1 day ago
São Paulo, BrazilStaff+
Responsibilities
- Analyze cyber threat intelligence, attack trends, and security telemetry to develop threat models and robust detections.
- Lead adoption of AI and machine learning for anomaly detection, behavioral analytics, alert triage, threat intelligence enrichment, investigation prioritization, and response automation.
- Define validation, quality, explainability, and security controls for AI-assisted capabilities, including protections against data leakage, prompt injection, model manipulation, and adversarial evasion.
- Lead Purple Team activities, adversary simulations, emulation plans, and detection validation mapped to MITRE ATT&CK.
- Identify detection and prevention gaps, measure coverage, reduce false positives, and drive remediation plans.
- Establish feedback loops between offensive and defensive teams using simulation and incident lessons to improve detection and response.
- Define success criteria and track detection coverage, validation success, false-positive reduction, investigation time, response efficiency, and remediation cycle time.
- Build and lead the Threat Detection team, mentoring engineers and fostering ownership, accountability, collaboration, and continuous learning.
- Partner with security and engineering teams to build scalable security-event analysis solutions and resilient security architecture.
Requirements
- Solid hands-on experience with threat hunting and incident response, including resolving complex security incidents.
- Experience as a technical leader identifying, analyzing, and responding to complex security threats, with responsibility for mentoring team members.
- Experience developing and maintaining detection-as-code solutions.
- Proven information security operations experience managing and analyzing logs and other security data.
- Proficiency with SIEM and EDR tools, WAFs, firewalls such as Palo Alto and Cisco ASA, and IDS/IPS.
- Experience integrating threat intelligence feeds to improve detection.
- Proficiency in SQL for querying and managing security-related databases.
- Knowledge of cloud security principles and experience securing cloud environments across providers such as AWS.
- Track record of developing processes, measuring results, and delivering continuous improvement.
- Strong communication and team leadership skills, ability to collaborate in diverse teams, and advanced English proficiency.
Benefits
- Equity opportunity at Nubank.
- Food or meal card, public transportation benefit, psychological, financial and legal assistance, life insurance, medical and dental plans.
- Language courses, learning platform access, extended parental leave, daycare allowance, parental consultancy, gym partnerships, 30 days of paid vacation, and relocation assistance when applicable.
- Work-from-home allowance.
- Hybrid work model requiring office attendance two to three times per week in São Paulo, Campinas, Rio de Janeiro, or Belo Horizonte, Brazil.
About Nubank
Nubank is a digital banking platform for consumers and small businesses in Latin America, offering a no-fee credit card, accounts, payments, lending, and investments through Nu Asset Management. It monetizes via interchange, interest, and product fees within its app-based ecosystem. Founded in 2013 and headquartered in São Paulo, it serves over 100 million customers across Brazil, Mexico, and Colombia and is listed on the NYSE (ticker: NU).
