The posting, in Nubank's own words
archived Sep 20, 2026About Nu
Nu is the leading digital bank in Latin America, serving 140 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services. Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns. Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks. Visit our Institutional Page
About the role
You will lead the team that stands between adversaries and 135 million customers. The Threat Detection team proactively hunts for security threats and builds robust, actionable detections to protect both customers and Nubankers — operating as a true Security Operations Center, backed by strong engineering power and intelligence from our internal Threat Intelligence team. As Lead, you own the strategic Threat Detection program end to end: intelligence gathering, threat modeling, detection engineering, AI-assisted analysis, Purple Team validation, incident response and post-incident learning. Your goal is to make sure effective detection rules, actionable insights and AI-enabled security capabilities are in place and aligned with industry best practices, so that adversary activity across Nubank's environment is identified, prevented and detected before it reaches our customers. You'll also build and lead a high-performing team, support Security leadership in building a world-class security organization, and ensure detection processes meet auditing requirements and support clear communication with regulatory bodies. Learn more about Nubank Infosec: https://blog.nubank.com.br/infosec-nubank-protecao-dados/
Read the full posting ↓
You'll be responsible for
Analyzing cyber threat intelligence, emerging attack trends and security telemetry to develop robust detections and threat models, while reducing false positives and improving the efficiency of security operations. Leveraging AI and machine learning across the detection lifecycle — anomaly detection, behavioral analytics, alert triage, threat intelligence enrichment, investigation prioritization and response automation — and leading their adoption so these capabilities are reliable, measurable and secure. Defining validation, quality, explainability and security controls for AI-assisted capabilities, accounting for risks such as inaccurate outputs, data leakage, prompt injection, model manipulation and adversarial evasion. Leading Purple Team activities with Offensive Security, Threat Intelligence, Incident Response and Engineering: translating adversary behaviors into realistic attack simulations, adversary emulation plans and detection validation scenarios mapped to frameworks such as MITRE ATT&CK. Identifying detection and prevention gaps, validating security controls, measuring detection coverage and driving remediation through actionable improvement plans. Establishing feedback loops between offensive and defensive teams so lessons from simulations and real incidents continuously improve detection, investigation and response. Defining success criteria and tracking metrics: detection coverage, validation success rate, false-positive reduction, investigation time, response efficiency and remediation cycle time. Building and leading the team — mentoring engineers and fostering a culture of ownership, accountability, collaboration and continuous learning. Partnering closely with Security Engineering, Threat Intelligence, Software Engineering and Incident Response to build scalable solutions for analyzing security event data and a resilient security architecture aligned with Business Unit strategy.