{"id":1539341,"url":"https://alion.io/job/nubank-lead-security-engineer-vulnerability-management","title":"Lead Security Engineer - Vulnerability Management","company":{"id":13935,"name":"Nubank","domain":"nubank.com.br","url":"https://alion.io/company/nu-bank","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":100,"open_postings":8,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":39,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["São Paulo, Brazil"],"countries":["BR"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":61000,"max_usd":161000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":399},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"GitHub","optional":false},{"name":"SLI/SLO/SLA","optional":false}],"status":"live","first_seen_at":"2026-09-30T11:40:58Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-04T23:56:37Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"About Nu\nNu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.\nProprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability.\nVisit ourInstitutional Page\nAbout the role\nAs a Lead Security Engineer, you will operate as a technical leader within Vulnerability Management, owning complex and ambiguous problems that span multiple teams and business areas.\nYou will help evolve Nubank’s vulnerability management capabilities into a scalable, auditable and risk-driven program. This includes improving detection and asset coverage, strengthening ownership and remediation workflows, increasing automation, supporting regulatory and audit readiness, and enabling engineering teams to resolve vulnerabilities efficiently.\nThis role requires strong autonomy, deep security engineering expertise, sound judgment and the ability to influence stakeholders without relying on formal authority. The role is aligned with IC6 expectations: leading complex cross-functional initiatives, setting standards, making technical decisions and acting as a multiplier for the broader organization.\nYou can find more about Nubank Infosec here: https://blog.nubank.com.br/infosec-nubank-protecao-dados/\nYou will be responsible for\nLead initiatives that improve the end-to-end vulnerability management lifecycle, from discovery and prioritization through remediation, verification and closure.\n\nDesign and evolve scalable processes, controls, workflows and automations for vulnerability intake, enrichment, ownership resolution, prioritization and SLA tracking.\n\nDrive improvements across vulnerability identification sources, including cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments and threat intelligence.\n\nPartner with Engineering, AppSec, Cloud Security, Offensive Security, Risks and other stakeholders to remove blockers and drive timely remediation.\n\nProvide technical guidance on complex vulnerabilities, including risk context, remediation options, compensating controls and residual risk.\n\nLead root-cause analysis for recurring findings, data-quality problems, ownership gaps and workflow failures.\n\nDefine and improve metrics, dashboards and reporting that enable risk-based prioritization and executive decision-making.\n\nSupport regulatory, audit and compliance activities by ensuring that processes, evidence and remediation records are complete and auditable.\n\nContribute to the evolution of VM architecture, tooling and integrations, reducing operational toil and technical debt using AI tools.\n\nMentor engineers, share knowledge and raise the technical and operational bar across the security organization.\n\nParticipate in hiring and help build a strong, diverse and collaborative security engineering team.\n\nWe are looking for a person who has\nSignificant experience in information security, security engineering, vulnerability management, application security, cloud security or a related discipline.\n\nDeep understanding of vulnerability management principles, including risk-based prioritization, remediation processes, verification and SLAs.\n\nExperience designing or operating security controls and processes at scale.\n\nExperience integrating security tools, scanners, ticketing systems, asset inventories and reporting platforms.\n\nStrong technical understanding of at least some of the following areas: cloud infrastructure, application security, source code security, container security, network security, operating systems, CI/CD, APIs and automation.\n\nAbility to investigate complex findings, identify root causes and translate technical analysis into clear remediation guidance.\n\nProven experience leading complex, ambiguous, cross-functional initiatives with multiple stakeholders.\n\nStrong communication skills, with the ability to influence engineers, technical leaders, risk teams and senior stakeholders.\n\nProfessional fluency in English, given the global scope of Nubank’s security organization.\n\nNice to Have:\nExperience working in regulated environments or supporting audits and compliance programs.\n\nExperience developing scripts, automations or integrations using a programming or scripting language.\n\nContinuous Threat Exposure Management (CTEM) knowledge.\n\nYou’ll fit well if you\nTake ownership of complex problems and move them forward with autonomy.\n\nAre comfortable operating in ambiguity and creating structure where processes or solutions are not yet defined.\n\nChallenge the status quo and look for simpler, more scalable and more efficient ways of working.\n\nBalance technical rigor, risk reduction, operational reliability and developer experience.\n\nCommunicate clearly with different audiences and build alignment across teams.\n\nEnjoy mentoring others and multiplying your impact through standards, documentation and knowledge sharing.\n\nCare deeply about protecting customers and enabling the business to move quickly and safely.\n\nLocation for this opportunity (City, Country)\nSão Paulo, Brazil\n\nCampinas, Brazil\n\nRio de Janeiro, Brazil\n\nBelo Horizonte, Brazil\n\nBenefits\nChance of earning equity at Nubank\n\nFood/ Meal Card (Vale-Refeição and/or Vale Alimentação)\n\nPublic Transportation Commuting Benefit (Vale-Transporte)\n\nNuCare - Psychological, Financial and Legal Assistance Program\n\nLife Insurance\n\nMedical Plan\n\nDental Plan\n\nNuLanguage - Language Course Program\n\nNucleo - Our learning platform of courses\n\nExtended Parental Leave\n\nDaycare Allowance\n\nParental Consultancy\n\nWork-from-home Allowance\n\nGym Partnerships\n\n30 days of paid vacation\n\nRelocation Assistance Package, if applicable\n\nWork Model for this Role\nHybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/\nOur recruitment process may involve the use of artificial intelligence-enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.\nTo maintain a consistent and fair process for every candidate, Nu does not provide individualized technical feedback. See how our policy works here","description_format":"text","description_chars":6642,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Equity","Hybrid work","Life insurance","Parental leave","Relocation assistance"],"hiring_locations":[{"name":"Brazil","iso":"BR","kind":"country"}],"hiring_excludes":[],"relocation_offered":true,"industries":["Endpoint Security","Information Security","Vulnerability Management","Cards & Card Issuing"],"lifecycle":[{"event":"open","at":"2026-09-30T20:22:20Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":3,"expected_fill_days":39,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/nubank-lead-security-engineer-vulnerability-management","json_url":"https://alion.io/job/nubank-lead-security-engineer-vulnerability-management.json","meta":{"generated_at":"2026-10-05T00:13:58Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":190,"day_limit":5000,"remaining_today":4810,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}