NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
1 day agoBe an early applicant
Apply with autofill
Apply with autofill
Nubank Mexico·Fintech·1 day ago
1 day agoBe an early applicant

Lead Security Engineer (Threat Detection)

São Paulo, BrazilFull-timeHybridSenior · 6-10 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at Nubank Mexico

How you compare FREE

?
Your scoreYour score: not yet known
→
45
Top 10%Top 10%: 45 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in Brazil.

Must-have skills for this role

  • threat hunting
  • incident response
  • siem
  • detection-as-code

PDF or DOCX · no account needed

Apply faster with autofill FREENubank Mexico uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Analyzing cyber threat intelligence, emerging attack trends and security telemetry to develop robust detections and threat models, while reducing false positives and improving the efficiency of security operations.
  • Leveraging AI and machine learning across the detection lifecycle — anomaly detection, behavioral analytics, alert triage, threat intelligence enrichment, investigation prioritization and response automation — and leading their adoption so these capabilities are reliable, measurable and secure.
  • Defining validation, quality, explainability and security controls for AI-assisted capabilities, accounting for risks such as inaccurate outputs, data leakage, prompt injection, model manipulation and adversarial evasion.
  • Leading Purple Team activities with Offensive Security, Threat Intelligence, Incident Response and Engineering: translating adversary behaviors into realistic attack simulations, adversary emulation plans and detection validation scenarios mapped to frameworks such as MITRE ATT&CK.
  • Identifying detection and prevention gaps, validating security controls, measuring detection coverage and driving remediation through actionable improvement plans.
  • Establishing feedback loops between offensive and defensive teams so lessons from simulations and real incidents continuously improve detection, investigation and response.
  • Defining success criteria and tracking metrics: detection coverage, validation success rate, false-positive reduction, investigation time, response efficiency and remediation cycle time.
  • Building and leading the team — mentoring engineers and fostering a culture of ownership, accountability, collaboration and continuous learning.
  • Partnering closely with Security Engineering, Threat Intelligence, Software Engineering and Incident Response to build scalable solutions for analyzing security event data and a resilient security architecture aligned with Business Unit strategy.

What they're looking for

  • Solid hands-on experience with Threat Hunting and Incident Response, including handling and resolving complex security incidents.
  • Experience as a technical leader in the identification, analysis and response to complex security threats, providing mentorship and guidance to team members.
  • Experience developing and maintaining detection-as-code solutions to automate threat identification and response.
  • Proven experience in information security operations, with expertise in managing, analyzing and deriving insights from logs and other security-related data.
  • Proficiency with SIEM and EDR tools, and with security platforms such as WAFs, firewalls (e.g. Palo Alto, Cisco ASA) and IDS/IPS.
  • Experience using and integrating threat intelligence feeds to improve detection.
  • Proficiency in SQL for querying and managing security-related databases.
  • Knowledge of cloud security principles and experience securing cloud environments across providers (e.g. AWS).
  • Track record of developing processes, measuring results and delivering continuous improvement.
  • Strong communication skills, a genuine team player and team leader, able to thrive in a team where diversity is key to high performance.
  • Advanced English.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About Nu

Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.

 

Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability.

Visit our Institutional Page

About the role

You will lead the team that stands between adversaries and 135 million customers. The Threat Detection team proactively hunts for security threats and builds robust, actionable detections to protect both customers and Nubankers — operating as a true Security Operations Center, backed by strong engineering power and intelligence from our internal Threat Intelligence team.

As Lead, you own the strategic Threat Detection program end to end: intelligence gathering, threat modeling, detection engineering, AI-assisted analysis, Purple Team validation, incident response and post-incident learning. Your goal is to make sure effective detection rules, actionable insights and AI-enabled security capabilities are in place and aligned with industry best practices, so that adversary activity across Nubank's environment is identified, prevented and detected before it reaches our customers.

You'll also build and lead a high-performing team, support Security leadership in building a world-class security organization, and ensure detection processes meet auditing requirements and support clear communication with regulatory bodies.

Learn more about Nubank Infosec: https://blog.nubank.com.br/infosec-nubank-protecao-dados/

You'll be responsible for

  • Analyzing cyber threat intelligence, emerging attack trends and security telemetry to develop robust detections and threat models, while reducing false positives and improving the efficiency of security operations.

