As a Security Engineer in our Application Security (AppSec) team, you will be part of the group responsible for enabling secure software development practices across Nubank’s entire engineering organization. We support teams working with a diverse technology stack – including Clojure, Python, Go for backend and Kotlin, Swift, Dart for mobile – by embedding security into their SDLC
This role is ideal for someone with a strong foundation in application security concepts, who enjoys working closely with engineering teams to drive security best practices, and who has a keen interest in emerging areas such as AI security and threat modeling
Your mission will include helping design and deploy security tools in our CI/CD pipelines (SAST, DAST, SCA), performing threat modeling for new projects, supporting security reviews, and contributing to the automation of AppSec processes, including those involving new AI technologies like Model Context Protocol (MCP) Servers and agents
You'll be responsible for
Embed security practices into the SDLC across backend, mobile, and web applications
Deploy and maintain security tools (SAST, DAST, SCA, MAST) in CI/CD pipelines
Perform threat modeling and security reviews for new and existing projects
Develop scripts and tools (Python, Go, Bash) to automate security checks and processes
Collaborate with engineering teams to explain and remediate vulnerabilities
Support AI-related security initiatives, ensuring safe adoption of ML/AI features in products
Contribute to the evolution of internal security guidelines and baselines
Participate in cross-functional discussions to align security requirements with business goals
WE ARE LOOKING FOR A PERSON WHO HAS