Staff Security Engineer (IAM) - BR - 2026
Nubank
| Company | Nubank |
| Category | Engineering |
| Location | São Paulo |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 20 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (ashby) |
Description
ABOUT NU
Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Visit our Institutional Page https://www.nu.com/2026-en
About the Role
Nubank is seeking a Staff Security Engineer to contribute in the Identity and Access Management security function across a financial technology organization serving over 100 million customers in Brazil, Mexico, and Colombia.
This is a senior individual-contributor role with organizational-level technical influence, responsible for supporting a multi-year IAM security strategy, directing its execution across multiple engineering teams, and ensuring that identity and access controls meet the security, regulatory, and operational requirements of a globally operating financial institution.
The Staff Security Engineer is expected to bring a demonstrated history of delivering consequential security programs — including programs that encountered setbacks — and the technical judgment that only sustained, hands-on experience in the domain produces.
Critically, this role requires a security engineering philosophy grounded in business enablement: the conviction that security done well accelerates what the organization can do, not merely protects it. This means rigorously distinguishing between controls that reduce real risk and those that create the appearance of compliance without reducing exposure, taking genuine ownership of outcomes rather than delegating accountability through policy, and continuously questioning inherited assumptions about what security measures are necessary, sufficient, or proportionate.
WHAT YOU’LL BE RESPONSIBLE FOR
- Defining, communicating, and executing a multi-year security strategy (especially in the IAM field) aligned with the organization's risk posture, regulatory obligations, and business objectives across multiple countries and regulatory jurisdictions.
- Lead organization-wide authentication migrations that span heterogeneous surfaces — browser, operating system login, CLI tooling, and API-level integrations — across thousands of employees, multiple device ecosystems, and distributed work environments, producing measurable outcomes: authentication success rates above 99%, material reductions in per-authentication time, support exception rates below 1%, and return on investment within weeks of enforcement.
- Designing and maintaining the core identity infrastructure with the durability and operational discipline required at organizational scale: enterprise Identity Provider, PKI and X.509 certificate lifecycle automation, mutual TLS for service-to-service authentication, and credential management systems engineered to remain sound as the organization grows.
- Translating least-privilege access from a principle into a measurable, organization-wide program — with defined metrics, visible adoption curves, and accountability structures that allow Security and Engineering leadership to track and act on the organization's access risk posture over time.
- Designing and maintaining a security engineering framework — comprising technical mechanisms, policies, incentives, and assurance processes — that ensures security properties are durable, verifiable, and operationally sound, rather than dependent on individual vigilance or periodic audits.