  • Leveraging AI and machine learning across the detection lifecycle — anomaly detection, behavioral analytics, alert triage, threat intelligence enrichment, investigation prioritization and response automation — and leading their adoption so these capabilities are reliable, measurable and secure.

  • Defining validation, quality, explainability and security controls for AI-assisted capabilities, accounting for risks such as inaccurate outputs, data leakage, prompt injection, model manipulation and adversarial evasion.

  • Leading Purple Team activities with Offensive Security, Threat Intelligence, Incident Response and Engineering: translating adversary behaviors into realistic attack simulations, adversary emulation plans and detection validation scenarios mapped to frameworks such as MITRE ATT&CK.

  • Identifying detection and prevention gaps, validating security controls, measuring detection coverage and driving remediation through actionable improvement plans.

  • Establishing feedback loops between offensive and defensive teams so lessons from simulations and real incidents continuously improve detection, investigation and response.

  • Defining success criteria and tracking metrics: detection coverage, validation success rate, false-positive reduction, investigation time, response efficiency and remediation cycle time.

  • Building and leading the team — mentoring engineers and fostering a culture of ownership, accountability, collaboration and continuous learning.

  • Partnering closely with Security Engineering, Threat Intelligence, Software Engineering and Incident Response to build scalable solutions for analyzing security event data and a resilient security architecture aligned with Business Unit strategy.

We are looking for a person who has

  • Solid hands-on experience with Threat Hunting and Incident Response, including handling and resolving complex security incidents.

  • Experience as a technical leader in the identification, analysis and response to complex security threats, providing mentorship and guidance to team members.

  • Experience developing and maintaining detection-as-code solutions to automate threat identification and response.

  • Proven experience in information security operations, with expertise in managing, analyzing and deriving insights from logs and other security-related data.

  • Proficiency with SIEM and EDR tools, and with security platforms such as WAFs, firewalls (e.g. Palo Alto, Cisco ASA) and IDS/IPS.

  • Experience using and integrating threat intelligence feeds to improve detection.

  • Proficiency in SQL for querying and managing security-related databases.

  • Knowledge of cloud security principles and experience securing cloud environments across providers (e.g. AWS).

  • Track record of developing processes, measuring results and delivering continuous improvement.

  • Strong communication skills, a genuine team player and team leader, able to thrive in a team where diversity is key to high performance.

  • Advanced English.

Location for this opportunity (City, Country)

  • São Paulo, Brazil

  • Campinas, Brazil

  • Rio de Janeiro, Brazil

  • Belo Horizonte, Brazil

Our Benefits

  • Chance of earning equity at Nubank

  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)

  • Public Transportation Commuting Benefit (Vale-Transporte)

  • NuCare – Psychological, Financial and Legal Assistance Program

  • Life Insurance

  • Medical Plan

  • Dental Plan

  • NuLanguage – Language Course Program

  • Nucleo - Our learning platform of courses

  • Extended Parental Leave

  • Daycare Allowance

  • Parental Consultancy

  • Work-from-home Allowance

  • Gym Partnerships

  • 30 days of paid vacation

  • Relocation Assistance Package, if applicable

Work Model for this Role

  • Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/

Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

To maintain a consistent and fair process for every candidate, Nu does not provide individualized technical feedback. See how our policy works here

Fintech

Company

Nubank MexicoFintech
São Paulo, Brazil

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Nubank Mexico's careers site·first seen 20 Sept 2026·last verified 21 Sept 2026·How we source jobs

Similar jobs

  • Security Engineer at caylentBRAZIL–match not yet calculated
  • Senior Security Engineer | CloudSec at Gympass (Wellhub)São Paulo, Brazil–match not yet calculated
  • Grupo QuintoAndar | Senior Security Engineer - CSIRT at QuintoAndarSão Paulo, Brazil–match not yet calculated
  • Product Security Engineer (remote in Brazil) at knowbe4São Paulo, Brazil–match not yet calculated
  • Senior Security Engineer (AI Security) at Nubank MexicoSão Paulo, Brazil–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom
  • Retail Sales Associate jobs in United States