Skip to content

SDE III - Security

NaviBengaluru, KA, IndiaSeptember 3, 2026
On-site
Full-time
Security Engineering
Senior · 5–10 yrs

SDE3 – Security Engineer

Location: Bangalore

About Navi

At Navi, our mission is to simplify finance for a billion people, through technology-first products built at scale.

Founded in 2018 by Sachin Bansal and Ankit Agarwal, Navi has grown rapidly across Loans, UPI, Insurance, Mutual Funds and Digital Gold – building products designed around speed, simplicity and customer experience.

Today, millions of customers use Navi for experiences like instant personal loans, fully digital home loan sanctions within minutes, low-cost mutual funds, instant credit lines in minutes and one of India’s fastest-growing UPI platforms.

What makes Navi different is the way we build. We move fast, solve real customer problems and give people the ownership to create meaningful impact early in their journey.

Why Explore a Career at Navi?

Where Ownership Creates Real Impact
At Navi, ownership starts early. People here are trusted to solve problems, make decisions and drive outcomes that directly shape the products and experiences used by millions of customers every day.

Where Careers Accelerate
Growth at Navi is driven by impact, not tenure. We strongly believe in promoting from within and creating opportunities for people to take on larger responsibilities as they grow. If you consistently raise the bar, you’ll find the space to grow quickly here.

Where Great Talent Builds Together
We take pride in building high talent-density teams where ambitious people learn from one another every day. Working on high-scale business and technology problems creates steep learning curves, fast execution cycles and opportunities to make visible impact throughout your journey.

About the Role

We are looking for an experienced SDE3 – Security Engineer to design, build, and operate scalable security solutions across Navi’s applications, cloud infrastructure, and engineering platforms.

In this role, you will work closely with software, infrastructure, and product teams to identify and mitigate security risks through secure architecture, threat modeling, automation, and security tooling. You will own technically complex security initiatives end-to-end—from design and implementation to deployment, monitoring, and continuous improvement.

The ideal candidate is a strong software engineer with deep security expertise who can build production-grade security systems, automate security controls, and proactively identify vulnerabilities across distributed applications and cloud environments.

What you'll Own

  • Security Engineering & Architecture: Design and implement scalable security controls across applications, APIs, cloud infrastructure, Kubernetes, CI/CD pipelines, and internal platforms.

  • Application & API Security: Identify and mitigate vulnerabilities across web applications, APIs, microservices, authentication systems, and distributed architectures. Apply secure coding principles and OWASP guidance throughout the software development lifecycle.

  • Threat Modeling: Conduct threat modeling for new products, services, and architectural changes using methodologies such as STRIDE and PASTA. Translate identified threats into practical engineering controls and security requirements.

  • WAF & Perimeter Security: Build, configure, and continuously improve WAF, API gateway, bot-management, rate-limiting, and other application-layer security controls. Analyze attack patterns and develop appropriate detection and mitigation mechanisms.

  • Cloud & Infrastructure Security: Implement security controls across AWS/OCI, Docker, Kubernetes, IAM/SSO, networking, secrets management, and infrastructure-as-code. Identify architectural weaknesses and drive remediation.

  • Security Automation: Build internal security tools, automation, and services using Python, Go, Bash, or similar technologies to improve vulnerability detection, security monitoring, incident response, and developer security workflows.

  • DevSecOps: Integrate security checks into CI/CD pipelines, including SAST, DAST, SCA, container security, secrets detection, IaC scanning, and policy enforcement.

  • Vulnerability Management: Develop tooling and processes to continuously identify, prioritize, and remediate vulnerabilities across applications and infrastructure. Work with engineering teams to drive vulnerabilities to closure.

  • Incident Response: Investigate security incidents, analyze attack paths and root causes, develop detection/mitigation mechanisms, and implement long-term engineering fixes to prevent recurrence.

  • Security Detection & Monitoring: Develop security detections, alerts, telemetry, and automated response mechanisms for suspicious activity across applications, infrastructure, and cloud environments.

