are complete and auditable.

  • Contribute to the evolution of VM architecture, tooling and integrations, reducing operational toil and technical debt using AI tools.

  • Mentor engineers, share knowledge and raise the technical and operational bar across the security organization.

  • Participate in hiring and help build a strong, diverse and collaborative security engineering team.

We are looking for a person who has

  • Significant experience in information security, security engineering, vulnerability management, application security, cloud security or a related discipline.

  • Deep understanding of vulnerability management principles, including risk-based prioritization, remediation processes, verification and SLAs.

  • Experience designing or operating security controls and processes at scale.

  • Experience integrating security tools, scanners, ticketing systems, asset inventories and reporting platforms.

  • Strong technical understanding of at least some of the following areas: cloud infrastructure, application security, source code security, container security, network security, operating systems, CI/CD, APIs and automation.

  • Ability to investigate complex findings, identify root causes and translate technical analysis into clear remediation guidance.

  • Proven experience leading complex, ambiguous, cross-functional initiatives with multiple stakeholders.

  • Strong communication skills, with the ability to influence engineers, technical leaders, risk teams and senior stakeholders.

  • Professional fluency in English, given the global scope of Nubank’s security organization.

Nice to Have:

  • Experience working in regulated environments or supporting audits and compliance programs.

  • Experience developing scripts, automations or integrations using a programming or scripting language.

  • Continuous Threat Exposure Management (CTEM) knowledge.

You’ll fit well if you

  • Take ownership of complex problems and move them forward with autonomy.

  • Are comfortable operating in ambiguity and creating structure where processes or solutions are not yet defined.

  • Challenge the status quo and look for simpler, more scalable and more efficient ways of working.

  • Balance technical rigor, risk reduction, operational reliability and developer experience.

  • Communicate clearly with different audiences and build alignment across teams.

  • Enjoy mentoring others and multiplying your impact through standards, documentation and knowledge sharing.

  • Care deeply about protecting customers and enabling the business to move quickly and safely.

Location for this opportunity (City, Country)

  • São Paulo, Brazil

  • Campinas, Brazil

  • Rio de Janeiro, Brazil

  • Belo Horizonte, Brazil

Benefits

  • Chance of earning equity at Nubank

  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)

  • Public Transportation Commuting Benefit (Vale-Transporte)

  • NuCare - Psychological, Financial and Legal Assistance Program

  • Life Insurance

  • Medical Plan

  • Dental Plan

  • NuLanguage - Language Course Program

  • Nucleo - Our learning platform of courses

  • Extended Parental Leave

  • Daycare Allowance

  • Parental Consultancy

  • Work-from-home Allowance

  • Gym Partnerships

  • 30 days of paid vacation

  • Relocation Assistance Package, if applicable

Work Model for this Role

Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/

Our recruitment process may involve the use of artificial intelligence-enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

To maintain a consistent and fair process for every candidate, Nu does not provide individualized technical feedback. See how our policy works here

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,011,843 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
São Paulo
≈ $35k – $86k per year (Estimated) • In office • Full-Time • São Paulo
Python
PowerShell
Bash
AI/ML
Red Teaming
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Linux
Windows
Cybersecurity
MITRE ATT&CK
Active Directory
SIEM
OWASP
Apply
≈ $38k – $93k per year (Estimated) • In office • Belo Horizonte
DevOps
Terraform
GCP
Azure
AWS
Cybersecurity
PCI DSS
Least Privilege
Apply
≈ $43k – $119k per year (Estimated) • In office • Full-Time • São Paulo
DevOps
Linux
Windows
TCP/IP
DNS
Cybersecurity
Zero Trust
LDAP
SIEM
Apply
≈ $44k – $122k per year (Estimated) • In office • Full-Time • Bachelor's Degree • São Paulo
DevOps
AWS
Cybersecurity
SIEM
Apply
≈ $43k – $120k per year (Estimated) • In office • Full-Time • São Paulo
DevOps
Linux
Windows
TCP/IP
Cybersecurity
Crowdstrike
CVSS
EPSS
Apply
Engineering Lead 1 day ago
≈ $16k – $35k per year (Estimated) • In office • Full-Time • 8+ years exp • Bengaluru
JavaScript
SQL
Node JS
Databases
PostgreSQL
Redis
Oracle
Couchbase
Apache Kafka
DevOps
CI/CD
Jenkins
AWS
Docker
Kubernetes
Bitbucket
AWS Lambda
Amazon EC2
Amazon S3
API Gateway
Management
Agile
Scrum
Kanban
QA
JMeter
Apply
In office
DevOps
SLI/SLO/SLA
Cybersecurity
Active Directory
Management
ITIL
Service Desk
Apply
In office • 5+ years exp
Python
JavaScript
Java
TypeScript
SQL
C#
C++
Node JS
Python
FastAPI
Java
Spring Boot
Node JS
Express
Databases
PostgreSQL
MS SQL
Frontend
Vue.js
Next.js
Angular
React.js
DevOps
CI/CD
Management
Agile
Apply
In office
DevOps
VMWare
Azure
AWS
Hyper-V
SLI/SLO/SLA
Linux
Windows
Apply
In office
JavaScript
SQL
C++
DevOps
VMWare
Windows Server
Hyper-V
SLI/SLO/SLA
Linux
Unix
DNS
DHCP
VPN
Cybersecurity
Active Directory
Apply
≈ $63k – $142k per year (Estimated) • Hybrid • Full-Time • São Paulo
Python
JavaScript
Node JS
Node JS
Commander.js
DevOps
GCP
Azure
AWS
Self-Healing
Cybersecurity
MITRE ATT&CK
Apply
≈ $62k – $164k per year (Estimated) • Hybrid • Full-Time • São Paulo
SQL
AI/ML
Machine Learning
DevOps
AWS
Cybersecurity
MITRE ATT&CK
Threat Modeling
SIEM
Apply
≈ $65k – $146k per year (Estimated) • Hybrid • Full-Time • São Paulo • Rio de Janeiro • Belo Horizonte • Campinas
AI/ML
Red Teaming
DevOps
CI/CD
AWS
Cybersecurity
Burp Suite
Metasploit
Nmap
Nessus
SQLmap
Shodan
Censys
Threat Modeling
Frida
OWASP
Apply
≈ $72k – $169k per year (Estimated) • Hybrid • Full-Time • São Paulo • Rio de Janeiro • Belo Horizonte • Campinas
DevOps
IAM
Cybersecurity
Keycloak
Okta
Zero Trust
Least Privilege
PKI
Apply
≈ $130k – $322k per year (Estimated) • Hybrid • Full-Time • Bogotá
Cybersecurity
MITRE ATT&CK
Management
Google Docs
Apply
≈ $49k – $119k per year (Estimated) • In office • Full-Time • São Paulo
AI/ML
Copilot Studio
Management
Power Automate
Power Apps
Apply
≈ $26k – $67k per year (Estimated) • Hybrid • Full-Time • São Paulo
JavaScript
TypeScript
Frontend
Angular
Bootstrap
React.js
JQuery
DevOps
Rest API
Jenkins
Git
GitLab
Management
Confluence
Jira
Scrum
Apply
Content Producer 7 hours ago
In office • São Paulo
Apply
Associate Consultant 7 hours ago
≈ $17k – $41k per year (Estimated) • In office • Full-Time • 3+ years exp • São Paulo
Management
Outlook
Microsoft Office
Apply
Estágio em TI 1 day ago
≈ $21k – $40k per year (Estimated) • In office • Internship • São Paulo
SQL
Management
Microsoft Office
Apply
See all jobs
This is one of many
1,011,843 more open roles from verified company boards, updated every day.