Non-Financial Risk Management Expert - IT & Cyber Risk

Nubank

$116K — $145K *
Miami, FL 33186In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of technology risk management experience, specifically in banking or fintech environments.
  • Demonstrated ability to independently assess information security programs against OCC/FFIEC standards.
  • Familiarity with cloud computing models and service providers like AWS.
  • Strong understanding of cybersecurity principles and practices related to technology risk.
  • Bachelor's or equivalent in Engineering, Computer Science, IT, or Risk Management; Master's preferred.
  • Excellent communication skills for engaging with senior stakeholders and regulators.

Responsibilities

  • Act as the second line of defense subject-matter expert in technology risk management.
  • Develop and implement the Technology Risk framework and associated policies.
  • Coordinate with internal parties to assess and challenge remediation plans for technology gaps.
  • Lead preparation of regulatory reports and present key findings to governing bodies.
  • Monitor technology risk metrics and consolidate insights for oversight bodies.
  • Review disaster recovery plans and their adequacy in managing technology risks.
  • Stay updated on regulatory standards, emerging threats, and industry best practices.

Benefits

  • Equity earning opportunities at Nubank.
  • Comprehensive medical, dental, and vision insurance.
  • Life insurance and accidental death & dismemberment coverage.
  • Enhanced maternity and paternity leave options.
  • Access to a dedicated learning platform and language program.
  • Mental health and wellness assistance through NuCare.
  • 401K plans and health savings options.
  • Work-from-home allowance and potential relocation assistance.
Full Job Description
About the Team

The Non-Financial Risk (NFR) team is part of Risk Management and provides second-line oversight and independent challenge across operational, technology, resilience, reputation and other non-financial risks. The team helps the organization identify, assess, prioritize, respond to, monitor, and communicate risks through consistent frameworks, governance, data, and tooling.

About the Role

Strategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company's strategy.

Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.

You will operate with significant autonomy, influence without formal authority, and accountability for outcomes that directly affect customers, OCC and FFIEC examination readiness, the bank's launch conditions, and Nubank U.S.'s ability to operate securely and in compliance from day one. As an independent second-line function, you set the risk frameworks, methodologies, and standards and then review, challenge, and validate.
You'll be Responsible for
  • Act as a senior individual contributor and the Second Line of Defense (2LoD) subject-matter expert for information security and technology risk at Nubank U.S., providing independent oversight and challenge of the first line.
  • Strategize implementation plans with senior partners locally and globally.
  • Work with senior colleagues and technical areas to independently assess the root cause of material technology gaps and challenge the adequacy of remediation plans and control-strengthening actions.
  • Define, update, and oversee the Technology Risk framework, including policies, standards, methodologies, and assessment and reporting criteria.
  • Establish, update, and monitor technology risk metrics (KRIs, RAS), consolidating the view of exposure and trends for governing bodies.
  • Lead the preparation of regulatory reports and presentations to committees and governing bodies on Technology and Cybersecurity Risk.
  • Prepare responses and coordinate attention to regulatory and audit requests related to Technology Risk, interacting directly with those authorities when appropriate.
  • Provide independent oversight and challenge of the management of high-materiality technology and cybersecurity incidents, reviewing classification, root-cause analysis, and the adequacy of corrective actions.
  • Independently review and challenge the execution of institutional crisis protocols for technology and cybersecurity incidents, including the adequacy of pre-crisis reporting, internal communications, and coordination across key areas.
  • Provide second-line review and challenge of the first line's disaster recovery plans (DRP) and their testing, assessing the adequacy of technology controls and recovery capabilities.
  • Independently review and challenge the Business Impact Analysis (BIA), assessing whether the technology dependencies identified by the first line adequately reflect criticality and exposure to Technology Risk.
  • Provide guidance and challenge technology risk assessments for new products, features, and architectures, ensuring consistency and completeness.
  • Independently review the quality and consistency of IT and cybersecurity control testing, technology RCSAs, and incident monitoring performed by the first line.
  • Act as a key advisor to the leadership of Risk, Engineering, Security, Data, and other areas, fostering a strong culture of Technology Risk management.
  • Stay up to date on regulation, technology trends, emerging threats, and industry best practices, incorporating these learnings into the evolution of the Technology Risk framework.


What We're Looking For Someone Who Has

Required
  • Demonstrated ability to independently review, challenge, and validate a WISP (or equivalent information security program) against OCC/FFIEC standards - identifying gaps and building remediation plans.
  • Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.
  • Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, Cyberincident management, etc.
  • Understanding of Business Continuity and Disaster Recovery (BC/DR) practices
  • Knowledge of NIST CSF 2.0 as US banking cybersecurity assessment standards
  • Bachelor's degree in Engineering, Computer Science, Information Technology, a Risk Management-related field, or equivalent experience (Master's a plus); fluent English required and Portuguese is a plus
  • Excellent communication skills to articulate complex risk scenarios to senior stakeholders, auditors, and regulators.

Nice to Have
  • Prior experience standing up or examining a De Novo or newly chartered bank's information security program.
  • Proven experience in risk management within the fintech sector is a plus.
  • Professional certifications such as CRISC, CISA, CISM, and CDPSE
  • Hands-on experience with GRC platforms, control-testing workflows, security dashboards, and risk data models.
  • Knowledge of ISO 27001/27002, SOC 2, and related information security control frameworks.


Work Setup

Location

Miami, USA

Work model

Hybrid

Office requirement

2 days per week at the office. Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration.
For more details, visit https://building.nubank.com/nu-hybrid-work-model/

Total compensation includes base salary, RSUs and benefits. Base salary range: US$116k - US$145k.

Our Benefits
  • Opportunity of earning equity at Nu
  • Medical Insurance
  • Dental and Vision Insurance
  • Life Insurance and AD&D
  • Extended maternity and paternity leaves
  • Nucleo - Our learning platform of courses
  • NuLanguage - Our language learning program
  • NuCare - Our mental health and wellness assistance program
  • Extended maternity and paternity leaves
  • 401K
  • Saving Plans - Health Saving Account and Flexible Spending Account
  • Work-from-home Allowance
  • Relocation Assistance Package, if applicable.

Our recruitment process may involve the use of artificial intelligence-enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

Similar Jobs

More Jobs at Nubank

More Information Technology Jobs

Find similar Non-Financial Risk Management Expert - IT & Cyber Risk jobs: