远程工作雷达

资深安全工程师 (IAM)

Staff Security Engineer (IAM)

开发工程未标注地域
公司Nubank
薪资未公开
工作地点São Paulo / Campinas / Belo Horizonte / Rio de Janeiro
地域资格未标注地域
时区要求无特别要求
用工类型FullTime
发布时间2026-07-20
数据来源Ashby
前往企业招聘页投递 →

关于Nu

Nu是拉丁美洲领先的数字银行,在巴西、墨西哥和哥伦比亚为1.4亿客户提供服务。该公司通过利用数据和专有技术,开发创新产品和服务,引领行业变革。

以对抗复杂性并赋能人们为使命,Nu为客户提供完整的金融旅程,通过负责任的贷款和透明度促进金融准入和进步。公司由一个高效且可扩展的商业模式驱动,结合低成本服务与不断增长的回报。

Nu的影响已获得多项奖项的认可,包括《时代》100家最具影响力公司、《快公司》最具创新力公司以及《福布斯》全球最佳银行。

访问我们的机构页面 https://www.nu.com/2026-en

职位描述

Nubank正在寻找一名资深安全工程师,为服务于巴西、墨西哥和哥伦比亚超过1亿客户的金融科技组织中的身份与访问管理安全职能做出贡献。
这是一个具有组织级技术影响力的高级个人贡献者角色,负责支持多年期IAM安全策略的制定,指导其在多个工程团队中的执行,并确保身份和访问控制满足全球运营金融机构的安全、合规和运营要求。

该资深安全工程师需要具备成功交付重要安全项目的实际经验——包括那些遇到挫折的项目——以及只有长期、实际经验才能带来的技术判断力。
关键的是,这个角色需要一种以业务推动为核心的安全部门哲学:坚信安全做得好可以加速组织能做的事情,而不仅仅是保护它。这意味着严格区分真正降低风险的控制措施和仅创造合规表象而不减少暴露的措施,对结果承担真正的责任,而不是通过政策将责任推卸出去,以及持续质疑关于哪些安全措施是必要、充分或适当的既有假设。

你将负责以下工作

- 制定、传达并执行与组织风险立场、合规义务和业务目标一致的多年安全策略(特别是在IAM领域)

查看英文原文

ABOUT NU

Nu is the leading digital bank in Latin America, serving 140 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.

Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.

Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.

Visit our Institutional Page https://www.nu.com/2026-en

About the Role

Nubank is seeking a Staff Security Engineer to contribute in the Identity and Access Management security function across a financial technology organization serving over 100 million customers in Brazil, Mexico, and Colombia.
This is a senior individual-contributor role with organizational-level technical influence, responsible for supporting a multi-year IAM security strategy, directing its execution across multiple engineering teams, and ensuring that identity and access controls meet the security, regulatory, and operational requirements of a globally operating financial institution.

The Staff Security Engineer is expected to bring a demonstrated history of delivering consequential security programs — including programs that encountered setbacks — and the technical judgment that only sustained, hands-on experience in the domain produces.
Critically, this role requires a security engineering philosophy grounded in business enablement: the conviction that security done well accelerates what the organization can do, not merely protects it. This means rigorously distinguishing between controls that reduce real risk and those that create the appearance of compliance without reducing exposure, taking genuine ownership of outcomes rather than delegating accountability through policy, and continuously questioning inherited assumptions about what security measures are necessary, sufficient, or proportionate.

WHAT YOU’LL BE RESPONSIBLE FOR

- Defining, communicating, and executing a multi-year security strategy (especially in the IAM field) aligned with the organization's risk posture, regulatory obligations, and business objectives across multiple countries and regulatory jurisdictions.

- Lead organization-wide authentication migrations that span heterogeneous surfaces — browser, operating system login, CLI tooling, and API-level integrations — across thousands of employees, multiple device ecosystems, and distributed work environments, producing measurable outcomes: authentication success rates above 99%, material reductions in per-authentication time, support exception rates below 1%, and return on investment within weeks of enforcement.

- Designing and maintaining the core identity infrastructure with the durability and operational discipline required at organizational scale: enterprise Identity Provider, PKI and X.509 certificate lifecycle automation, mutual TLS for service-to-service authentication, and credential management systems engineered to remain sound as the organization grows.

- Translating least-privilege access from a principle into a measurable, organization-wide program — with defined metrics, visible adoption curves, and accountability structures that allow Security and Engineering leadership to track and act on the organization's access risk posture over time.

- Designing and maintaining a security engineering framework — comprising technical mechanisms, policies, incentives, and assurance processes — that ensures security properties are durable, verifiable, and operationally sound, rather than dependent on individual vigilance or periodic audits.

- Leading technical incident response for identity and access security events, including critical vulnerabilities in remote access infrastructure, ensuring thorough investigation, documented root cause analysis, and structural improvements that reduce the likelihood and impact of recurrence.

- Designing and facilitating large-scale preparedness exercises grounded in realistic attack paths — involving engineering, operations, and executive functions — to identify genuine gaps in IAM controls, not merely satisfy a compliance requirement.

- Providing technical mentorship and coaching to senior engineers; lead innovative projects with universities and actively collaborate in hiring and career decisions in order to maintain a high technical standard throughout the safety organization.

- Serving as the technical authority in engagements with Legal, Compliance, internal audit, and external regulators on matters related to identity, authentication, and access control.

WE ARE LOOKING FOR A PERSON WHO HAS

Must-have

- +15 years of professional experience in security engineering, with a concentration in identity, authentication, or access management.

- Demonstrated track record of leading complex, multi-year security programs from conception through measurable outcome — including programs that required navigating organizational obstacles, technical constraints, or material mid-course corrections.

- Expert-level knowledge of IAM and authentication protocols: OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mTLS, and Public Key Infrastructure (PKI).

- Proficiency in software engineering: ability to produce, review, and reason about production-quality code in at least one general-purpose programming language.

- Demonstrated ability to model identity-related threat scenarios, assess attacker techniques relevant to the IAM surface, and design controls that remain effective under adversarial conditions.

- A demonstrable commitment to security as an organizational capability that enables business outcomes: a track record of solving real security problems, a disposition to challenge inherited security assumptions, and a clear pattern of distinguishing genuine risk reduction from security theater or responsibility transfer.

- Experience communicating technical risk assessments and strategic recommendations to senior non-technical stakeholders, including executives and regulators.

Nice-to-have

- Experience operating within a financial services institution or similarly regulated environment subject to multiple concurrent regulatory frameworks.

- Hands-on experience administering or integrating with an enterprise Identity Provider at scale, particularly Okta, or Keycloak.

- Experience designing and enforcing security controls for third-party, BPO, or partner environments without direct operational control of the partner's infrastructure.

- Experience leading organizational adoption of Zero Trust architecture, including authentication and authorization mechanisms for hybrid and multi-cloud environments.

- Contributions to the broader security community — published research, conference presentations, open-source tooling, or participation in standards bodies.

OUR BENEFITS

- Chance of earning equity at Nubank

- Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)

- Public Transportation Commuting Benefit (Vale-Transporte)

- NuCare – Psychological, Financial and Legal Assistance Program

- Life Insurance

- Medical Plan

- Dental Plan

- NuLanguage – Language Course Program

- Nucleo - Our learning platform of courses

- Extended Parental Leave

- Daycare Allowance

- Parental Consultancy

- Work-from-home Allowance

- Gym Partnerships

- 30 days of paid vacation

WORK MODEL FOR THIS ROLE

Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/

Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

业务分析师

NubankCiudad de MéxicoFullTime昨天
其他未标注地域

← 返回全部职位