All roles with salary

Lead Security Engineer - Vulnerability Management

Nubank São PauloEst. Est. BRL 15,000–21,000 / monthSenior

Estimated range based on role, country and industry — not published by the company.

Key requirements

  • Ci/Cd
  • Audit
  • Compliance
  • Information Security
  • Cloud Security
  • Network Security
About Nu Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.   Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability. Visit our Institutional Page About the role As a Lead Security Engineer, you will operate as a technical leader within Vulnerability Management, owning complex and ambiguous problems that span multiple teams and business areas. You will help evolve Nubank’s vulnerability management capabilities into a scalable, auditable and risk-driven program. This includes improving detection and asset coverage, strengthening ownership and remediation workflows, increasing automation, supporting regulatory and audit readiness, and enabling engineering teams to resolve vulnerabilities efficiently. This role requires strong autonomy, deep security engineering expertise, sound judgment and the ability to influence stakeholders without relying on formal authority. The role is aligned with IC6 expectations: leading complex cross-functional initiatives, setting standards, making technical decisions and acting as a multiplier for the broader organization. You can find more about Nubank Infosec here: https://blog.nubank.com.br/infosec-nubank-protecao-dados/ You will be responsible for Lead initiatives that improve the end-to-end vulnerability management lifecycle, from discovery and prioritization through remediation, verification and closure. Design and evolve scalable processes, controls, workflows and automations for vulnerability intake, enrichment, ownership resolution, prioritization and SLA tracking. Drive improvements across vulnerability identification sources, including cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments and threat intelligence. Partner with Engineering, AppSec, Cloud Security, Offensive Security, Risks and other stakeholders to remove blockers and drive timely remediation. Provide technical guidance on complex vulnerabilities, including risk context, remediation options, compensating controls and residual risk. Lead root-cause analysis for recurring findings, data-quality problems, ownership gaps and workflow failures. Define and improve metrics, dashboards and reporting that enable risk-based prioritization and executive decision-making. Support regulatory, audit and compliance activities by ensuring that processes, evidence and remediation records are complete and auditable. Contribute to the evolution of VM architecture, tooling and integrations, reducing operational toil and technical debt using AI tools. Mentor engineers, share knowledge and raise the technical and operational bar across the security organization. Participate in hiring and help build a strong, diverse and collaborative security engineering team. We are looking for a person who has Significant experience in information security, security engineering, vulnerability management, application security, cloud security or a related discipline. Deep understanding of vulnerability management principles, including risk-based prioritization, remediation processes, verification and SLAs. Experience designing or operating security controls and processes at scale. Experience integrating security tools, scanners, ticketing systems, asset inventories and reporting platforms. Strong technical understanding of at least some of the following areas: cloud infrastructure, application security, source code security, container security, network security, operating systems, CI/CD, APIs and automation. Ability to investigate complex findings, identify root causes and translate tech

See your match score for this role.

Xecodai maps the interview stages and shows what is preventing a 95% match.

Analyse this role