Non-Financial Risk Management Expert — IT & Cyber Risk
$116k - $145kNubank
About Nu
Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns. Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks. Visit our Institutional PageAbout the Team
The Non-Financial Risk (NFR) team is part of Risk Management and provides second-line oversight and independent challenge across operational, technology, resilience, reputation and other non-financial risks. The team helps the organization identify, assess, prioritize, respond to, monitor, and communicate risks through consistent frameworks, governance, data, and tooling.
About the RoleStrategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company’s strategy.
Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.You will operate with significant autonomy, influence without formal authority, and accountability for outcomes that directly affect customers, OCC and FFIEC examination readiness, the bank's launch conditions, and Nubank U.S.'s ability to operate securely and in compliance from day one. As an independent second-line function, you set the risk frameworks, methodologies, and standards and then review, challenge, and validate.
You’ll be Responsible for
Act as a senior individual contributor and the Second Line of Defense (2LoD) subject-matter expert for information security and technology risk at Nubank U.S., providing independent oversight and challenge of the first line.
Strategize implementation plans with senior partners locally and globally.
Work with senior colleagues and technical areas to independently assess the root cause of material technology gaps and challenge the adequacy of remediation plans and control-strengthening actions.
Define, update, and oversee the Technology Risk framework, including policies, standards, methodologies, and assessment and reporting criteria.
Establish, update, and monitor technology risk metrics (KRIs, RAS), consolidating the view of exposure and trends for governing bodies.
Lead the preparation of regulatory reports and presentations to committees and governing bodies on Technology and Cybersecurity Risk.
Prepare responses and coordinate attention to regulatory and audit requests related to Technology Risk, interacting directly with those authorities when appropriate.
Provide independent oversight and challenge of the management of high-materiality technology and cybersecurity incidents, reviewing classification, root-cause analysis, and the adequacy of corrective actions.
Independently review and challenge the execution of institutional crisis protocols for technology and cybersecurity incidents, including the adequacy of pre-crisis reporting, internal communications, and coordination across key areas.
Provide second-line review and challenge of the first line's disaster recovery plans (DRP) and their testing, assessing the adequacy of technology controls and recovery capabilities.
Independently review and challenge the Business Impact Analysis (BIA), assessing whether the technology dependencies identified by the first line adequately reflect criticality and exposure to Technology Risk.
Provide guidance and challenge technology risk assessments for new products, features, and architectures, ensuring consistency and completeness.
Independently review the quality and consistency of IT and cybersecurity control testing, technology RCSAs, and incident monitoring performed by the first line.
Act as a key advisor to the leadership of Risk, Engineering, Security, Data, and other areas, fostering a strong culture of Technology Risk management.
Stay up to date on regulation, technology trends, emerging threats, and industry best practices, incorporating these learnings into the evolution of the Technology Risk framework.
What We're Looking For Someone Who Has
Required
Demonstrated ability to independently review, challenge, and validate a WISP (or equivalent information security program) against OCC/FFIEC standards — identifying gaps and building remediation plans.
Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.
Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, Cyberincident management, etc.
Understanding of Business Continuity and Disaster Recovery (BC/DR) practices
Knowledge of NIST CSF 2.0 as US banking cybersecurity assessment standards
Bachelor's degree in Engineering, Computer Science, Information Technology, a Risk Management-related field, or equivalent experience (Master's a plus); fluent English required and Portuguese is a plus
Excellent communication skills to articulate complex risk scenarios to senior stakeholders, auditors, and regulators.
Nice to Have
Prior experience standing up or examining a De Novo or newly chartered bank's information security program.
Proven experience in risk management within the fintech sector is a plus.
Professional certifications such as CRISC, CISA, CISM, and CDPSE
Hands-on experience with GRC platforms, control-testing workflows, security dashboards, and risk data models.
Knowledge of ISO 27001/27002, SOC 2, and related information security control frameworks.
Work Setup
Location
Miami, USA
Work model
Hybrid
Office requirement
2 days per week at the office. Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration.
For more details, visit
Our Benefits
Opportunity of earning equity at Nu
Medical Insurance
Dental and Vision Insurance
Life Insurance and AD&D
Extended maternity and paternity leaves
Nucleo - Our learning platform of courses
NuLanguage - Our language learning program
NuCare - Our mental health and wellness assistance program
Extended maternity and paternity leaves
401K
Saving Plans - Health Saving Account and Flexible Spending Account
Work-from-home Allowance
Relocation Assistance Package, if applicable.
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.
