Senior Security Engineer - Application Security- BR - 2026
Nubank São Paulo, São Paulo, Brazil
Financial Services · 5,001-10,000 employees
About the role
The role involves embedding security practices into the software development lifecycle and deploying security tools within CI/CD pipelines. You will also perform threat modeling, conduct security reviews, and automate security processes to support secure innovation.
What they look for
Requirements
Candidates must have a solid understanding of application security concepts and hands-on experience with CI/CD pipelines and security tools. Proficiency in scripting languages like Python or Go and experience with modern software architectures are also required.
Benefits
Full description
About Nu
Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Visit our Institutional Page
About the team
The Application Security team is part of the Information Security area. The team focuses on proactive hunting for and mitigating potential security threats on Nubank to protect our customers' financial assets and data. For that, we perform many tasks such as embedding and developing security controls on the applications, supporting all engineers during the software development lifecycle. Our AppSec team is at the forefront of enabling secure innovation at Nubank. We believe security should be an enabler, not a blocker, and we build scalable solutions to help developers ship secure code without friction. From designing AI-powered threat modeling tools to automating security in CI/CD, our work impacts every Nubanker engineer.
About the role
As a Security Engineer in our Application Security (AppSec) team, you will be part of the group responsible for enabling secure software development practices across Nubank’s entire engineering organization. We support teams working with a diverse technology stack – including Clojure, Python, Go for backend and Kotlin, Swift, Dart for mobile – by embedding security into their SDLC.
This role is ideal for someone with a strong foundation in application security concepts, who enjoys working closely with engineering teams to drive security best practices, and who has a keen interest in emerging areas such as AI security and threat modeling.
Your mission will include helping design and deploy security tools in our CI/CD pipelines (SAST, DAST, SCA), performing threat modeling for new projects, supporting security reviews, and contributing to the automation of AppSec processes, including those involving new AI technologies like Model Context Protocol (MCP) Servers and agents.
You'll be responsible for Embed security practices into the SDLC across backend, mobile, and web applications.
- Deploy and maintain security tools (SAST, DAST, SCA, MAST) in CI/CD pipelines.
- Perform threat modeling and security reviews for new and existing projects.
- Develop scripts and tools (Python, Go, Bash) to automate security checks and processes.
- Collaborate with engineering teams to explain and remediate vulnerabilities.
- Support AI-related security initiatives, ensuring safe adoption of ML/AI features in products.
- Contribute to the evolution of internal security guidelines and baselines.
- Participate in cross-functional discussions to align security requirements with business goals.
We are looking for a person who has
Must-have
- Solid understanding of application security concepts and secure software development practices.
- Hands-on experience with CI/CD pipelines and implementing security tools (e.g., SAST, DAST, SCA).
- Knowledge of scripting/programming with commonly used languages like Python, Go, bash, etc for automation and tooling.
- Familiarity with container security tools (e.g., Trivy, Aqua).
- Experience working with modern software architectures: Web, Mobile, APIs, and MCPs.
- Strong communication and collaboration skills to work with multi-disciplinary teams.
Nice to Have
- Previous experience conducting security assessments in distributed systems environments.
- Experience with tools like Semgrep, Fortify, Checkmarx, Veracode.
- Experience with pipeline tools like Github Actions, Gitlab Workflow, others.
- Experience with AI security concepts and emerging AI/ML security risks.
- Familiarity with threat modeling methodologies (e.g., STRIDE, PASTA, OWASP Threat Dragon).
- Knowledge of regulatory and compliance requirements relevant to financial services.
Location
São Paulo, Brazil Campinas, Brazil Rio de Janeiro, Brazil Belo Horizonte, Brazil
Our Benefits
- Chance of earning equity at Nubank
- Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)
- Public Transportation Commuting Benefit (Vale-Transporte)
- NuCare – Psychological, Financial and Legal Assistance Program
- Life Insurance
- Medical Plan
- Dental Plan
- NuLanguage – Language Course Program
- Nucleo - Our learning platform of courses
- Extended Parental Leave
- Daycare Allowance
- Parental Consultancy
- Work-from-home Allowance
- Gym Partnerships
- 30 days of paid vacation
- Relocation Assistance Package, if applicable
Work Model for this Role
Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.
Similar roles
-
Vice President, Institutional Sales (financial technology, digital assets, blockchain, cybersecurity..)
Ant-Tech United States · $140K–$220K/yr
-
Senior Security Engineer
The Lottery Corporation Brisbane, Queensland, Australia
-
Security Engineer II, Stores AppSec
Amazon Austin, Texas, United States · $159K–$202K/yr
-
Security Engineer II, Stores Application Security, SDO AppSec, Stores Security
Amazon New York, New York, United States · $159K–$213K/yr
-
LeadRisk Assessor_Cybersecurity
XPT Software Australia Pty Ltd Victoria, Australia
-
Senior Content Security Engineer, GME Security
Amazon London, England, United Kingdom