SDE 1 Security Engineer

Navi

Bengaluru

On-site

INR 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Navi, a technology-first finance platform, is seeking a proactive Security Engineer I to defend our web, mobile, and backend APIs. You’ll write automation to streamline testing and build security tools, suitable for an early-career engineer who loves breaking things and collaborating with product teams.

You’ll work on Vulnerability Assessment and Penetration Testing (VAPT), align with OWASP Top 10, and help fix vulnerabilities while growing within Navi’s fast-paced, ownership-driven culture.

Qualifications

  • Experience in application security, penetration testing, or software engineering (0-2 years).
  • Hands-on understanding of OWASP Top 10 (Web and Mobile).
  • Ability to manually exploit common vulnerabilities (e.g., XSS, SQLi, IDOR).
  • Strong proficiency in Python or similar languages for automation.
  • Familiarity with security testing tools (Burp Suite, OWASP ZAP, MobSF).
  • Understanding of web technologies (HTTP/HTTPS, APIs) and mobile app basics.

Responsibilities

  • Conduct routine VAPT on web applications, REST/GraphQL APIs, and mobile apps.
  • Design and maintain custom scripts and automation tools to streamline testing.
  • Review security alerts, filter false positives, and validate vulnerabilities.
  • Collaborate with software engineers to communicate impact and remediation steps.
  • Maintain and tune security testing tools within deployment pipelines.
  • Draft penetration testing reports with PoCs and mitigation strategies.

Skills

Python
VAPT
OWASP Top 10
API security
Burp Suite

Tools

Burp Suite
OWASP ZAP
Postman
Nmap
MobSF

Job description

At Navi, our mission is to simplify finance for a billion people, through technology-first products built at scale.

Founded in 2018 by Sachin Bansal and Ankit Agarwal, Navi has grown rapidly across Loans, UPI, Insurance, Mutual Funds and Digital Gold - building products designed around speed, simplicity and customer experience.

Today, millions of customers use Navi for experiences like instant personal loans, fully digital home loan sanctions within minutes, low-cost mutual funds, instant credit lines in minutes and one of India’s fastest-growing UPI platforms.

What makes Navi different is the way we build. We move fast, solve real customer problems and give people the ownership to create meaningful impact early in their journey.

Why Explore a Career at Navi?
Where Ownership Creates Real Impact

At Navi, ownership starts early. People here are trusted to solve problems, make decisions and drive outcomes that directly shape the products and experiences used by millions of customers every day.

Where Careers Accelerate

Growth at Navi is driven by impact, not tenure. We strongly believe in promoting from within and creating opportunities for people to take on larger responsibilities as they grow. If you consistently raise the bar, you’ll find the space to grow quickly here.

Where Great Talent Builds Together

We take pride in building high talent-density teams where ambitious people learn from one another every day. Working on high-scale business and technology problems creates steep learning curves, fast execution cycles and opportunities to make visible impact throughout your journey.

About the Engineering Team

Navi’s Engineering team builds the backbone of our financial products. We operate as

cross-functional teams that work closely with Product, Data, and Business functions to

deliver reliable, high-performance systems at scale. Our engineers focus on solving

real-world challenges through scalable architecture, automation, and long-term

thinking, along with providing quality feedback - ensuring every Navi product is built to

serve millions efficiently and seamlessly.

About the Role

We are seeking a proactive and technically curious Security Engineer I to join our product security team. In this role, you will be on the front lines of defending our products, focusing heavily on Vulnerability Assessment and Penetration Testing (VAPT) across our web applications, mobile apps (iOS/Android), and backend APIs. Because we believe in scaling our defenses, a major component of this role involves writing automation to streamline repetitive testing and operational tasks. This is a fantastic opportunity for an early-career engineer who loves breaking things, writing code to build custom security tools, and collaborating with development teams to fix vulnerabilities.

