About us
Nubank was founded in 2013 with the mission of fighting complexity to empower people in their daily lives by reinventing financial services. Today, we are one of the largest digital banking platforms in the world, serving millions of customers across Brazil, Mexico, and Colombia. For more information, visit our careers page: [Upgrade to PRO to see link]
About the team
The Governance, Risk and Compliance (GRC) team enables Nubank to remain compliant with legal, regulatory, and internal requirements, while continuously identifying, classifying, and monitoring risks and providing strategic insights and performance evaluation to leadership.
The GRC squad collaborates with multidisciplinary teams to align our technology security strategy with Nubankβs overall business objectives, ensuring that identified risks are mitigated and that risk-based decision-making is enabled within and beyond the IT & Security Business Unit.
About the role
You will be responsible for acting as a technical reference in security, certifications, and internal controls, serving as a bridge between engineering, risk, audit, and business stakeholders.
You will define strategies, support risk-based decision-making, and ensure that security and compliance requirements are effectively embedded into processes, systems, and products.
Key responsibilities
β’ Act as a senior technical and governance reference across security, certifications, risk, and internal controls, influencing strategy.
β’ Identify control gaps and improvement opportunities in technical procedures required for certification and recertification processes (e.g., ISO 27001, PCI-DSS).
β’ Develop and maintain strong partnerships with business and technical leaders to orchestrate audits, assessments, and remediation plans in a risk-based and scalable way.
β’ Collaborate with technical teams to define action plans that ensure adherence to regulatory requirements and internal policies.
β’ Conduct assessments of internal controls, ensuring adherence to internal policies, legal requirements, and industry standards.
β’ Identify gaps and improvement opportunities in the internal controls landscape and lead control reviews, ensuring timely resolution of issues.
β’ Work closely with Risk teams to align on the mitigation of identified risks.
β’ Support responses to audit requests, regulatory inquiries, and due diligence from business partners.
β’ Partner with Engineering, Product, IT, and global teams to integrate compliance and security requirements into processes and systems.
β’ Define and monitor KRIs and KPIs, delivering forward-looking, data-driven insights to senior management and Committees.
β’ Drive continuous improvement and scale, simplifying processes and strengthening Nubankβs Security Maturity as the company grows globally.
Qualification Requirements
β’ Solid experience in information security, with strong knowledge of frameworks such as PCI-DSS, ISO 27000 family, NIST, and similar.
β’ Prior experience with security certification processes and/or internal controls, compliance, and audit support.
β’ Excellent executive communication skills, capable of translating complex topics into clear, actionable insights for senior leadership and committees.
β’ Experience operating in regulated and global environments, including interaction with auditors and regulators.
β’ Bachelorβs degree in Engineering, Technology, Security Information, Risk Management or related fields.
β’ Familiarity with using AI and automation (e.g., machine learning, generative AI, or LLM-based tooling) to enhance security compliance use cases.
β’ Knowledge of the regulatory landscape relevant to financial services, such as SOx, BACEN, CVM, CNBV, ANBIMA, SEC, and related regulations.
β’ Hands-on experience with cloud environments (e.g., AWS, GCP) and implementing security controls in these contexts.
β’ Advanced English (written and verbal) required.
Nice to have Requirements
β’ Relevant certifications such as CRISC, CISA, Security+, CISSP, or CISM are considered a strong plus.
International experience is highly desirable.
Our Benefits
β’ Chance of earning equity at Nubank
β’ Food/ Meal Card (Vale-RefeiΓ§Γ£o and/or Vale AlimentaΓ§Γ£o)
β’ Public Transportation Commuting Benefit (Vale-Transporte)
β’ NuCare β Psychological, Financial and Legal Assistance Program
β’ Life Insurance
β’ Medical Plan
β’ Dental Plan
β’ NuLanguage β Language Course Program
β’ Nucleo - Our learning platform of courses
β’ Extended Parental Leave
β’ Daycare Allowance
β’ Parental Consultancy
β’ Work-from-home Allowance
β’ Gym Partnerships
β’ 30 days of paid vacation
β’ Relocation Assistance Package, if applicable
Work Model for this Role
Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit [Upgrade to PRO to see link]