Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Nubank

Lead Security Engineer – Vulnerability Management

Nubank

. Lead initiatives improving the end-to-end vulnerability management lifecycle from discovery and prioritization through remediation, verification and closure .

Posted 9/30/2026full-timeSão Paulo • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in vulnerability management, including risk-based prioritization, remediation processes, and compliance activities. Proficient in designing scalable security controls and integrating security tools to enhance operational efficiency.

Highest-signal resume keywords
Vulnerability ManagementRisk-Based PrioritizationSecurity Controls DesignTechnical Guidance on VulnerabilitiesCross-Functional Initiative Leadership

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecuritySecurity EngineeringApplication SecurityCloud SecurityVulnerability IdentificationScripting or Programming LanguageRoot Cause AnalysisMetrics and ReportingAutomationCI/CD
Soft Skills
Strong Communication SkillsInfluencing StakeholdersMentoring EngineersCollaboration
Tools & Technologies
Cloud Infrastructure ScannersGitHub Security FindingsTicketing SystemsAsset InventoriesAI Tools
Industry Keywords
Regulatory ComplianceAudit SupportCTEM KnowledgeThreat IntelligenceBug Bounty Reports

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Lead initiatives improving the end-to-end vulnerability management lifecycle from discovery and prioritization through remediation, verification and closure
  • Design and evolve scalable processes, controls, workflows and automations for vulnerability intake, enrichment, ownership resolution, prioritization and SLA tracking
  • Improve vulnerability identification sources including cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments and threat intelligence
  • Partner with Engineering, AppSec, Cloud Security, Offensive Security, Risks and other stakeholders to remove blockers and drive timely remediation
  • Provide technical guidance on complex vulnerabilities, including risk context, remediation options, compensating controls and residual risk
  • Lead root-cause analysis for recurring findings, data-quality problems, ownership gaps and workflow failures
  • Define and improve metrics, dashboards and reporting for risk-based prioritization and executive decision-making
  • Support regulatory, audit and compliance activities by ensuring processes, evidence and remediation records are complete and auditable
  • Contribute to VM architecture, tooling and integrations, reducing operational toil and technical debt using AI tools
  • Mentor engineers, share knowledge and raise the technical and operational bar across security
  • Participate in hiring and help build a strong, diverse and collaborative security engineering team

Requirements

What you’ll need
  • Significant experience in information security, security engineering, vulnerability management, application security, cloud security or a related discipline
  • Deep understanding of vulnerability management principles, including risk-based prioritization, remediation processes, verification and SLAs
  • Experience designing or operating security controls and processes at scale
  • Experience integrating security tools, scanners, ticketing systems, asset inventories and reporting platforms
  • Strong technical understanding of some of the following: cloud infrastructure, application security, source code security, container security, network security, operating systems, CI/CD, APIs and automation
  • Ability to investigate complex findings, identify root causes and translate technical analysis into clear remediation guidance
  • Proven experience leading complex, ambiguous, cross-functional initiatives with multiple stakeholders
  • Strong communication skills and ability to influence engineers, technical leaders, risk teams and senior stakeholders
  • Professional fluency in English
  • Experience working in regulated environments or supporting audits and compliance programs
  • Experience developing scripts, automations or integrations using a programming or scripting language
  • CTEM knowledge
  • Availability to work onsite two to three days per week
  • Legal authorization to work in Brazil

Benefits

Comp & perks
  • Chance of earning equity at Nubank
  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
  • Public Transportation Commuting Benefit (Vale-Transporte)
  • NuCare – Psychological, Financial and Legal Assistance Program
  • Life Insurance
  • Medical Plan
  • Dental Plan
  • NuLanguage – Language Course Program
  • Nucleo - Our learning platform of courses
  • Extended Parental Leave
  • Daycare Allowance
  • Parental Consultancy
  • Work-from-home Allowance
  • Gym Partnerships
  • 30 days of paid vacation
  • Relocation Assistance Package, if applicable