Key Responsibilities
  • Application Penetration Testing: Conduct routine VAPT on web applications, REST/GraphQL APIs, and mobile applications (iOS and Android) to identify security flaws before they reach production.
  • Security Automation: Design, write, and maintain custom scripts and automation tools (primarily in Python, or another preferred language like Go/Bash) to streamline vulnerability scanning, log parsing, and reporting workflows.
  • Vulnerability Triage & Validation: Review alerts from automated security scanners (SAST/DAST), filter out false positives, and manually validate suspected vulnerabilities.
  • Developer Collaboration: Work directly with software engineering teams to clearly communicate the impact of identified vulnerabilities and provide actionable remediation guidance based on the OWASP Top 10.
  • Tool Maintenance: Assist in integrating, configuring, and tuning open-source and commercial security testing tools within our deployment pipelines.
  • Reporting & Documentation: Draft clear, concise penetration testing reports detailing attack vectors, proofs of concept (PoCs), and mitigation strategies.
Required Qualifications
  • Experience: 0-2 years of experience in application security, penetration testing, or software
  • engineering (including strong internships, bug bounty experience, or intensive cybersecurity programs).
  • VAPT Knowledge: Hands-on understanding of the OWASP Top 10 (Web and Mobile) and the
  • ability to manually exploit common vulnerabilities (e.g., XSS, SQLi, IDOR, improper API authorization).
  • Scripting & Automation: Strong proficiency in Python (or similar languages like Go, Ruby, or Bash).
  • You should be comfortable interacting with APIs, automating tool executions, and manipulating data via code.
  • Security Tooling: Familiarity with standard penetration testing tools such as Burp Suite, OWASPZAP, Postman, Nmap, or mobile-specific tools like MobSF.
  • Core Fundamentals: Solid understanding of how the web works (HTTP/HTTPS, TCP/IP, DNS), API architectures and basic mobile application structures (APKs/IPAs).
The Navi OS

The Navi OS is our Operating System for how we work every day. Success at Navi is defined by living these core values.

  • Start with the Customer
  • Master the Details
  • Act with Urgency
  • Own the Outcome
  • Build for a Decade - Not a Day
  • Win as One

We hire talented individuals who already show these strengths, because those who share these values thrive at Navi and grow with the organisation.

To read more about the Navi OS, visit navi.com/our-values

Life at Navi

Life at Navi is fast-paced, ambitious and deeply collaborative. Beyond work, teams come together through sports, celebrations, offsites, music jams, team outings and many more shared experiences that make the journey exciting and memorable.

We believe people do their best work when they feel supported, through flexible leave policies, strong health and wellness benefits, free financial, legal and medical consultations, ESOPs and a workplace designed for both productivity and well-being.

Whether it’s the sports turf, gym, focus zone or nap rooms, the campus is built to make everyday work more enjoyable.

If you’d like to know more about life at Navi, our culture and employee benefits, head to our careers page: navi.com/careers/life-at-navi

If solving meaningful problems, building at scale and growing alongside ambitious teams excites you,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager - Security
Engineering Manager - Security

Navi • Bengaluru Urban

On-site
INR 2,500,000 - 4,500,000
SDE I (Frontend)
SDE I (Frontend)

Navi Limited • Bengaluru

On-site
INR 600,000 - 900,000
Engineering Manager - Product Security
Engineering Manager - Product Security

Navi • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Associate Program Manager II
Associate Program Manager II

Navi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Data Science Manager
Data Science Manager

Navi • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Senior Manager - Cyber Security
Senior Manager - Cyber Security

Navi • Bengaluru

On-site
INR 3,500,000 - 8,000,000
Associate Manager - IT Application Access Management
Associate Manager - IT Application Access Management

Navi Limited • Bengaluru

On-site
INR 1,200,000 - 2,100,000
CloudOps Engineer - I
CloudOps Engineer - I

Navi • Bengaluru Urban

On-site
INR 500,000 - 800,000
SDE-II Data Platform
SDE-II Data Platform

Navi • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Manager - Admin (Building Management Systems)
Manager - Admin (Building Management Systems)

Navi • Bengaluru

On-site
INR 1,000,000 - 1,400,000