$155.6k - $306.8k
...: The mission of Quality and Risk Management (QRM) is to manage the risk in... ...complex business to improve financial performance and protect the firm... .... Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality... ...), Teaming Agreements, and Non-Disclosure Agreements.Conducts...CyberFinancialContract workFor subcontractorWork at officeLocal area$119k - $299.93k
...and objective assessments of financial statements, internal controls... ...including assessing governance and risk management processes and related... ...including processes and controls, cyber security measures, data and... ..., and controls, and leading IT-related controls assurance or...CyberFinancialFull timeH1b$72k - $184.44k
...and objective assessments of financial statements, internal controls... ...including assessing governance and risk management processes and related... ...including processes and controls, cyber security measures, data and... ...financial reporting and IT risks- Analyzing current and...CyberFinancialFull timeH1bWork at office$124k - $280k
...Implementation Solutions - Senior Manager, you will focus on maintaining... ...compliance and managing risks for clients, providing advice and solutions. Within our Cyber, Data & Tech Risk practice, you... ...on anti-money laundering and financial crime prevention measures Utilizing...CyberFinancialH1b- ...will help companies build cyber resilience to grow with... ...from within. We blend risk strategy, digital identity... ...security, and managed service solutions to rethink... ...security consulting role. It is not a compliance advisory... ...production environment—non-negotiable; theoretical...CyberFull timeWork experience placementLive inWork at officeLocal area
$76.6k - $157k
...Consultant - Technology Third Party Risk Management (TPRM) role offers an... ...Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy,... ...messages for technical and non-technical audiences and keep... ...:Experience in a tax, financial services, or professional services...CyberFinancialWork at officeLocal areaVisa sponsorshipShift work- ...Security teams to reduce risk to Carnival Corp... ...security posture management (AISPM/DSPM) across... ...concepts in non-technical terms to... ...Bachelor's degree in Cyber Security, Computer... ...an in-office role, it requires employees... ...disability coverage Financial Benefits: 401(k) plan...CyberFinancialFull timePart timeWork at officeLocal areaWork from homeRelocationMonday to Thursday
- ...leading GVW’s enterprise risk capability across the... ..., and technology risk. It is not a traditional compliance... ..., and actively managed across operations, investments... ...business. Technology, Cyber & AI Risk Oversee... ...key risks (operational, financial, supply chain, product)...CyberFinancialWork at office
$300k - $360k
...of the Bank’s Executive Management Team and will be... ...expectations, supports the Bank’s risk appetite, and protects... ...validate readiness for cyber incidents and system... ...at a regulated financial institution or Fintech.... ...Core Competencies Expert knowledge of information...CyberFinancialWork at officeRemote workFlexible hours- ...efficiency. The Head of Group Risk & Decision Governance... ...or product failures Cyber incidents Regulatory... ...handled reactively Financial, Treasury, & Counterparty... ...required to perform. Management reserves the right to modify... ...with applicable laws. Non‑Exhaustive List of...CyberFinancialContract workWork at officeLocal areaRemote work
$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the... ...of cyber threats and vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end...CyberLocal areaVisa sponsorship$175k - $250k
...to collaboration, disciplined risk management and continuous learning. With... ...center of excellence for expert-level solutions, architecture... ...software demos for technical and non-technical audiences,... ...Preferred experience includes financial services or fintech, building...FinancialFlexible hours$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...CyberLocal areaVisa sponsorship$116.2k - $229.1k
...The Team The mission of Quality and Risk Management (QRM) is to manage the risk in our growing... ...increasingly complex business to improve financial performance and protect the firm’s assets... ...findings clearly to both technical and non-technical audiencesStakeholder engagement...FinancialLocal area$142.6k - $297.2k
...a Technology Business Analyst Manager, where you will bridge the gap... ..., or projects with a focus on risk management. Your responsibilities... .../or integrations with SAP and non-SAP systems. Consistently... ...Managerial Accounting Financial Accounting Material Management...FinancialFull timeSummer holidayFlexible hours$82.5k
...global leader and innovator in the financial services industry and is... ...analysts responsible for agency and non-agency loan servicing... ...challenges. Loan Servicing Execution Manage the full lifecycle of... ...including front office, credit risk, legal, compliance, and technology...FinancialWork experience placementWork at officeShift work$96k - $113k
