远程工作雷达

高级安全工程师(进攻性安全)

Senior Security Engineer (Offensive Security)

开发工程未标注地域
公司Nubank
薪资未公开
工作地点São Paulo / Campinas / Belo Horizonte / Rio de Janeiro
地域资格未标注地域
时区要求无特别要求
用工类型FullTime
发布时间今天
数据来源Ashby
前往企业招聘页投递 →

Nu 是拉丁美洲领先的数字银行,为巴西、墨西哥和哥伦比亚的 1.4 亿客户提供服务。公司通过利用数据和专有技术开发创新产品和服务,引领行业变革。

秉承着对抗复杂性并赋能人们的使命,Nu 为客户完整的金融旅程提供服务,通过负责任的借贷和透明度促进金融可及性和进步。公司由一个高效且可扩展的商业模式驱动,结合低成本服务与不断增长的回报。

Nu 的影响力已获得多项奖项的认可,包括《时代》100 家最具影响力公司、《快公司》最具创新力公司以及《福布斯》全球最佳银行。

访问我们的机构页面 https://www.nu.com/2026-en

关于团队

我们正在寻找对通过进攻性技术提升安全成熟度充满热情的求知欲强、有动力的个人——并且能够超越自身领域进行思考。作为我们进攻性安全团队的高级安全工程师,你不仅仅是执行任务:你将负责识别和缓解可能影响我们客户、Nubankers 和财务资产的安全威胁。

我们的进攻性安全团队在 Nubank 中扮演战略角色。通过模拟现实世界中的攻击,我们强化安全态势,并持续演进防御策略以领先于对手。我们大胆思考,目标高远,并挑战自己对“安全”定义的假设——因为现状始终是一个待验证的假设,而不是一个需要接受的边界。

你将与安全工程师、产品团队和其他利益相关者紧密合作,对他们进行教育、指导和支持,帮助他们从基础开始构建安全性。这是一个在整个组织中产生实际影响的激动人心的机会——并且作为负责人,而非仅仅是贡献者来实现它。

我们相信多元化的观点能让我们的安全更强大。无论你的背景来自 CTF 比赛、漏洞赏金计划、传统渗透测试,还是非线性的进攻性安全路径——我们都希望听到你的声音。

作为高级安全工程师(进攻性安全),你将负责:

- 全流程推动基础设施、网络和移动/API 渗透测试;

- 设计并执行红队操作,以挑战我们的防御;

- 领导漏洞管理项目并协助优先处理修复;

- 构建工具以增强进攻性安全能力;

- 协助制定和实施安全策略,确保符合行业标准和法规要求;

- 与跨职能团队协作,推动安全意识和最佳实践的落地。

查看英文原文

ABOUT NU

Nu is the leading digital bank in Latin America, serving 140 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.

Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.

Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.

Visit our Institutional Page https://www.nu.com/2026-en

ABOUT THE TEAM

We are looking for curious, driven individuals who are passionate about enhancing security maturity through offensive techniques — and who think beyond their own lane. As a Senior Security Engineer on our Offensive Security team, you won't just execute tasks: you'll take ownership of identifying and mitigating security threats before they impact our customers, Nubankers, and financial assets.

Our Offensive Security team plays a strategic role at Nubank. By simulating real-world attacks, we strengthen our security posture and continuously evolve our defense strategies to stay ahead of adversaries. We think boldly, aim high, and challenge our own assumptions about what secure looks like — because the status quo is always a hypothesis to test, not a boundary to accept.

You'll work closely with security engineers, product teams, and other stakeholders to educate, guide, and support them in building security in from the ground up. This is an exciting opportunity to drive real impact across the whole organization — and to do it as an owner, not just a contributor.

We believe diverse perspectives make our security stronger. Whether your background comes from CTF competitions, bug bounty programs, traditional pentesting, or a non-linear path into offensive security — we want to hear from you.

AS A SENIOR SECURITY ENGINEER (OFFENSIVE SECURITY), YOU'LL TAKE OWNERSHIP OF:

- Driving infrastructure, web, and mobile/API pentests end-to-end;

- Crafting and executing red team operations that challenge our defenses;

- Leading vulnerability management initiatives and helping prioritize remediation;

- Building tools that enhance offensive security reviews and automate repetitive tasks;

- Partnering with development squads to ensure security issues are understood and addressed at the root;

- Contributing to architectural and logical reviews of different systems and products.

WHAT WE'RE LOOKING FOR

Must have:

- Strong Offensive Security background, with a focus on Red Team activities;

- Deep experience across the pentest lifecycle: reconnaissance, enumeration, exploitation, post-exploitation, lateral movement;

- Strong knowledge of current and historical attack vectors, exploitation techniques, and how to remediate them;

- Ability to replicate the behavior of Advanced Persistent Threat (APT) groups;

- Experience with security frameworks such as OWASP;

- Experience working in cloud environments (AWS preferred);

- Ability to harden and improve CI/CD Pipelines and experience with SDLC;

- Solid knowledge across security domains, with strong depth in Operating Systems, Networks, Databases, and Infrastructure Architecture;

- Experience with Threat Modeling.

Nice to have:

- Active participation in CTF competitions or Bug Bounty programs;

- Proficiency with security assessment tools such as Burp Suite, Nmap, Metasploit, SQLmap, Nessus, Censys, Shodan, or Frida.re https://frida.re — or any equivalent tooling that supports security validation.

BENEFITS

- Chance of earning equity at Nubank

- Food / Meal Card (Vale-Refeição and/or Vale Alimentação)

- Public Transportation Commuting Benefit (Vale-Transporte)

- NuCare – Psychological, Financial and Legal Assistance Program

- Life Insurance

- Medical Plan

- Dental Plan

- NuLanguage – Language Course Program

- Nucleo – Our learning platform of courses

- Extended Parental Leave

- Daycare Allowance

- Parental Consultancy

- Work-from-home Allowance

- Gym Partnerships

- 30 days of paid vacation

- Relocation Assistance Package, if applicable

WORK MODEL FOR THIS ROLE

Hybrid 2–3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/.

Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位