US CISO
About The Team
The company is guided by its mission to fight complexity and empower people, catering to customers' complete financial journey while promoting financial access and advancement with responsible lending and transparency.
About The Role
We are seeking a visionary, highly specialized US Chief Information Security Officer (CISO) to join our expanding team in the US. This is not a traditional operational CISO role. You will serve as the executive pillar for Nubank's US strategy, bridging the gap between traditional financial regulations and modern, hyper-scalable crypto and AI technology platforms.
Key Responsibilities And Expectations
US Regulatory & Regulatory Agency Liaison: Serve as the primary US security authority and point of contact for regulators (e.g. OCC). Oversee all mandatory statutory disclosures, including financial and IBFR background reviews.
Crypto & Web3 Product Defense: Partner with crypto product and infrastructure teams to secure future-proof financial technologies, translating complex blockchain architectures into compliant, enterprise-grade risk frameworks.
Governance, Risk, and Compliance (GRC) Transformation: Uplevel Nubank’s GRC program to support multi-geography scaling.
AI Security Frameworks: Lead the strategic security response for AI initiatives—from developer workflows and engineering toolsets to model integrity and deployment risks.
Insider Threat Program Development: Design, build, and deploy an end-to-end enterprise Insider Threat program across first and second lines of defense in close partnership with Risk and Legal teams.
Qualifications
Professional Experience & Education: Executive Leadership Experience: 15+ years in Information Security, with significant experience operating at an executive, director, or CISO level within FinTech, Banking, or Digital Assets.
US Financial Regulatory Expertise: Deep hands-on experience navigating US regulatory environments, specifically working with the OCC, statutory disclosure processes, and financial institution compliance.
Cryptocurrency & Blockchain Security: Demonstrated domain expertise in cryptocurrency security, decentralized finance, or digital asset platforms. Experience at leading crypto-native institutions or hyper-growth FinTechs is highly valued.
AI Security Strategy: Familiarity with modern AI security risks, LLM integrations, safe code generation tools, and model security.
GRC Upleveling: Proven track record of rebuilding or scaling GRC frameworks within complex, multi-national organizations.
Executive Communication: Exceptional communication skills needed to interface effectively with regulatory examiners, executive leadership, and board members.
Competencies & Attributes
Fluency in English is required; Portuguese and/or Spanish are a plus.
Strong people leadership at scale, including developing managers and leading teams of differing maturity through change and ambiguity.
Excellent stakeholder management and communication, with maturity in negotiation and conflict resolution across senior cross-functional partners.
A pragmatic, hybrid profile, balanced across people leadership, product sensibility, and technical depth rather than weighted to any single one.
A genuine product mindset focused on customer and agent outcomes, with the technical depth to raise the bar in architectural discussions.