Talent.com
Nubank
Senior Security Engineer (Application Security)Nubank • São Paulo, São Paulo, Brazil
Senior Security Engineer (Application Security)

Senior Security Engineer (Application Security)

Nubank • São Paulo, São Paulo, Brazil
Há 2 dias
Descrição da vaga

About Nu

Nu serves more than 140 million customers guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.

Proprietary technology and data at scale power Nus digital platform built to promote financial access advancement and transparency. Its business model thrives on customer love and lower costs feeding a flywheel of growth and profitability.

Visit our Institutional Page

About the team

The Application Security team is part of the Information Security area. The team focuses on proactive hunting for and mitigating potential security threats on Nubank to protect our customers financial assets and data. For that we perform many tasks such as embedding and developing security controls on the applications supporting all engineers during the software development lifecycle.
Our AppSec team is at the forefront of enabling secure innovation at Nubank. We believe security should be an enabler not a blocker and we build scalable solutions to help developers ship secure code without friction. From designing AI-powered threat modeling tools to automating security in CI/CD our work impacts every Nubanker engineer.

About the role

As a Security Engineer in our Application Security (AppSec) team you will be part of the group responsible for enabling secure software development practices across Nubanks entire engineering organization. We support teams working with a diverse technology stack including Clojure Python Go for backend and Kotlin Swift Dart for mobile by embedding security into their SDLC.

This role is ideal for someone with a strong foundation in application security concepts who enjoys working closely with engineering teams to drive security best practices and who has a keen interest in emerging areas such as AI security and threat modeling.

Your mission will include helping design and deploy security tools in our CI/CD pipelines (SAST DAST SCA) performing threat modeling for new projects supporting security reviews and contributing to the automation of AppSec processes including those involving new AI technologies like Model Context Protocol (MCP) Servers and agents.

Youll be responsible for
Embed security practices into the SDLC across backend mobile and web applications.

  • Deploy and maintain security tools (SAST DAST SCA MAST) in CI/CD pipelines.

  • Perform threat modeling and security reviews for new and existing projects.

  • Develop scripts and tools (Python Go Bash) to automate security checks and processes.

  • Collaborate with engineering teams to explain and remediate vulnerabilities.

  • Support AI-related security initiatives ensuring safe adoption of ML/AI features in products.

  • Contribute to the evolution of internal security guidelines and baselines.

  • Participate in cross-functional discussions to align security requirements with business goals.

We are looking for a person who has

Must-have

  • Solid understanding of application security concepts and secure software development practices.

  • Hands-on experience with CI/CD pipelines and implementing security tools (e.g. SAST DAST SCA).

  • Knowledge of scripting/programming with commonly used languages like Python Go bash etc for automation and tooling.

  • Familiarity with container security tools (e.g. Trivy Aqua).

  • Experience working with modern software architectures: Web Mobile APIs and MCPs.

  • Strong communication and collaboration skills to work with multi-disciplinary teams.

Nice to Have

  • Previous experience conducting security assessments in distributed systems environments.

  • Experience with tools like Semgrep Fortify Checkmarx Veracode.

  • Experience with pipeline tools like Github Actions Gitlab Workflow others.

  • Experience with AI security concepts and emerging AI/ML security risks.

  • Familiarity with threat modeling methodologies (e.g. STRIDE PASTA OWASP Threat Dragon).

  • Knowledge of regulatory and compliance requirements relevant to financial services.


Location

São Paulo Brazil
Campinas Brazil
Rio de Janeiro Brazil
Belo Horizonte Brazil

Our Benefits

  • Chance of earning equity at Nubank

  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)

  • Public Transportation Commuting Benefit (Vale-Transporte)

  • NuCare Psychological Financial and Legal Assistance Program

  • Life Insurance

  • Medical Plan

  • Dental Plan

  • NuLanguage Language Course Program

  • Nucleo - Our learning platform of courses

  • Extended Parental Leave

  • Daycare Allowance

  • Parental Consultancy

  • Work-from-home Allowance

  • Gym Partnerships

  • 30 days of paid vacation

  • Relocation Assistance Package if applicable


Work Model for this Role

Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week on strategic days designed to maximize team connection and collaboration. For more details visit recruitment process may involve the use of artificial intelligenceenabled tools such as automated interview transcription and analysis to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

To maintain a consistent and fair process for every candidate Nu does not provide individualized technical feedback. See how our policy works
here


Required Experience:

Senior IC


Employment Type : Full-Time
Experience: years
Vacancy: 1

Criar um alerta de emprego para esta pesquisa

Senior Security Engineer (Application Security) • São Paulo, São Paulo, Brazil