**Join Nu: Secure the Future of Finance for 135 Million Customers!**
Imagine reshaping the financial landscape for 135 million people across Brazil, Mexico, and Colombia. Nu, Latin America's leading digital bank, is a fintech pioneer driving an industry-wide transformation. We leverage cutting-edge data and proprietary technology to craft innovative financial products and services that empower individuals.
Guided by our relentless mission to conquer complexity and empower people, Nu provides a complete financial journey, fostering access and advancement through responsible lending and unparalleled transparency. Our efficient, scalable business model combines low cost-to-serve with consistently growing returns, fueling our rapid expansion and impact.
Our commitment to innovation and customer empowerment has earned us global recognition, including being named among Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Discover more about our journey on our Institutional Page.
**About Our Application Security Team**
Join Nu's elite Application Security (AppSec) team, a critical pillar within our Information Security area. We are the architects of secure innovation, constantly hunting for and proactively mitigating potential security threats to safeguard our customers' financial assets and sensitive data.
At Nu, we believe security should be an enabler, not a blocker. Our team is at the forefront of embedding robust security controls into our applications and empowering every engineer throughout the software development lifecycle. From designing AI-powered threat modeling tools to automating security within CI/CD pipelines, our work directly impacts the security posture and success of every Nubanker engineer.
**About the Role: Security Engineer, Application Security**
As a Security Engineer on our Application Security (AppSec) team, you will be a vital guardian, architecting and enabling secure software development practices across Nu’s entire engineering organization. You’ll immerse yourself in a diverse and dynamic technology stack, supporting teams working with Clojure, Python, Go for backend services, and Kotlin, Swift, Dart for mobile applications, by seamlessly embedding security into their SDLC.
This role is perfect for a seasoned professional with a deep foundation in application security concepts, a passion for collaborating closely with engineering teams to champion security best practices, and a keen interest in pioneering emerging areas like AI security and advanced threat modeling.
Your mission will involve designing and deploying state-of-the-art security tools within our CI/CD pipelines (SAST, DAST, SCA, MAST), conducting comprehensive threat modeling for new and existing projects, performing rigorous security reviews, and spearheading the automation of AppSec processes, including those leveraging cutting-edge AI technologies like Model Context Protocol (MCP) Servers and agents.
**What You'll Be Responsible For:**
Champion and embed robust security practices into the SDLC across our backend, mobile, and web application landscapes.
Strategically deploy and meticulously maintain a suite of security tools (SAST, DAST, SCA, MAST) within our CI/CD pipelines.
Perform detailed threat modeling and conduct comprehensive security reviews for both nascent and established projects.
Develop sophisticated scripts and tools using languages like Python, Go, and Bash to automate critical security checks and processes.
Forge strong collaborations with engineering teams, providing clear explanations of vulnerabilities and guiding remediation efforts.
Play a key role in AI-related security initiatives, ensuring the safe and responsible adoption of ML/AI features into our products.
Actively contribute to the evolution and refinement of internal security guidelines and baselines.
Participate in crucial cross-functional discussions, aligning security requirements with broader business objectives.
**What You'll Bring to the Team:**
**Must-Have Qualifications:**
Solid understanding of application security concepts and secure software development practices.
Hands-on experience with CI/CD pipelines and the implementation of security tools (e.g., SAST, DAST, SCA).
Proficiency in scripting/programming with languages such as Python, Go, Bash, etc., for automation and tooling.
Familiarity with container security tools (e.g., Trivy, Aqua).
Experience working with modern software architectures: Web, Mobile, APIs, and MCPs.
Strong communication and collaboration skills to effectively partner with multi-disciplinary teams.
**Even Better If You Have:**
Previous experience conducting security assessments in distributed systems environments.
Experience with specialized security tools like Semgrep, Fortify, Checkmarx, or Veracode.
Experience with pipeline orchestration tools such as Github Actions, Gitlab Workflow, or similar.
Exposure to AI security concepts and a grasp of emerging AI/ML security risks.
Familiarity with established threat modeling methodologies (e.g., STRIDE, PASTA, OWASP Threat Dragon).
Knowledge of regulatory and compliance requirements relevant to the financial services industry.
**Location:**
São Paulo, Brazil
Campinas, Brazil
Rio de Janeiro, Brazil
Belo Horizonte, Brazil
**Our Benefits:**
Chance of earning equity at Nubank
Food/Meal Card (Vale-Refeição and/or Vale Alimentação)
Public Transportation Commuting Benefit (Vale-Transporte)
NuCare – Psychological, Financial, and Legal Assistance Program
Life Insurance
Medical Plan
Dental Plan
NuLanguage – Language Course Program
Nucleo - Our learning platform of courses
Extended Parental Leave
Daycare Allowance
Parental Consultancy
Work-from-home Allowance
Gym Partnerships
30 days of paid vacation
Relocation Assistance Package, if applicable
**Work Model for this Role:**
**Hybrid 2-3 times/week:** Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.