Jobs › Washington State › Seattle › Staff Security Engineer - Identity Risk & Governance
Staff Security Engineer - Identity Risk & Governance
Nubank is hiring for the role of Staff Security Engineer - Identity Risk & Governance, Seattle, WA (Hybrid). This is a Cybersecurity role in the governance, risk, and compliance field. Review the full details below and apply directly with Nubank.
About Nu Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services. Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns. Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks. Visit our Institutional Page About the Role Nubank is seeking a Staff Security Engineer to contribute in the Identity and Access Management security function across a financial technology organization serving over 100 million customers in Brazil, Mexico, and Colombia. This is a senior individual-contributor role with organizational-level technical influence, responsible for supporting a multi-year IAM security strategy, directing its execution across multiple engineering teams, and ensuring that identity and access controls meet the security, regulatory, and operational requirements of a globally operating financial institution. The Staff Security Engineer is expected to bring a demonstrated history of delivering consequential security programs — including programs that encountered setbacks — and the technical judgment that only sustained, hands-on experience in the domain produces. Critically, this role requires a security engineering philosophy grounded in business enablement: the conviction that security done well accelerates what the organization can do, not merely protects it. This means rigorously distinguishing between controls that reduce real risk and those that create the appearance of compliance without reducing exposure, taking genuine ownership of outcomes rather than delegating accountability through policy, and continuously questioning inherited assumptions about what security measures are necessary, sufficient, or proportionate. What You’ll Be Responsible For Defining, communicating, and executing a multi-year security strategy (especially in the IAM field) aligned with the organization's risk posture, regulatory obligations, and business objectives across multiple countries and regulatory jurisdictions. Lead organization-wide authentication migrations that span heterogeneous surfaces — browser, operating system login, CLI tooling, and API-level integrations — across thousands of employees, multiple device ecosystems, and distributed work environments, producing measurable outcomes: authentication success rates above 99%, material reductions in per-authentication time, support exception rates below 1%, and return on investment within weeks of enforcement. Designing and maintaining the core identity infrastructure with the durability and operational discipline required at organizational scale: enterprise Identity Provider, PKI and X.509 certificate lifecycle automation, mutual TLS for service-to-service authentication, and credential management systems engineered to remain sound as the organization grows. Translating least-privilege access from a principle into a measurable, organization-wide program — with defined metrics, visible adoption curves, and accountability structures that allow Security and Engineering leadership to track and act on the organization's access risk posture over time. Designing and maintaining a security engineering framework — comprising technical mechanisms, policies, incentives, and assurance processes — that ensures security properties are durable, verifiable, and operationally sound, rather than dependent on individual vigilance or periodic audits. Leading technical incident response for identity and access security events, including critical vulnerabilities in remote access infrastructure, ensuring thorough investigation, documented root cause analysis, and structural improvements that reduce the likelihood and impact of recurrence. Designing and facilitating large-scale preparedness exercises grounded in realistic attack paths — involving engineering, operations, and executive functions — to identify genuine gaps in IAM controls, not merely satisfy a compliance requirement. Providing technical mentorship and coaching to senior engineers; lead innovative projects with universities and actively collaborate in hiring and career decisions in order to maintain a high technical standard throughout the safety organization. Serving as the technical authority in engagements with Legal, Compliance, internal audit, and external regulators on matters related to identity, authentication, and access control. We Are Looking for a Person Who Has Must-have +15 years of professional experience in security engineering, with a concentration in identity, authentication, or access management. Demonstrated track record of leading complex, multi-year security programs from conception through measurable outcome — including programs that required navigating organizational obstacles, technical constraints, or material mid-course corrections. Expert-level knowledge of IAM and authentication protocols: OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, mTLS, and Public Key Infrastructure (PKI). Proficiency in software engineering: ability to produce, review, and reason about production-quality code in at least one general-purpose programming language. Demonstrated ability to model identity-related threat scenarios, assess attacker techniques relevant to the IAM surface, and design controls that remain effective under adversarial conditions. A demonstrable commitment to security as an organizational capability that enables business outcomes: a track record of solving real security problems, a disposition to challenge inherited s
Location and market context
This role is based in Seattle on-site. Local candidates benefit from being close to Nubank's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance roles
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance role
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Nubank would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Deputy Director, Digital Transformation and AI Policy & Advocacy · Bill & Melinda Gates Foundation · Seattle, WA
- Deputy Director, Artificial Intelligence & Digital Health Evidence and Learning · Bill & Melinda Gates Foundation · Seattle, WA
- Director, Compliance and Risk · Premera · Seattle, WA
- Regional Compliance Officer · KeyBank · Seattle, WA
- Staff Product Manager, Risk Product Experience · Stripe · Seattle, New-York, San Francisco
- Cybersecurity GRC Team Lead · University of Texas at Austin · Austin, TX · Remote
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.