Nubank
Staff Security Engineer (IAM)
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · São Paulo
Employer listed it 2 months ago · Added yesterday
Been open since 2 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
Hybrid · São Paulo
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 596 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around São Paulo, Campinas, Belo Horizonte, Rio de Janeiro, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "São Paulo, Campinas, Belo Horizonte, Rio de Janeiro, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Nu
Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.
Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability. Visit our Institutional Page
About the Role
Nubank is seeking a Staff Security Engineer to contribute in the Identity and Access Management security function across a financial technology organization serving over 100 million customers in Brazil, Mexico, and Colombia. This is a senior individual-contributor role with organizational-level technical influence, responsible for supporting a multi-year IAM security strategy, directing its execution across multiple engineering teams, and ensuring that identity and access controls meet the security, regulatory, and operational requirements of a globally operating financial institution.
The Staff Security Engineer is expected to bring a demonstrated history of delivering consequential security programs — including programs that encountered setbacks — and the technical judgment that only sustained, hands-on experience in the domain produces. Critically, this role requires a security engineering philosophy grounded in business enablement: the conviction that security done well accelerates what the organization can do, not merely protects it. This means rigorously distinguishing between controls that reduce real risk and those that create the appearance of compliance without reducing exposure, taking genuine ownership of outcomes rather than delegating accountability through policy, and continuously questioning inherited assumptions about what security measures are necessary, sufficient, or proportionate.
What You’ll Be Responsible For
Defining, communicating, and executing a multi-year security strategy (especially in the IAM field) aligned with the organization's risk posture, regulatory obligations, and business objectives across multiple countries and regulatory jurisdictions.
Lead organization-wide authentication migrations that span heterogeneous surfaces — browser, operating system login, CLI tooling, and API-level integrations — across thousands of employees, multiple device ecosystems, and distributed work environments, producing measurable outcomes: authentication success rates above 99%, material reductions in per-authentication time, support exception rates below 1%, and return on investment within weeks of enforcement.
Designing and maintaining the core identity infrastructure with the durability and operational discipline required at organizational scale: enterprise Identity Provider, PKI and X.509 certificate lifecycle automation, mutual TLS for service-to-service authentication, and credential management systems engineered to remain sound as the organization grows.
Translating least-privilege access from a principle into a measurable, organization-wide program — with defined metrics, visible adoption curves, and accountability structures that allow Security and Engineering leadership to track and act on the organization's access risk posture over time.
Designing and maintaining a security engineering framework — comprising technical mechanisms, policies, incentives, and assurance processes — that ensures security properties are durable, verifiable, and operationally sound, rather than dependent on individual vigilance or periodic audits.
Leading technical incident response for identity and access security events, including critical vulnerabilities in remote access infrastructure, ensuring thorough investigation, documented root cause analysis, and structural improvements that reduce the likelihood and impact of recurrence.
Designing and facilitating large-scale preparedness exercises grounded in realistic attack paths — involving engineering, operations, and executive functions — to identify genuine gaps in IAM controls, not merely satisfy a compliance requirement.
Providing technical mentorship and coaching to senior engineers; lead innovative projects with universities and actively collaborate in hiring and career decisions in order to maintain a high technical standard throughout the safety organization.
Serving as the technical authority in engagements with Legal, Compliance, internal audit, and external regulators on matters related to identity, authentication, and access control.
We Are Looking for a Person Who Has
Must-have
+15 years of professional experience in security engineering, with a concentration in identity, authentication, or access management.
Demonstrated track record of leading complex, multi-year security programs from conception through measurable outcome — including programs that required navigating organizational obstacles, technical constraints, or material mid-course corrections.
Expert-level knowledge of IAM and authentication protocols: OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mTLS, and Public Key Infrastructure (PKI).
Proficiency in software engineering: ability to produce, review, and reason about production-quality code in at least one general-purpose programming language.
Demonstrated ability to model identity-related threat scenarios, assess attacker techniques relevant to the IAM surface, and design controls that remain effective under adversarial conditions.
A demonstrable commitment to security as an organizational capability that enables business outcomes: a track record of solving real security problems, a disposition to challenge inherited security assumptions, and a clear pattern of distinguishing genuine risk reduction from security theater or responsibility transfer.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Chance of earning equity at Nubank
- ·Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
- ·Public Transportation Commuting Benefit (Vale-Transporte)
- ·NuCare – Psychological, Financial and Legal Assistance Program
- ·NuLanguage – Language Course Program
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Nubank, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.