8 hours ago
São Paulo, BrazilStaff+
Responsibilities
- Lead improvements to the end-to-end vulnerability management lifecycle, including discovery, prioritization, remediation, verification, and closure.
- Design and evolve scalable vulnerability intake, enrichment, ownership, prioritization, SLA tracking, and remediation workflows.
- Improve vulnerability identification across cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments, and threat intelligence.
- Partner with engineering and security stakeholders to remove remediation blockers and provide technical guidance on complex vulnerabilities, compensating controls, and residual risk.
- Lead root-cause analysis, improve metrics and dashboards, and support regulatory, audit, and compliance activities with complete evidence and remediation records.
- Evolve vulnerability management architecture, tooling, integrations, and automation; mentor engineers and participate in hiring.
Requirements
- Significant experience in information security, security engineering, vulnerability management, application security, cloud security, or a related discipline.
- Deep understanding of vulnerability management, including risk-based prioritization, remediation, verification, and SLAs.
- Experience designing or operating security controls and processes at scale and integrating security tools, scanners, ticketing systems, asset inventories, and reporting platforms.
- Strong technical understanding of areas such as cloud infrastructure, application security, source code security, container security, network security, operating systems, APIs, and automation.
- Ability to investigate complex findings, identify root causes, and translate technical analysis into clear remediation guidance.
- Proven experience leading complex, ambiguous, cross-functional initiatives and influencing engineers, technical leaders, risk teams, and senior stakeholders.
- Professional fluency in English.
- Preferred: experience in regulated environments, audit and compliance programs, scripting or automation integrations, and Continuous Threat Exposure Management knowledge.
Benefits
- Equity opportunity, meal and transportation benefits, psychological/financial/legal assistance, life insurance, medical and dental plans, language courses, learning platform access, extended parental leave, daycare allowance, parental consultancy, gym partnerships, 30 days of paid vacation, and relocation assistance when applicable.
- Hybrid work model requiring attendance at the office at least two to three times per week.
- Positions are located in São Paulo, Campinas, Rio de Janeiro, or Belo Horizonte, Brazil.
Categories
About Nubank
Nubank is a digital banking platform for consumers and small businesses in Latin America, offering a no-fee credit card, accounts, payments, lending, and investments through Nu Asset Management. It monetizes via interchange, interest, and product fees within its app-based ecosystem. Founded in 2013 and headquartered in São Paulo, it serves over 100 million customers across Brazil, Mexico, and Colombia and is listed on the NYSE (ticker: NU).
