ForgeApply · Job listing
IT Risk Senior Specialist
Nubank
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
ABOUT NU
Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks. Visit our institutional page: https://www.nu.com/2026-en
ABOUT THE ROLE
Strategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company’s strategy.
Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.
RESPONSIBILITIES
- Define, update, and oversee the Technology Risk framework (policies, standards, methodologies) and maintain risk metrics (KRIs, RAS) for governing bodies.
- Lead regulatory reports and committee presentations on Technology/Cybersecurity Risk, and coordinate responses to regulatory/audit requests.
- Oversee classification and root-cause analysis of high-materiality tech/cyber incidents and lead execution of crisis protocols.
- Review and challenge first-line DRP design/testing and BIA technology dependencies to ensure adequate resilience and risk exposure assessment.
- Challenge technology risk assessments for new products/architectures and drive root-cause analysis and remediation of material gaps.
- Design IT Third-Party Risk frameworks, oversee control testing quality, and act as key advisor to Risk, Engineering, Security, and Data leadership.
QUALIFICATIONS
- Bachelors’ degree in Engineering, Computer Science, Information Technology, a Risk Management related field, or equivalent experience (Master's degree is a plus)
- Minimum of 7 years of experience in cybersecurity or IT Risk Management ( Proven experience in fintech sector is a plus)
- In-depth knowledge of IT and cybersecurity risk management concepts, practices and methods.
- Fluent in English and Spanish, with exceptional communication skills to articulate complex risk scenarios and strategies effectively.
- Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.
- Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, etc.
- Understanding of DevOps practices and tools used in cloud environments, such as continuous integration/continuous deployment (CI/CD) pipelines and containerization.
- Knowledge of risk management frameworks and methodologies to identify, assess and manage risks.
- Certificates in information security or IT risk management (CISSP, CEH, OSCP, CISA, CISM, CRISC, ISO27001 and/or other) is a plus.
LOCATION & WORK MODEL
- Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration.
- This position is based in Mexico City, Mexico
BENEFITS
- Chance of earning equity at Nu
- Extended maternity and paternity leaves
- Health and life insurance
- Dental and Vision Insurance
- NuCare - Our mental health and wellness assistance program
- Nucleo - Our learning platform of courses
- NuLanguage - Our language learning program
- Holiday Bonus ("Aguinaldo") of 30 days of pay per year
- 17 days of paid vacation with 25% vacation bonus
- Gym partnership
- Food card
- Work-from-home Allowance
- Parental Consultancy
- Relocation Assistance Package, if applicable
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.
By submitting an application, I acknowledge that I have read and understand the Nubank Candidate Privacy Notice.
Nubank Candidate Privacy Notice https://script.google.com/macros/s/AKfycbzQM3zufHPOWmXrulh93xgy0DQcCF6QEQPnX-B7q0DX-T4cfhiIdoDP4dh0ijN9_Myh/exec
Ready to apply to Nubank?
Apply in about a minuteSimilar jobs
- Risk Advisory - IT Risk Senior Associate — Riveron · Atlanta, GA
- Operational Risk Senior Specialist — Nubank · Bogota
- Crypto Risk Senior Specialist — Robinhood · Denver, CO; Menlo Park, CA; New York, NY; Westlake, TX
- Senior Manager, Technology Risk — Upstart · Remote
- Sr Risk Analyst — Crunchyroll · Dallas, Texas, United States
- Sr. Program Specialist, Risk & Compliance Operations — Whoop · Boston, MA
- Security Risk Management Lead — Affirm · Remote
- Senior Manager - Security Risk Engineering — Klaviyo · Boston, MA
More like this: More jobs at Nubank · Browse all jobs