IT风险管理专员
IT Risk Management Specialist
Nu 是拉丁美洲领先的数字银行,为巴西、墨西哥和哥伦比亚的 14000 万客户提供服务。该公司通过利用数据和专有技术推动行业变革,开发创新产品和服务。
以“对抗复杂性,赋能人们”为使命,Nu 为客户提供完整的金融旅程,通过负责任的贷款和透明度促进金融准入和进步。公司采用高效且可扩展的商业模式,结合低成本的服务与不断增长的回报。
Nu 的影响力已获得多项奖项的认可,包括《时代》100 家最具影响力公司、《快公司》最具创新力公司以及《福布斯》全球最佳银行。
访问我们的机构页面 https://www.nu.com/2026-en
关于该职位
该职位位于 Nubank 全球风险管理团队,负责对 Nubank 全球系统、平台和流程中的技术和信息安全风险进行第二线监督。你将与工程、信息安全、数据、产品、业务和当地风险管理团队紧密合作,识别、评估和管理技术风险,同时使公司能够安全且快速地成长。
该职位结合了实际的风险评估与利益相关者合作,风险监控、控制监督、事件跟进以及持续改进 IT 风险实践。你将帮助在全球范围内一致应用框架和方法论,同时考虑当地的监管要求和每种技术环境的特点。
你将负责以下工作
- 在技术领域、平台、产品、功能和关键流程中开展 IT 和网络安全风险评估,识别威胁、漏洞、潜在影响以及适当的应对措施。
- 评估与新产品、功能、系统、基础设施和重大变更相关的技术风险,帮助团队在生命周期早期识别和解决风险。
- 与工程、信息安全、数据、产品、业务和当地风险管理团队合作,制定符合风险偏好、全球标准和适用监管要求的缓解计划。
- 支持全球 IT 风险框架、方法论、政策、程序、指标和治理实践在 Nubank 运营中的实施和一致应用。
查看英文原文
ABOUT NU
Nu is the leading digital bank in Latin America, serving 140 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Visit our Institutional Page https://www.nu.com/2026-en
ABOUT THE ROLE
This position sits within Nubank’s global risk management team and provides second-line oversight of technology and information security risks across Nubank’s global systems, platforms, and processes. You will work closely with Engineering, Information Security, Data, Product, Business, and local Risk Management teams to identify, assess, and govern technology risks while enabling the company to grow safely and at speed.
The role combines hands-on risk assessment with stakeholder partnership, risk monitoring, control oversight, incident follow-up, and continuous improvement of IT Risk practices. You will help apply global frameworks and methodologies consistently across geographies, while considering local regulatory requirements and the characteristics of each technology environment.
YOU’LL BE RESPONSIBLE FOR
- Conduct IT and cybersecurity risk assessments across technology domains, platforms, products, features, and critical processes, identifying threats, vulnerabilities, potential impacts, and appropriate risk responses.
- Assess and challenge technology risks associated with new products, features, systems, infrastructure, and material changes, helping teams identify and address risks early in the lifecycle.
- Partner with Engineering, Information Security, Data, Product, Business, and local Risk Management teams to develop mitigation plans aligned with risk appetite, global standards, and applicable regulatory requirements.
- Support the implementation and consistent application of global IT Risk frameworks, methodologies, policies, procedures, metrics, and governance practices across Nubank’s operations.
- Implement, mMonitor and analyse Key Risk Indicators, metrics, and dashboards for technology and cybersecurity risks, identifying changes in risk exposure and escalating matters that require attention.
- Prepare clear risk assessments, reports, and recommendations for technical stakeholders, senior management, governance forums, and risk committees.
- Support independent control testing and the assessment of control effectiveness, documenting gaps and recommending practical risk mitigants and action plans.
- Monitor technology, cybersecurity, and data-platform incidents; contribute to root-cause analysis, assess systemic implications, and connect remediation plans to the risk governance framework.
- Provide IT and cybersecurity risk expertise for third-party services, cloud environments, APIs, telecommunications infrastructure, and other technology dependencies.
- Monitor regulatory developments, emerging threats, technology changes, and industry practices, assessing their implications for Nubank’s IT Risk posture.
- Contribute to risk-related inquiries, workshops, thematic reviews, and governance routines, translating technical topics into actionable risk guidance.
- Identify opportunities to improve the efficiency, consistency, and scalability of IT Risk activities through data analytics, workflow automation, AI platforms, and other technology-enabled approaches.
- Support the development of junior colleagues and contribute to the continuous improvement of the team’s practices, tools, and methodologies.
What We're Looking For Someone Who Has
- Strong experience in technology areas, information security, IT risk management, internal controls or another risk-heavy technical role.
- Solid understanding of modern technology environments, including information security fundamentals, cloud-native environments such as AWS and GCP, microservices, APIs, CI/CD pipelines, containers, serverless technologies, and distributed systems.
- Strong grounding in risk assessment, risk analysis, mitigation planning, control effectiveness, incident management, risk monitoring, and governance reporting.
- Familiarity with risk and security frameworks and regulatory expectations, such as NIST, ISO/IEC 27001, LGPD, and applicable financial-services requirements.
- Ability to translate complex technical topics into clear business and risk-oriented insights for audiences with different levels of technical knowledge and seniority.
- Constructive-challenge mindset, with the ability to remain independent while building effective partnerships with first-line teams.
- Strong analytical and problem-solving skills, including the ability to structure ambiguous situations, prioritise risks, and make sound risk-based recommendations.
- Excellent communication and stakeholder management skills.
- Ability to work effectively across global and local teams, geographies, functions, and lines of defence.
- Pragmatic and collaborative approach to risk management, balancing robust controls with simplicity, speed, and customer focus.
- Strong ownership, organisation, attention to detail, and ability to manage multiple priorities in a fast-moving environment.
- Bachelor’s degree in Computer Science, Engineering, Information Technology, Business, or a related field.
- Relevant experience in cybersecurity, technology risk, IT risk management, information security, internal controls, or a related area.
- Demonstrated experience working with technology teams and evaluating risks across cloud environments, applications, infrastructure, data platforms, or third-party services.
- Experience contributing to risk frameworks, policies, control assessments, KRIs, incident management, regulatory responses, or risk governance processes.
- Experience in a regulated financial institution or fintech is a plus.
- Experience working across countries, global technology teams, or multiple regulatory environments is a plus.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, CHE, ISO 27001, or equivalent are a plus.
- Advanced English communication skills, both written and verbal, are essential for this global role.
Location
São Paulo - SP, Brazil
Work model
Hybrid
Office requirement
2-3 days per week at the office.
OUR BENEFITS
- Chance of earning equity at Nubank
- Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
- Public Transportation Commuting Benefit (Vale-Transporte)
- NuCare – Psychological, Financial and Legal Assistance Program
- Life Insurance
- Medical Plan
- Dental Plan
- NuLanguage – Language Course Program
- Nucleo - Our learning platform of courses
- Extended Parental Leave
- Daycare Allowance
- Parental Consultancy
- Work-from-home Allowance
- Gym Partnerships
- 30 days of paid vacation
- Relocation Assistance Package, if applicable
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.