IT风险高级专员
IT Risk Senior Specialist
关于Nu
Nu是拉丁美洲领先的数字银行,为巴西、墨西哥和哥伦比亚的1.4亿客户提供服务。该公司通过利用数据和专有技术,开发创新产品和服务,引领行业变革。
以应对复杂性并赋能人们为使命,Nu为客户提供完整的金融旅程,通过负责任的贷款和透明度促进金融准入和进步。公司由一个高效且可扩展的商业模式驱动,结合低成本服务与不断增长的回报。
Nu的影响已获得多项奖项的认可,包括《时代》100家最具影响力公司、《快公司》最具创新力公司以及福布斯全球最佳银行。
访问我们的机构页面 https://www.nu.com/2026-en
关于该职位
战略与监管导向,专注于技术风险框架的设计和强化,以及通过技术风险部门和业务部门监督其实施,确保全面、前瞻性的管理,符合监管要求和公司战略。
支持技术风险职能的监督和发展,定义框架、指标和指南,并监督系统、数据、基础设施和技术第三方带来的风险的正确管理。作为与监管机构和治理机构在IT风险问题上的主要联系人,协调对重大事件和技术危机的响应,并协助执行技术环境的测试、评估和监控。
职责
- 定义、更新并监督技术风险框架,包括政策、标准、方法论和评估及报告标准。
- 建立、更新并监控技术风险指标(KRIs、RAS),汇总治理机构的风险暴露和趋势视图。
- 准备回应并协调处理与技术风险相关的监管和审计请求,必要时直接与相关机构互动。
- 监督高重要性技术与网络安全事件的管理,包括正确分类、根本原因分析和纠正措施的制定。
- 为新产品、功能和架构的技术风险评估提供指导并提出挑战,确保一致性和完整性。
- 设计和维护与i相关的IT第三方风险框架
查看英文原文
ABOUT NU
Nu is the leading digital bank in Latin America, serving 140 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Visit our Institutional Page https://www.nu.com/2026-en
ABOUT THE ROLE
Strategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company’s strategy.
Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.
RESPONSIBILITIES
- Define, update, and oversee the Technology Risk framework, including policies, standards, methodologies, and assessment and reporting criteria.
- Establish, update, and monitor technology risk metrics (KRIs, RAS), consolidating the view of exposure and trends for governing bodies.
- Prepare responses and coordinate attention to regulatory and audit requests related to Technology Risk, interacting directly with those authorities when appropriate.
- Oversee the management of high-materiality technology and cybersecurity incidents, including proper classification, root-cause analysis, and definition of corrective actions.
- Provide guidance and challenge technology risk assessments for new products, features, and architectures, ensuring consistency and completeness.
- Design and maintain IT Third-Party Risk frameworks, aligned with institutional standards and regulatory requirements.
- Oversee the quality and consistency of IT and cybersecurity control testing, technology RCSAs, and incident monitoring.
- Act as a key advisor to the leadership of Risk, Engineering, Security, Data, and other areas, fostering a strong culture of Technology Risk management.
QUALIFICATIONS
- Minimum of 5-6 years of experience in cybersecurity or IT Risk Management.
- Bachelors’ degree in Engineering, Computer Science, Information Technology, a Risk Management related field, or equivalent experience.
- In-depth knowledge of IT and cybersecurity risk management concepts, practices and methods.
- Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.
- Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, Cyberincident management, etc.
- Understanding of DevOps practices and tools used in cloud environments, such as continuous integration/continuous deployment (CI/CD) pipelines and containerization.
- Understanding of Business Continuity and Disaster Recovery (BC/DR) practices, along with experience executing and coordinating the full Business Continuity Management lifecycle and contingency response.
- Fluent in English and Spanish, with exceptional communication skills to articulate complex risk scenarios and strategies effectively.
- Demonstrated ability and experience to thrive in a tech-driven environment, ensuring the safe and practical use of technology through targeted challenge and inquiry directed at process and system owners.
LOCATION & WORK MODEL
- Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration.
- This position is based in Mexico City, Mexico
BENEFITS
- Chance of earning equity at Nu
- Extended maternity and paternity leaves
- Health and life insurance
- Dental and Vision Insurance
- NuCare - Our mental health and wellness assistance program
- Nucleo - Our learning platform of courses
- NuLanguage - Our language learning program
- Holiday Bonus ("Aguinaldo") of 30 days of pay per year
- 17 days of paid vacation with 25% vacation bonus
- Gym partnership
- Food card
- Work-from-home Allowance
- Parental Consultancy
- Relocation Assistance Package, if applicable
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.