Cybersecurity Manager — Nium Brazil
Nium
Curitiba, PR, Brazil
With a growing presence in Latin America, Nium Brazil is at the forefront of transforming how businesses and consumers transact in one of the world’s most dynamic fintech markets. Our Brazil operations are fully regulated and committed to delivering secure, compliant, and innovative payment experiences.
Role Overview
Nium Brazil is seeking a Cybersecurity Manager to own the organisation’s cybersecurity compliance obligations under Resolution BCB 85/2021 and act as the primary point of accountability for cyber risk in Brazil. Reporting to the Country Manager with a dotted reporting line to the Group CISO, this role sits at the intersection of local regulatory compliance and hands-on security operations in a fast-growing, regulated payment institution.
This is an opportunity for a cybersecurity professional to step into a high-impact, visible role with broad cross-functional exposure — shaping how Nium Brazil manages cyber risk as the business scales.
Key Responsibilities
- Ensure the Group’s cybersecurity policy remains fully aligned with BCB Resolution 85/2021 and any subsequent regulatory updates.
- Act as the designated local lead for all BCB cybersecurity obligations, coordinating with Group security teams to meet local requirements.
- Produce regular management reporting on the organisation’s cybersecurity posture, open risks, and any incidents.
- Track regulatory changes to cybersecurity requirements and lead the assessment and implementation of any operational or process impacts.
- Enforce local access controls across critical systems, ensuring user permissions are regularly reviewed and appropriately restricted.
- Oversee identity and access management for Brazil-based users and systems, working with Group IT to align with global standards.
- Manage privileged access reviews and ensure segregation of duties is maintained across key operational functions.
- Act as first responder to local cybersecurity incidents — logging, triaging, escalating, and reporting within required regulatory timeframes.
- Maintain and regularly test Brazil’s incident response and business continuity procedures in line with BCB guidance.
- Coordinate vulnerability assessments and penetration testing programmes with the Group technology team, tracking remediation to closure.
- Monitor threat intelligence relevant to the Brazilian payments landscape and proactively brief senior leadership on emerging risks.
- Manage third-party and vendor cybersecurity risk, ensuring external partners and service providers meet Nium’s security standards and BCB requirements.
- Conduct or oversee cybersecurity due diligence for new vendor onboarding and periodic reviews of existing suppliers.
- Maintain a register of critical third-party relationships and their associated cyber risk profiles.
Regulatory Compliance & Governance
Access Controls & System Security
Incident Response & Threat Management
Third-Party & Vendor Risk
What We’re Looking For
- 3–5 years of experience in a cybersecurity, information security, or technology risk role within a regulated financial institution or payment institution.
- Demonstrable knowledge of BCB Resolution 85/2021 and related cybersecurity regulatory requirements in Brazil.
- Hands-on experience with incident response, access management, vulnerability management, and third-party risk.
- Experience operating as a first line of defence in a regulated environment.
- Fluency in Portuguese and English.
- Strong understanding of cybersecurity frameworks and controls relevant to financial services (e.g. ISO 27001, NIST).
- Ability to translate complex regulatory requirements into practical, operational controls.
- Confident working cross-functionally with technology, operations, legal, and product teams.
- Familiarity with LGPD (Lei Geral de Proteção de Dados) obligations in a financial services context.
- Highly organised with strong attention to detail.
- Comfortable working in a fast-paced, evolving regulatory environment.
- A self-starter who can take ownership of obligations and drive them to resolution.
- A collaborative team player who can influence without authority.
- Strong communicator, able to present technical risk topics clearly to non-technical stakeholders.
Experience
Skills & Knowledge
Personal Attributes