IT Risk Management Specialist
Job Summary
Nu is the leading digital bank in Latin America serving 135 million customers across Brazil Mexico and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people Nu caters to customers complete financial journey promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nus impact has been recognized in multiple awards including Time 100 Most Influential Companies Fast Companys Most Innovative Companies and Forbes Worlds Best Banks.
Visit our Institutional Page
This position sits within Nubanks global risk management team and provides second-line oversight of technology and information security risks across Nubanks global systems platforms and processes. You will work closely with Engineering Information Security Data Product Business and local Risk Management teams to identify assess and govern technology risks while enabling the company to grow safely and at speed.
The role combines hands-on risk assessment with stakeholder partnership risk monitoring control oversight incident follow-up and continuous improvement of IT Risk practices. You will help apply global frameworks and methodologies consistently across geographies while considering local regulatory requirements and the characteristics of each technology environment.
Youll be Responsible for
Conduct IT and cybersecurity risk assessments across technology domains platforms products features and critical processes identifying threats vulnerabilities potential impacts and appropriate risk responses.
Assess and challenge technology risks associated with new products features systems infrastructure and material changes helping teams identify and address risks early in the lifecycle.
Partner with Engineering Information Security Data Product Business and local Risk Management teams to develop mitigation plans aligned with risk appetite global standards and applicable regulatory requirements.
Support the implementation and consistent application of global IT Risk frameworks methodologies policies procedures metrics and governance practices across Nubanks operations.
Implement mMonitor and analyse Key Risk Indicators metrics and dashboards for technology and cybersecurity risks identifying changes in risk exposure and escalating matters that require attention.
Prepare clear risk assessments reports and recommendations for technical stakeholders senior management governance forums and risk committees.
Support independent control testing and the assessment of control effectiveness documenting gaps and recommending practical risk mitigants and action plans.
Monitor technology cybersecurity and data-platform incidents; contribute to root-cause analysis assess systemic implications and connect remediation plans to the risk governance framework.
Provide IT and cybersecurity risk expertise for third-party services cloud environments APIs telecommunications infrastructure and other technology dependencies.
Monitor regulatory developments emerging threats technology changes and industry practices assessing their implications for Nubanks IT Risk posture.
Contribute to risk-related inquiries workshops thematic reviews and governance routines translating technical topics into actionable risk guidance.
Identify opportunities to improve the efficiency consistency and scalability of IT Risk activities through data analytics workflow automation AI platforms and other technology-enabled approaches.
Support the development of junior colleagues and contribute to the continuous improvement of the teams practices tools and methodologies.
What Were Looking For Someone Who Has
Strong experience in technology areas information security IT risk management internal controls or another risk-heavy technical role.
Solid understanding of modern technology environments including information security fundamentals cloud-native environments such as AWS and GCP microservices APIs CI/CD pipelines containers serverless technologies and distributed systems.
Strong grounding in risk assessment risk analysis mitigation planning control effectiveness incident management risk monitoring and governance reporting.
Familiarity with risk and security frameworks and regulatory expectations such as NIST ISO/IEC 27001 LGPD and applicable financial-services requirements.
Ability to translate complex technical topics into clear business and risk-oriented insights for audiences with different levels of technical knowledge and seniority.
Constructive-challenge mindset with the ability to remain independent while building effective partnerships with first-line teams.
Strong analytical and problem-solving skills including the ability to structure ambiguous situations prioritise risks and make sound risk-based recommendations.
Excellent communication and stakeholder management skills.
Ability to work effectively across global and local teams geographies functions and lines of defence.
Pragmatic and collaborative approach to risk management balancing robust controls with simplicity speed and customer focus.
Strong ownership organisation attention to detail and ability to manage multiple priorities in a fast-moving environment.
Bachelors degree in Computer Science Engineering Information Technology Business or a related field.
Relevant experience in cybersecurity technology risk IT risk management information security internal controls or a related area.
Demonstrated experience working with technology teams and evaluating risks across cloud environments applications infrastructure data platforms or third-party services.
Experience contributing to risk frameworks policies control assessments KRIs incident management regulatory responses or risk governance processes.
Experience in a regulated financial institution or fintech is a plus.
Experience working across countries global technology teams or multiple regulatory environments is a plus.
Relevant certifications such as CISA CISSP CISM CRISC CHE ISO 27001 or equivalent are a plus.
Advanced English communication skills both written and verbal are essential for this global role.
Location
São Paulo - SP Brazil
Work model
Hybrid
Office requirement
2-3 days per week at the office.
Chance of earning equity at Nubank
Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
Public Transportation Commuting Benefit (Vale-Transporte)
NuCare Psychological Financial and Legal Assistance Program
Life Insurance
Medical Plan
Dental Plan
NuLanguage Language Course Program
Nucleo - Our learning platform of courses
Extended Parental Leave
Daycare Allowance
Parental Consultancy
Work-from-home Allowance
Gym Partnerships
30 days of paid vacation
Relocation Assistance Package if applicable
Our recruitment process may involve the use of artificial intelligenceenabled tools such as automated interview transcription and analysis to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.
Required Experience:
IC
About Company
Você finalmente no controle do seu dinheiro. Controle total do cartão de crédito e da conta 100% digital