SDE I - Security

Navi Limited

Bengaluru

On-site

INR 600,000 - 1,000,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Navi Limited in Bengaluru seeks a proactive Security Engineer I to join the product security team. You will defend our products, focusing on vulnerability assessment and pentesting across web, mobile, and backend APIs, while building automation to scale testing tasks.

Early-career engineers who enjoy breaking things and writing code to build security tools will thrive, collaborating with development teams to fix vulnerabilities and strengthen defenses.

Qualifications

  • 02 years of experience in application security, penetration testing, or related roles.
  • Hands-on knowledge of OWASP Top 10 Web and Mobile threats and exploitation basics.
  • Strong scripting ability in Python or equivalent to automate tasks.

Responsibilities

  • Conduct routine VAPT on web applications, REST/GraphQL APIs, and mobile apps to identify security flaws.
  • Design, write and maintain custom automation tools to streamline vulnerability scanning and reporting.
  • Review security alerts, filter false positives, and manually validate vulnerabilities.
  • Collaborate with software engineering teams to communicate impacts and remediation guidance based on OWASP Top 10.
  • Maintain and tune security testing tools within deployment pipelines.

Skills

OWASP Top 10
Python scripting
Penetration testing
Automation tooling
REST/GraphQL APIs
Mobile security

Tools

Burp Suite
OWASP ZAP
Postman
Nmap
MobSF

Job description


Position Summary

We are seeking a proactive and technically curious Security Engineer I to join our product security team. In

this role, you will be on the front lines of defending our products, focusing heavily on Vulnerability

Assessment and Penetration Testing (VAPT) across our web applications, mobile apps (iOS/Android), andbackend APIs. Because we believe in scaling our defenses, a major component of this role involves writing automation to streamline repetitive testing and operational tasks. This is a fantastic opportunity for an early-career engineer who loves breaking things, writing code to build custom security tools, and

collaborating with development teams to fix vulnerabilities.


Key Responsibilities
  • Application Penetration Testing: Conduct routine VAPT on web applications, REST/GraphQL APIs, and mobile applications (iOS and Android) to identify security flaws before they reach production.
  • Security Automation: Design, write, and maintain custom scripts and automation tools (primarily in Python, or another preferred language like Go/Bash) to streamline vulnerability scanning, log parsing, and reporting workflows.
  • Vulnerability Triage & Validation: Review alerts from automated security scanners (SAST/DAST),filter out false positives, and manually validate suspected vulnerabilities.
  • Developer Collaboration: Work directly with software engineering teams to clearly communicate
  • the impact of identified vulnerabilities and provide actionable remediation guidance based on the OWASP Top 10.
  • Tool Maintenance: Assist in integrating, configuring, and tuning open-source and commercial security testing tools within our deployment pipelines.
  • Reporting & Documentation: Draft clear, concise penetration testing reports detailing attack vectors, proofs of concept (PoCs), and mitigation strategies.

Required Qualifications
  • Experience: 02 years of experience in application security, penetration testing, or software engineering (including strong internships, bug bounty experience, or intensive cybersecurity programs).
  • VAPT Knowledge: Hands-on understanding of the OWASP Top 10 (Web and Mobile) and the ability to manually exploit common vulnerabilities (e.g., XSS, SQLi, IDOR, improper API authorization).
  • Scripting & Automation: Strong proficiency in Python (or similar languages like Go, Ruby, or Bash).
  • You should be comfortable interacting with APIs, automating tool executions, and manipulating data via code.
  • Security Tooling: Familiarity with standard penetration testing tools such as Burp Suite, OWASP
  • ZAP, Postman, Nmap, or mobile-specific tools like MobSF.
  • Core Fundamentals: Solid understanding of how the web works (HTTP/HTTPS, TCP/IP, DNS), API architectures and basic mobile application structures (APKs/IPAs).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Security Engineer-2
Security Engineer-2

Cashfree Payments India Private Limited • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

On-site
INR 900,000 - 1,500,000
Senior Security Engineer
Senior Security Engineer

HappyFox Inc. • Chennai

On-site
INR 600,000 - 1,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
DevSecOps Engineer (SAST/DAST)
DevSecOps Engineer (SAST/DAST)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Vulnerability Assessment & Penetration Testing (VAPT) Engineer
Vulnerability Assessment & Penetration Testing (VAPT) Engineer

Zensar • Pune District

On-site
INR 1,200,000 - 2,800,000
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000