yandex
nubank
Страна
Мексика
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorГибридПолная занятость

Senior Cyber & IT Risk

Оценка ИИ

Nubank — престижный работодатель с отличным пакетом льгот (включая опционы) и сильной инженерной культурой. Позиция предлагает высокий уровень влияния на стратегию безопасности компании.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубоких знаний в области кибербезопасности, облачных технологий (AWS) и регуляторных требований Мексики. Высокий уровень ответственности за взаимодействие с государственными органами и управление кризисными ситуациями повышает сложность.

Анализ зарплаты

Медиана75 000 $
Рынок55 000 $ – 100 000 $
Оценка ИИ

Зарплата для Senior-позиций в области ИТ-рисков в Мехико в крупных финтех-компаниях обычно выше среднего по рынку. Nubank предлагает конкурентоспособный пакет, дополненный акциями компании (equity), что значительно увеличивает общий доход.

Сопроводительное письмо

I am writing to express my strong interest in the Senior Cyber & IT Risk position at Nubank. With over five years of experience in cybersecurity and risk management, I have developed a deep understanding of how to build and oversee robust technology risk frameworks within fast-paced, cloud-native environments. My background aligns perfectly with Nubank's mission to simplify financial services while maintaining the highest standards of security and regulatory compliance.

Throughout my career, I have successfully led the implementation of risk metrics (KRIs) and managed complex regulatory reporting, which are core components of this role. My technical proficiency in AWS, CI/CD pipelines, and containerization, combined with a strategic mindset, allows me to effectively challenge and support engineering teams in identifying and mitigating risks. I am particularly drawn to Nubank's innovative culture and the opportunity to contribute to the 'purple future' by ensuring the resilience of your digital platform.

I am fluent in both English and Spanish and possess the communication skills necessary to bridge the gap between technical teams and governing bodies. I am eager to bring my expertise in IT Third-Party Risk and incident management to your Mexico City team and help Nubank continue its impressive growth across Latin America.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в nubank уже сейчас

Присоединяйтесь к Nubank и станьте ключевым экспертом по управлению ИТ-рисками в одном из крупнейших необанков мира!

Описание вакансии

About Us

Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our mission to fight complexity and empower people, we are redefining financial services in Latin America and this is still just the beginning of the purple future we're building.

Listed on the New York Stock Exchange (NYSE: NU), we combine proprietary technology, data intelligence, and an efficient operating model to deliver financial products that are simple, accessible, and human.Our impact has been recognized by global rankings such as Time 100 Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Bank. Visit our institutional page https://international.nubank.com.br/careers/ 

About the role

Strategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company’s strategy.

Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.

You'll be responsible for

  • Define, update, and oversee the Technology Risk framework, including policies, standards, methodologies, and assessment and reporting criteria.
  • Establish, update, and monitor technology risk metrics (KRIs, RAS), consolidating the view of exposure and trends for governing bodies.
  • Lead the preparation of regulatory reports and presentations to committees and governing bodies on Technology and Cybersecurity Risk.
  • Prepare responses and coordinate attention to regulatory and audit requests related to Technology Risk, interacting directly with those authorities when appropriate.
  • Oversee the management of high-materiality technology and cybersecurity incidents, including proper classification, root-cause analysis, and definition of corrective actions.
  • Oversee the execution of institutional crisis protocols associated with technology and cybersecurity incidents, facilitating pre-crisis reports, internal communications, and coordination with key areas.
  • Support the first line in defining and updating disaster recovery plans (DRP) and in their testing, playing a second-line review and challenge role on the adequacy of technology controls and recovery capabilities.
  • Participate in the execution of the BIA, reviewing and challenging the technology dependencies identified by the first line, ensuring they adequately reflect criticality and exposure to Technology Risk.
  • Collaborate with senior colleagues and technical areas to determine the root cause of material technology gaps and agree on remediation plans and control-strengthening actions.
  • Provide guidance and challenge technology risk assessments for new products, features, and architectures, ensuring consistency and completeness.
  • Design and maintain IT Third-Party Risk frameworks, aligned with institutional standards and regulatory requirements.
  • Oversee the quality and consistency of IT and cybersecurity control testing, technology RCSAs, and incident monitoring.
  • Act as a key advisor to the leadership of Risk, Engineering, Security, Data, and other areas, fostering a strong culture of Technology Risk management.
  • Stay up to date on regulation, technology trends, emerging threats, and industry best practices, incorporating these learnings into the evolution of the Technology Risk framework.

