Senior Security Engineer (Offensive Security)

Nubank

2h ago 1 views 0 applications
Full-time Hybrid
São Paulo
Competitive
Full-time
Security Engineer

Job Description

Ready to Transform Digital Banking Security? Join Nu's Offensive Security Team!

Nu isn't just a bank; we're the leading digital financial services platform in Latin America, empowering over 140 million customers across Brazil, Mexico, and Colombia. We're revolutionizing an industry by fusing cutting-edge data science and proprietary technology to craft innovative, accessible financial products. Guided by our mission to dismantle complexity and champion financial empowerment, we're building a future where financial access is universal and transparent. Our efficient, scalable model drives massive impact, a fact recognized by multiple prestigious awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Curious to learn more about our journey and vision? Visit our Institutional Page.

About the Team: Offensive Security — Where the Status Quo is Always a Hypothesis

The security of Nu's vast ecosystem, protecting our customers, Nubankers, and financial assets, is paramount. Our Offensive Security team doesn't just execute tasks; we *own* the challenge of anticipating and neutralizing threats before they can materialize. We are the strategic vanguard, simulating real-world attacks to relentlessly harden our defenses and evolve our security posture, ensuring we always stay steps ahead of adversaries.
We're seeking curious, driven individuals who thrive on pushing boundaries and challenging assumptions. If you're passionate about offensive techniques and enhancing security maturity, and you think beyond your own lane, you'll fit right in. We encourage bold thinking, high aspirations, and a proactive approach to security — because for us, the status quo is never an endpoint, but an invitation to test, innovate, and improve.
As a Senior Security Engineer, you'll be a pivotal partner, collaborating closely with security engineers, product teams, and stakeholders across the organization. You'll educate, guide, and embed security from the ground up, driving tangible impact. This is an unparalleled opportunity to shape the security landscape of a rapidly growing, industry-leading fintech as an owner, not just a contributor.
We believe diverse perspectives forge stronger security. Whether your expertise comes from dominating CTF competitions, uncovering critical flaws in bug bounty programs, traditional pentesting, or a unique path into offensive security – we want to hear your story.

What You'll Own and Drive:

Leading end-to-end infrastructure, web, and mobile/API penetration tests.
Crafting and executing sophisticated red team operations designed to rigorously challenge our defense mechanisms.
Spearheading vulnerability management initiatives, including prioritization and strategic remediation planning.
Developing custom tools and automation solutions to enhance offensive security reviews and streamline repetitive tasks.
Partnering directly with development squads to ensure security issues are deeply understood and resolved at their root cause.
Contributing expert insights to architectural and logical reviews across diverse systems and products.

What We're Looking For:

Must-Have Skills & Experience:

A robust Offensive Security background, with a particular emphasis on Red Team activities.
Deep, hands-on experience across the entire pentest lifecycle: reconnaissance, enumeration, exploitation, post-exploitation, and lateral movement.
Strong knowledge of current and historical attack vectors, advanced exploitation techniques, and effective remediation strategies.
Proven ability to replicate the tactics, techniques, and procedures (TTPs) of Advanced Persistent Threat (APT) groups.
Extensive experience working with industry-standard security frameworks such as OWASP.
Practical experience in securing and operating within cloud environments (AWS preferred).
Ability to harden and improve CI/CD Pipelines, coupled with solid experience in the Software Development Life Cycle (SDLC).
Solid foundational knowledge across multiple security domains, with deep expertise in Operating Systems, Networks, Databases, and Infrastructure Architecture.
Demonstrated experience with Threat Modeling methodologies.

Nice-to-Have Bonus Points:

Active participation and proven success in CTF competitions or Bug Bounty programs.
Proficiency with leading security assessment tools such as Burp Suite, Nmap, Metasploit, SQLmap, Nessus, Censys, Shodan, or Frida.re – or equivalent tooling for robust security validation.

Beyond the Code: Our Comprehensive Benefits

Opportunity to earn equity at Nubank.
Food / Meal Card (Vale-Refeição and/or Vale Alimentação).
Public Transportation Commuting Benefit (Vale-Transporte).
NuCare – Comprehensive Psychological, Financial, and Legal Assistance Program.
Life Insurance.
Medical Plan.
Dental Plan.
NuLanguage – Language Course Program.
Nucleo – Our dedicated learning platform for continuous professional development.
Extended Parental Leave.
Daycare Allowance.
Parental Consultancy.
Work-from-home Allowance.
Gym Partnerships.
30 days of paid vacation.
Relocation Assistance Package, if applicable.

Work Model for this Role: Hybrid and Collaborative
This role operates on a hybrid model, bringing us to the office 2-3 times per week. These strategic office days are designed to maximize team connection, foster collaboration, and enhance our collective impact. For more details on our approach, please visit: https://building.nubank.com/nu-hybrid-work-model/.
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.