...we are reimagining the way we help customers to manage risk. Join us as Underwriting Quality Manager to play... ...help to find insurance solutions in areas including Financial Lines, Property, Casualty, Specialty Lines, Cyber, and Multinational Clients. We are reimagining...CyberFinancialFull timeWork experience placementWork at officeLocal areaHome office- Description The Non-Producing Branch Manager is responsible for the overall leadership, profitability, risk management, and operational excellence of the branch. This role focuses... ...is fully accountable for the branch’s financial results, sales execution, operational integrity...FinancialWork at officeLocal area
- ...maintenance and asset management. Are you open to diverse... ...solar and energy storage experts who bring deep... ...experienced Insurance Risk Manager to manage the organization... ...reports to Chief Financial Officer and is a regular... ...Directors & Officers, Cyber, Crime, etc.Work with internal...CyberFinancialFull timeWork at office
- ...cybersecurity services across strategy, risk management, digital identity, cyber defense, and managed security. With... ...role demands deep expertise across IT and OT environments and the ability... ...IT stakeholders, Accenture domain experts and other third-party teams as needed...CyberFull timeWork experience placementLive inWork at officeLocal areaRemote work
$169.01k - $370.53k
...Specialist Director, Cloud Security to join our Managed Services practice. Responsibilities:... ...including oversight of security posture, risk remediation, compliance, and continuous... ...management coordination and oversight of Cyber Managed Services delivery across multiple...CyberH1bLocal area$113.1k - $208.3k
...Deloitte, is seeking a Senior Manager to lead the Vendor... ...drives vendor governance, financial optimization, performance management, and risk alignment across a... ...Procurement, Finance, Legal, Cyber, Risk, and Technology to... ...years of experience in IT vendor management, supplier...CyberFinancialContract workWork at officeRemote workWork from home$134.5k - $265.1k
Position Summary Cyber Oracle Cloud Security - Manager / Engineering Manager II Are you interested in working... ...security by delivering governance, risk, and compliance solutions that... ...Advanced Access Controls, Advanced Financial Controls, and Financial Reporting Controls...CyberFinancialLocal areaVisa sponsorship- ...cybersecurity services across strategy, risk management, digital identity, cyber defense, and managed security. With... ...role demands deep expertise across IT and OT environments and the ability... ...IT stakeholders, Accenture domain experts, and third-party teams. You will lead...CyberFull timeWork experience placementLive inWork at officeLocal areaRemote work
$105k - $120k
...standards of excellence.Manages and coordinates... ...training, and quality and risk management.Conduct Phase... ...experience overseeing financial performance of an engineering... ...information to non-technical clients. REASONING... ...complex situations. Requires expert level analytical and...FinancialFull timeTemporary workFor subcontractorWork at officeLocal areaRemote work$102.8k - $176k
...seeking to add a Strategic Account Manager to our Enterprise Sales... ...growing our cybersecurity and risk consulting practice. The Strategic... ...is responsible for developing cyber and risk consulting accounts through... ...strategy, technology risk, IT audit, governance risk and compliance...CyberFull timeContract workWork experience placementInternshipWork at officeLocal area$82.5k
...global leader and innovator in the financial services industry and is... ...operations, with experience in a management or supervisory or leadership... ...experience with syndicated and non-agency loan products,... ...OnGoing/NH eGuide (foleon.com) Risk Culture We embrace a strong risk...FinancialHourly payContract workWork experience placementWork at officeShift work$134.5k - $265.1k
Position Summary Cyber Manager - ServiceNow Our Deloitte Cyber team... ...scope, schedule, budget, risks, assumptions, issues, dependencies... ...’s cyber posture. It includes design of the cyber... ...TPRM).3+ years managing program financials, executive reporting, stakeholder...CyberFinancialLocal areaRemote workVisa sponsorship$121.6k - $248k
...world’s leading vendor of Cyber Security, facing the... ...Solution Architect – Exposure Management is a senior global role... ...the senior technical expert throughout customer... ...exposure management or risk‑based vulnerability... ...with MSSPs, enterprise IT teams, or security operations...CyberTemporary work$152k - $193k
...joining the journey to build a financial platform and become a... ...hands-on and technical Product Manager for our Fraud team to lead the... ...scaling of our next-generation risk platform. This role requires a... ...setting up, and interpreting non-trivial A/B tests to ensure statistically...Financial
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Non-Financial Risk Management Expert — IT & Cyber Risk. Be the first to apply!
- technology expert Miami, FL
- subject matter expert Miami, FL
- fulfillment expert Miami, FL
- guest service support expert Miami, FL
- citizens financial group Miami, FL
- financial clearance Miami, FL
- financial executive Miami, FL
- financial educator Miami, FL
- financial recruiter Miami, FL
- emergent financial group Miami, FL

