SDE- II (Security)
SDE II - Security
Build products and experiences that simplify finance for a billion people.
Location: Bangalore
About Navi
At Navi, our mission is to simplify finance for a billion people, through technology-first products built at scale.
Founded in 2018 by Sachin Bansal and Ankit Agarwal, Navi has grown rapidly across Loans, UPI, Insurance, Mutual Funds and Digital Gold – building products designed around speed, simplicity and customer experience.
Today, millions of customers use Navi for experiences like instant personal loans, fully digital home loan sanctions within minutes, low-cost mutual funds, instant credit lines in minutes and one of India’s fastest-growing UPI platforms.
About the Team
Navi’s Engineering team builds the backbone of our financial products—spanning lending, payments, insurance, investments, and debt management. We operate as cross-functional teams that work closely with Product, Data, and Business functions to deliver reliable, high-performance systems at scale. Our engineers focus on solving real-world challenges through scalable architecture, automation, and long-term thinking—ensuring every Navi product is built to serve millions efficiently and seamlessly.
About the Role
We are seeking a Security Engineer II to strengthen Navi’s product security posture across web, mobile, and cloud-native systems. This mid-level role owns end-to-end security assessments for assigned product areas, builds scalable automation, and partners closely with engineering to drive remediation. You will operate independently on complex VAPT engagements, contribute to threat modeling and secure design reviews, and support red team and audit readiness efforts—while mentoring junior engineers and raising the security bar across the SDLC.
What You’ll Own
Application & Product Security Assessments
Independently plan and execute VAPT across web applications, REST/GraphQL APIs, microservices, and mobile apps (iOS/Android), covering complex multi-step attack paths beyond common OWASP findings.
Own security assessments for assigned product lines or release cycles—from scoping and testing through reporting and verified remediation.
Perform deeper mobile and client-side analysis (e.g., insecure storage, certificate pinning bypass patterns, API abuse) and validate issues with clear, reproducible PoCs.
2. Security Automation & Tooling
Design and maintain automation that scales repetitive VAPT, scanner triage, and reporting workflows (Python/Go/Bash).
Integrate and tune SAST/DAST/SCA and related security tooling in CI/CD pipelines; reduce false positives and improve signal quality for engineering teams.
Build reusable internal tools, checklists, and playbooks that improve coverage and consistency of product security testing.
3. Vulnerability Management & Remediation
Triage security findings; prioritize by risk, business impact, and exploitability.
Partner with engineering to drive timely remediation, validate fixes, and track residual risk for high-severity issues.
Produce clear technical reports for engineering and leadership that explain root cause, impact, and practical mitigations.
4. Threat Modeling & Secure Design Support
Participate in and increasingly lead threat modeling for new features and major architecture changes.
Review designs and PR-level changes for security anti-patterns; recommend pragmatic controls aligned with Navi’s risk posture.
Help embed secure coding guidance and DevSecOps guardrails into day-to-day engineering workflows.
5. Offensive Exercises & Detection Feedback
Contribute to Red Team / adversary simulation exercises under program guidance—covering realistic attack scenarios against apps, APIs, and cloud configurations.
Share findings that improve detection, logging, and response readiness in partnership with security operations and platform teams.
6. Mentorship
Mentor Security Engineers on VAPT methodology, tooling, report quality, and engineering collaboration.
Contribute to a security-first culture through knowledge sharing and clear developer-facing guidance.
What Makes You a Great Fit
Experience: 2–5 years of hands-on experience in Product Security, Application Security (AppSec), or Offensive Security / penetration testing.
VAPT Depth: Strong practical command of OWASP Top 10 / OWASP Mobile Top 10, with an ability to find and exploit complex issues such as authZ flaws, business-logic bugs, chained vulnerabilities, and API abuse.
Web and API Security: Hands-on experience testing web platforms and APIs, including proxying traffic, analyzing client behavior, and validating server-side impact.
Source Code Review: Experience performing manual and assisted source code reviews to identify insecure patterns (e.g., injection, auth/session flaws, cryptography misuse, secrets handling).
Secure Design Reviews: Experience participating in secure design / architecture reviews—evaluating trust boundaries, authN/authZ models, data flows, and control gaps early in the SDLC and recommending practical mitigations.
Mobile or Cloud Security: Working experience in at least one of mobile application security (Android/iOS) or cloud security (preferably AWS/OCI), applied to real product assessments.
Automation & Scripting: Strong proficiency in Python (or Go/Bash) to build custom security tooling, automate assessments, and integrate with APIs and CI/CD systems.
Security Tooling: Working expertise with tools such as Burp Suite/OWASP ZAP, Nmap, MobSF, and familiarity with SAST/DAST/SCA platforms.
Life at Navi
Life at Navi is fast-paced, ambitious and deeply collaborative. Beyond work, teams come together through sports, celebrations, offsites, music jams, team outings and many more shared experiences that make the journey exciting and memorable.
We believe people do their best work when they feel supported, through flexible leave policies, strong health and wellness benefits, free financial, legal and medical consultations, ESOPs and a workplace designed for both productivity and well-being.
Whether it’s the sports turf, gym, focus zone or nap rooms, the campus is built to make everyday work more enjoyable.
If you’d like to know more about life at Navi, our culture and employee benefits, head to our careers page: navi.com/careers/life-at-navi.
If solving meaningful problems, building at scale and growing alongside ambitious teams excites you,
Navi could be the place for you.
Job Details
Experience
Mid · 2–5 yrs