We are looking for a person who has

  • Minimum of 5 years of experience in cybersecurity or IT Risk Management.
  • Bachelors’ degree in Engineering, Computer Science, Information Technology, a Risk Management related field, or equivalent experience.
  • In-depth knowledge of IT and cybersecurity risk management concepts, practices and methods.
  • Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.
  • Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, etc.
  • Understanding of DevOps practices and tools used in cloud environments, such as continuous integration/continuous deployment (CI/CD) pipelines and containerization.
  • Knowledge of risk management frameworks and methodologies to identify, assess and manage risks.
  • Proven experience in risk management within the fintech sector is a plus.
  • An advanced degree (e.g., MS with concentration in information systems) is a plus.
  • Certificates in information security or IT risk management (CISSP, CEH, OSCP, CISA, CISM, CRISC, ISO27001 and/or other) is a plus.
  • Proficiency in using risk management software, tools, and agile methodologies is highly preferred.
  • An ability to navigate and thrive in a technology-driven environment, with a strategic mindset towards leveraging technology in risk management to transform our day-to-day.
  • Fluent in English and Spanish, with exceptional communication skills to articulate complex risk scenarios and strategies effectively.

Location for this opportunity (City, Country)

  • Mexico City, Mexico

Our Benefits

  • Chance of earning equity at Nubank
  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
  • Public Transportation Commuting Benefit (Vale-Transporte)
  • NuCare – Psychological, Financial and Legal Assistance Program
  • Life Insurance
  • Medical Plan
  • Dental Plan
  • NuLanguage – Language Course Program
  • Nucleo - Our learning platform of courses
  • Extended Parental Leave
  • Daycare Allowance
  • Parental Consultancy
  • Work-from-home Allowance
  • Gym Partnerships
  • 30 days of paid vacation
  • Relocation Assistance Package, if applicable

Work Model for this Role


Explore how we build technology at Nubank:

🔗building.nubank.com.br

🎥youtube.com/@building.nubank

🎧 Listen to our stories onSpotify

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Cybersecurity
  • IT Risk Management
  • AWS
  • IaaS
  • PaaS
  • SaaS
  • Cryptography
  • Network Security
  • Cloud Security
  • API Security
  • DevOps
  • CI/CD
  • Docker
  • Kubernetes
  • Agile
  • CISSP
  • CISA
  • CISM
  • CRISC
  • ISO 27001

Возможные вопросы на собеседовании

Проверка опыта работы с регуляторами и подготовки отчетности.

Опишите ваш опыт взаимодействия с финансовыми регуляторами в Мексике по вопросам ИТ-рисков. Как вы структурируете ответы на их запросы?

Оценка навыков управления инцидентами и кризисного менеджмента.

Расскажите о случае, когда вы курировали управление критическим инцидентом кибербезопасности. Какие шаги вы предприняли для анализа первопричин?

Проверка понимания специфики облачных рисков.

Какие специфические риски вы видите в использовании серверлесс-технологий и CI/CD пайплайнов в финтехе, и как их минимизировать?

Оценка способности работать в качестве 'второй линии защиты'.

Как вы подходите к проверке и оспариванию (challenge) планов аварийного восстановления (DRP), разработанных техническими командами?

Проверка навыков разработки методологии.

Как бы вы спроектировали систему ключевых показателей риска (KRI) для мониторинга безопасности сторонних ИТ-поставщиков?

Похожие вакансии

klaviyo
148 000 $ – 222 000 $

Senior Software Engineer - SecEng

SeniorГибридСША
Python · Go · AWS · Kubernetes · Terraform · Docker · Django · FastAPI · MySQL · Redis · Apache Kafka · Distributed Systems · IAM · Vault
+14 навыков
isccareers
150 000 $ – 180 000 $

Senior Cybersecurity Engineer

SeniorУдалённоСША
AWS · Terraform · Python · IAM · KMS · VPC · GuardDuty · SIEM · CloudFormation · GitHub Actions · GitLab · Network Security · Endpoint Security · Vulnerability Management · Container Security
+15 навыков
gongio
148 000 $ – 225 000 $

Sr. Manager, Identity & Access Management

SeniorУдалённоСША
Okta · IAM · SSO · MFA · RBAC · ABAC · SaaS · SOC 2 · ISO 27001 · SOX · Zero Trust · Google Workspace · Slack · Salesforce · Automation
+15 навыков
klaviyo
124 000 $ – 186 000 $

Manager, Privacy Compliance

SeniorВ офисеСША
GDPR · CCPA · CPRA · CIPP · CIPM · CIPT · OneTrust · Transcend · SaaS · Privacy-by-Design · DPIA · AI Governance · Data Protection · Compliance
+14 навыков
klaviyo
141 600 $ – 212 400 $

Senior Security Engineer - Detection and Response

SeniorГибридСША
Python · Go · SIEM · GitHub · CI/CD · Incident Response · Threat Hunting · Data Engineering · Machine Learning · Detection Engineering
+10 навыков
klaviyo
141 600 $ – 212 400 $

Senior Security Engineer - Detection and Response

SeniorГибридСША
Python · Go · SIEM · CI/CD · GitHub · Machine Learning · Data Engineering · Incident Response · Threat Hunting · Logging
+10 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

nubank
Страна
Мексика