  • AI/ML Security: Evaluate and integrate AI-powered security tools for vulnerability discovery and security automation. Design security controls and guardrails for AI/ML systems and proactively address AI-specific threats such as prompt injection, data leakage, insecure tool use, and model abuse.

  • Technical Leadership: Drive security projects independently, participate in architecture reviews, mentor engineers, conduct security design/code reviews, and influence engineering teams toward secure-by-design development practices.

What Makes You a Great Fit

  • Experience: 5–10+ years of software engineering, security engineering, application security, infrastructure security, or a closely related field.

  • Strong Software Engineering: Excellent programming skills in at least one language such as Go, Python, Java, C++, or similar, with experience building production-grade systems.

  • Security Engineering: Strong understanding of application, API, cloud, network, and infrastructure security, with hands-on experience implementing security controls.

  • Threat Modeling & Risk: Practical experience with STRIDE, PASTA, MITRE ATT&CK, attack-path analysis, security assessments, and risk-based prioritization.

  • Cloud Security: Strong understanding of AWS/OCI, IAM, networking, encryption, secrets management, logging/monitoring, and cloud-native security architectures.

  • Containers & Kubernetes: Strong understanding of Docker, Kubernetes security, container isolation, RBAC, network policies, admission controls, and runtime security.

  • Application Security: Strong knowledge of OWASP Top 10, API security, authentication/authorization, session management, cryptography fundamentals, secure coding, and common application attack techniques.

  • Security Automation: Experience building security automation, internal tools, security pipelines, or developer-facing security platforms.

  • CI/CD & DevSecOps: Experience integrating security controls into modern software development and CI/CD workflows.

  • Perimeter Security: Hands-on understanding of WAFs, API gateways, rate limiting, DDoS protection, bot mitigation, and Layer 7 attack detection.

  • Incident Response: Ability to investigate complex security incidents, perform root-cause analysis, understand attack chains, and implement engineering-level remediation.

Good to Have

  • Experience with security platforms, SIEM, EDR, CSPM, CNAPP, SAST/DAST/SCA, or similar enterprise security tooling.

  • Experience with Infrastructure as Code, particularly Terraform.

  • Experience developing custom security scanners, vulnerability detection tools, or security services.

  • Experience contributing to bug bounty, penetration testing, or vulnerability research programs.

  • Knowledge of zero-trust architectures and modern identity/security patterns.

  • Familiarity with OWASP Top 10 for LLM Applications, LLM security, prompt injection, AI agent security, and AI/ML threat modeling.

  • Experience working in fintech, banking, payments, or other highly regulated environments.

    The Navi OS

    The Navi OS is our Operating System for how we work every day. Success at Navi is defined by living these core values.

    • Start with the Customer

    • Master the Details

    • Act with Urgency

    • Own the Outcome

    • Build for a Decade - Not a Day

    • Win as One

    We hire talented individuals who already show these strengths, because those who share these values thrive at Navi and grow with the organisation.

    To read more about the Navi OS, visit navi.com/our-values

    Life at Navi

    Life at Navi is fast-paced, ambitious and deeply collaborative. Beyond work, teams come together through sports, celebrations, offsites, music jams, team outings and many more shared experiences that make the journey exciting and memorable.

    We believe people do their best work when they feel supported, through flexible leave policies, strong health and wellness benefits, free financial, legal and medical consultations, ESOPs and a workplace designed for both productivity and well-being.

    Whether it’s the sports turf, gym, focus zone or nap rooms, the campus is built to make everyday work more enjoyable.

    If you’d like to know more about life at Navi, our culture and employee benefits, head to our careers page: navi.com/careers/life-at-navi

    If solving meaningful problems, building at scale and growing alongside ambitious teams excites you,

    Navi could be the place for you.

Job Details

Experience

Senior · 5–10 yrs

Tools & Tech

AWS
Bash
C++
Docker
Go
Java
Kubernetes
Oracle Cloud
Python
Terraform