- Страна
- Бразилия
Откликайтесь
на вакансии с ИИ

Lead Security Engineer (GRC)
Nubank — это престижный работодатель с сильной инженерной культурой, предлагающий опционы, расширенный соцпакет и возможность работать над глобальными продуктами в быстрорастущем финтехе.
Сложность вакансии
Роль уровня Lead требует не только глубоких технических знаний в области облачной безопасности (AWS/GCP), но и экспертного владения комплаенс-фреймворками (PCI-DSS, ISO 27001), а также навыков взаимодействия с регуляторами и топ-менеджментом.
Анализ зарплаты
Предлагаемая позиция Lead уровня в крупном финтехе Бразилии обычно предполагает зарплату выше среднего по рынку, дополненную значительным пакетом бонусов и акций (equity). Наш прогноз базируется на данных для Senior/Lead ролей в Сан-Паулу.
Сопроводительное письмо
I am writing to express my strong interest in the Lead Security Engineer (GRC) position at Nubank. With extensive experience in information security frameworks such as ISO 27001 and PCI-DSS, combined with a deep understanding of the financial regulatory landscape, I am confident in my ability to bridge the gap between technical engineering and strategic compliance. My background in managing complex audits and implementing security controls within AWS environments aligns perfectly with Nubank's mission to simplify financial services while maintaining world-class security standards.
Throughout my career, I have focused on automating compliance processes and translating technical risks into actionable insights for senior leadership. I am particularly excited about Nubank's forward-thinking approach to using AI and automation to enhance security maturity. I look forward to the opportunity to contribute to your global growth and help strengthen the security posture of your digital banking platform across Brazil, Mexico, and Colombia.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в nubank уже сейчас
Присоединяйтесь к Nubank, чтобы возглавить направление GRC в одном из крупнейших цифровых банков мира и внедрять инновации в сфере безопасности.
Описание вакансии
About us
Nubank was founded in 2013 with the mission of fighting complexity to empower people in their daily lives by reinventing financial services. Today, we are one of the largest digital banking platforms in the world, serving millions of customers across Brazil, Mexico, and Colombia. For more information, visit our careers page: https://international.nubank.com.br/careers/
About the team
The Governance, Risk and Compliance (GRC) team enables Nubank to remain compliant with legal, regulatory, and internal requirements, while continuously identifying, classifying, and monitoring risks and providing strategic insights and performance evaluation to leadership.
The GRC squad collaborates with multidisciplinary teams to align our technology security strategy with Nubank’s overall business objectives, ensuring that identified risks are mitigated and that risk-based decision-making is enabled within and beyond the IT & Security Business Unit.
About the role
You will be responsible for acting as a technical reference in security, certifications, and internal controls, serving as a bridge between engineering, risk, audit, and business stakeholders.
You will define strategies, support risk-based decision-making, and ensure that security and compliance requirements are effectively embedded into processes, systems, and products.
Key responsibilities
- Act as a senior technical and governance reference across security, certifications, risk, and internal controls, influencing strategy.
- Identify control gaps and improvement opportunities in technical procedures required for certification and recertification processes (e.g., ISO 27001, PCI-DSS).
- Develop and maintain strong partnerships with business and technical leaders to orchestrate audits, assessments, and remediation plans in a risk-based and scalable way.
- Collaborate with technical teams to define action plans that ensure adherence to regulatory requirements and internal policies.
- Conduct assessments of internal controls, ensuring adherence to internal policies, legal requirements, and industry standards.
- Identify gaps and improvement opportunities in the internal controls landscape and lead control reviews, ensuring timely resolution of issues.
- Work closely with Risk teams to align on the mitigation of identified risks.
- Support responses to audit requests, regulatory inquiries, and due diligence from business partners.
- Partner with Engineering, Product, IT, and global teams to integrate compliance and security requirements into processes and systems.
- Define and monitor KRIs and KPIs, delivering forward-looking, data-driven insights to senior management and Committees.
- Drive continuous improvement and scale, simplifying processes and strengthening Nubank’s Security Maturity as the company grows globally.
Qualification Requirements
- Solid experience in information security, with strong knowledge of frameworks such as PCI-DSS, ISO 27000 family, NIST, and similar.
- Prior experience with security certification processes and/or internal controls, compliance, and audit support.
- Excellent executive communication skills, capable of translating complex topics into clear, actionable insights for senior leadership and committees.
- Experience operating in regulated and global environments, including interaction with auditors and regulators.
- Bachelor’s degree in Engineering, Technology, Security Information, Risk Management or related fields.
- Familiarity with using AI and automation (e.g., machine learning, generative AI, or LLM-based tooling) to enhance security compliance use cases.
- Knowledge of the regulatory landscape relevant to financial services, such as SOx, BACEN, CVM, CNBV, ANBIMA, SEC, and related regulations.
- Hands-on experience with cloud environments (e.g., AWS, GCP) and implementing security controls in these contexts.
- Advanced English (written and verbal) required.
Nice to have Requirements
- Relevant certifications such as CRISC, CISA, Security+, CISSP, or CISM are considered a strong plus.
International experience is highly desirable.
Our Benefits
- Chance of earning equity at Nubank
- Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
- Public Transportation Commuting Benefit (Vale-Transporte)
- NuCare – Psychological, Financial and Legal Assistance Program
- Life Insurance
- Medical Plan
- Dental Plan
- NuLanguage – Language Course Program
- Nucleo - Our learning platform of courses
- Extended Parental Leave
- Daycare Allowance
- Parental Consultancy
- Work-from-home Allowance
- Gym Partnerships
- 30 days of paid vacation
- Relocation Assistance Package, if applicable
Work Model for this Role
Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- ISO 27001
- PCI DSS
- NIST
- AWS
- GCP
- SOX
- Risk Management
- Information Security
- Audit
- Compliance
- Machine Learning
Возможные вопросы на собеседовании
Проверка опыта работы с ключевым стандартом для финтеха.
Опишите ваш опыт подготовки организации к сертификации PCI-DSS: с какими основными трудностями вы столкнулись и как их преодолели?
Оценка способности автоматизировать рутинные процессы GRC.
Как бы вы использовали AI или инструменты автоматизации для мониторинга эффективности внутренних контролей в реальном времени?
Проверка навыков коммуникации между техническими и бизнес-подразделениями.
Как вы объясните техническую уязвимость бизнес-стейкхолдерам, чтобы обосновать необходимость выделения ресурсов на её устранение?
Оценка опыта работы в облачных средах.
Какие специфические контроли безопасности вы считаете наиболее критичными при работе в инфраструктуре AWS или GCP для соблюдения банковских регуляций?
Проверка умения работать с рисками.
Расскажите о случае, когда вам пришлось принимать решение на основе анализа рисков в условиях неопределенности. Каков был результат?
Похожие вакансии
Lead Security Engineer
Lead Security Engineer (AI-Native)
Lead Security Engineer (AI-Native)
Lead Security Engineer (AI-Native)
FinCrime Operations Team Lead
Vehicle SOC Manager
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Бразилия