2 months ago
Responsibilities
- Define, communicate, and execute a multi-year IAM security strategy across multiple countries and regulatory jurisdictions.
- Lead organization-wide authentication migrations across browser, operating system login, CLI, and API surfaces.
- Design and maintain enterprise identity infrastructure, PKI and X.509 certificate lifecycle automation, mutual TLS, and credential management systems.
- Create measurable organization-wide least-privilege access programs and track access risk posture.
- Design and maintain security engineering frameworks covering technical mechanisms, policies, incentives, and assurance processes.
- Lead technical incident response, root cause analysis, and structural improvements for identity and access security events.
- Design and facilitate large-scale IAM preparedness exercises based on realistic attack paths.
- Mentor senior engineers, lead university projects, and participate in hiring and career decisions.
- Act as the technical authority for Legal, Compliance, internal audit, and external regulators on identity and access matters.
Requirements
- More than 15 years of professional experience in security engineering, particularly identity, authentication, or access management.
- Demonstrated success leading complex, multi-year security programs through measurable outcomes, including programs requiring significant organizational or technical adjustments.
- Expert knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mutual TLS, and PKI.
- Ability to produce, review, and reason about production-quality code in at least one general-purpose programming language.
- Experience modeling identity-related threats, assessing attacker techniques, and designing resilient security controls.
- Track record of solving practical security problems and distinguishing genuine risk reduction from compliance theater.
- Experience communicating technical risk and strategic recommendations to executives, regulators, and other non-technical stakeholders.
- Preferred experience in financial services or another regulated environment with multiple regulatory frameworks.
- Preferred hands-on experience administering or integrating enterprise identity providers at scale, especially Okta or Keycloak.
- Preferred experience securing third-party, BPO, or partner environments without direct operational control.
- Preferred experience leading Zero Trust adoption in hybrid and multi-cloud environments.
- Contributions to the security community through research, presentations, open-source tooling, or standards bodies are advantageous.
Benefits
- Equity opportunity.
- Food or meal card.
- Public transportation commuting benefit.
- Psychological, financial, and legal assistance program.
- Life, medical, and dental insurance.
- Language course program and learning platform access.
- Extended parental leave, daycare allowance, and parental consultancy.
- Work-from-home allowance and gym partnerships.
- 30 days of paid vacation.
- Hybrid work model requiring office attendance two to three times per week.
- Recruitment may use AI-enabled tools for interview transcription and analysis, while final decisions are made by human reviewers.
Categories
About Nubank
Nu is one of the largest digital financial services platforms in the world, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services. Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns. https://www.youtube.com/watch?v=kwwzcXK2PUo
