Nu is the leading digital bank in Latin America, serving 135 million customers across Brazil, Mexico, and Colombia. The company has been leading an industry transformation by leveraging data and proprietary technology to develop innovative products and services.
Guided by its mission to fight complexity and empower people, Nu caters to customers’ complete financial journey, promoting financial access and advancement with responsible lending and transparency. The company is powered by an efficient and scalable business model that combines low cost to serve with growing returns.
Nu’s impact has been recognized in multiple awards, including Time 100 Most Influential Companies, Fast Company’s Most Innovative Companies, and Forbes World’s Best Banks.
Visit our Institutional Page
The Operational Risk Specialist, plays a vital role within the operational risk management function at Nu Mexico. The main duties involve identifying, assessing, monitoring, and mitigating operational risks that may hinder the company from reaching its objectives. This is accomplished by developing methodologies and ensuring their implementation and execution within the first line of defense. This process includes training, review and challenge, monitoring key risk indicators, and escalating issues in appropriate Risk Forums. This role involves close collaboration with different departments and teams to execute various Operational Risk programs aimed at reducing and controlling the likelihood and impact of adverse operational risk events.
Lead the oversight and continuous improvement of the Op Risk Management System, ensuring that policies, methodologies, procedures, governance practices, and supporting documentation remain aligned with local regulation and global standards.
Lead and coordinate the annual and continuous RCSA process, maintaining high-quality risk and control matrices by ensuring that operational risks are properly identified, documented, classified, assigned to processes and business lines, and linked to accountable owners and controls.
Perform independent 2LoD review and challenge of 1LoD risk assessments and controls, including the evaluation of inherent risk, residual risk, control design, control execution, supporting evidence, and overall control effectiveness.
Own the governance and periodic maintenance of risk matrices across macroprocesses, ensuring that changes in products, processes, regulations, systems, incidents, control gaps, and organizational priorities are properly reflected, documented, and traceable in the institutional risk inventory.
Assess complex operational risks and define appropriate treatment strategies based on inherent and residual risk exposure, risk appetite, and tolerance thresholds, including mitigation plans, risk transfers, formal risk acceptances, and escalation of risks outside tolerance.
Monitor operational loss events, incidents, and control gaps; lead or support root cause analysis; ensure accurate and timely registration; and define corrective, preventive, and improvement actions to reduce the likelihood of recurrence.
Design, manage, and enhance the Key Risk Indicator program for priority operational risks, ensuring that each applicable risk in the RCM has measurable indicators, defined amber and red thresholds, reliable data sources, periodic monitoring, documented analysis, and appropriate escalation.
Evaluate operational risks associated with new products, features, processes, operational changes, and other initiatives, ensuring that potential control gaps are identified, mitigation plans are defined, and required actions are completed before launch or formal implementation.
Prepare and present accurate, well-structured risk reports, dashboards, and management materials for senior leadership, the Non-Financial Risk Technical Forum, the Risk Committee, and other governance bodies, ensuring consistency and traceability to the RCM, loss-event database, KRI inventory, and control-gap management tools.
Operate with limited direct supervision and act as a subject matter expert, providing strategic guidance, training, and constructive challenge to business areas and specialized risk teams while escalating material residual risks, control weaknesses, and non-compliance issues to the appropriate governance forums.
Bachelor’s degree in Business Administration, Industrial Engineer, Risk Management or related field.
Minimum of 3+ years experience in operational risk management, internal audit, compliance, consulting.
Strong knowledge of the operational risk management frameworks (RCSA, Loss Database, Third Party Risk Management, Risk assessment of new products, etc).
Strong regulatory knowledge
Excellent analytical, communication, and problem-solving skills.
Ability to work independently and collaboratively with cross-functional teams
Ability to work with databases, ETL
Experience with regulatory compliance and corporate governance standards.
Strong knowledge of Control Testing and Monitoring throughout substantive testing and Key Risk Indicators (KRIs).
Experience with Governance, Risk and Compliance (GRC) systems.
Demonstrated ability to thrive in a fast-paced, rapidly evolving environment and adapt quickly to shifting priorities and changes in processes or regulations.
Fluent in English is a must.
Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.