Navi logo

SDE 1 – Security Engineer

Navi

Bengaluru
0–2 Years
Full-time
As Per Industry Standards
Posted 2 hrs ago
Navi Banner

Navi is hiring an SDE 1 – Security Engineer to strengthen the security of its rapidly growing financial technology platform. This position offers early-career engineers the opportunity to work on application security, penetration testing, API security, automation, and secure software development practices while collaborating closely with engineering teams. Candidates who enjoy identifying vulnerabilities, building security automation, and contributing to secure products used by millions of users will find this role highly rewarding.


Security has become one of the most critical areas in modern fintech, where protecting customer data and preventing vulnerabilities directly impact millions of financial transactions every day. This opportunity at Navi allows engineers to work on real production applications while gaining practical experience in web security, mobile application testing, API protection, and automation. Engineers joining this team will work alongside developers and product teams to build secure systems from the earliest stages of development rather than treating security as an afterthought.


🔐 What You'll Be Working On

As a Security Engineer, your primary responsibility will be identifying weaknesses before attackers do. The role combines manual penetration testing with automation, allowing engineers to continuously improve security testing processes.

You will perform vulnerability assessments across web applications, REST APIs, GraphQL services, Android applications, and iOS applications while validating security findings through manual testing.

Hands-on Application Security Role

After every security assessment, you'll collaborate directly with software developers to explain security risks, reproduce vulnerabilities, and recommend practical remediation strategies.


⚙️ Engineering Exposure

Rather than relying only on automated scanners, this role emphasizes understanding how applications actually work.

You'll regularly work with:

Python Burp Suite OWASP ZAP Postman Nmap MobSF

A major responsibility includes developing Python automation scripts that simplify repetitive security activities such as vulnerability validation, reporting, log analysis, and scanning workflows. Candidates interested in scripting and automation will gain valuable experience that extends beyond traditional penetration testing.


🌐 Security Areas You'll Explore

The engineering team focuses on identifying vulnerabilities that commonly affect modern web and mobile applications, including:

  • Cross-Site Scripting (XSS)

  • SQL Injection (SQLi)

  • Insecure Direct Object References (IDOR)

  • Broken Authentication

  • Improper Authorization

  • API Security Issues

  • Mobile Application Vulnerabilities

  • Sensitive Data Exposure

  • Security Misconfigurations

Understanding why a vulnerability exists is just as valuable as knowing how to exploit it.

The role also involves validating findings from automated SAST and DAST tools to eliminate false positives before reporting issues to development teams.


🤝 Working With Product Teams

Security engineers at Navi work closely with software developers throughout the development lifecycle instead of operating independently.

You'll explain security findings using clear proof-of-concept demonstrations, help developers understand business impact, recommend secure coding practices, and verify fixes before production deployment. This collaborative approach ensures security becomes an integral part of product development.


📈 Skills That Will Help You Succeed

Candidates are expected to have practical understanding of modern web technologies along with strong programming fundamentals.

Helpful technical knowledge includes:

Required Skills

Additional Advantage

Python Programming

Go or Bash Scripting

HTTP & HTTPS

GraphQL Security

TCP/IP Fundamentals

Mobile Reverse Engineering

DNS Concepts

Cloud Security Basics

REST APIs

CI/CD Security

OWASP Top 10

Secure SDLC

Knowledge gained through internships, cybersecurity competitions, Capture The Flag (CTF) events, or bug bounty programs will also be valuable for this position.


🚀 Why This Position Stands Out

Unlike many entry-level security positions that primarily involve monitoring dashboards, this opportunity combines offensive security, automation, software engineering, and developer collaboration.

Engineers will gain production-level exposure to secure fintech applications operating at large scale while learning how security integrates into continuous development environments.

On-site Entry Level


🧠 Interview Preparation Tips

Applicants should revise the following topics before interviews:

  • OWASP Top 10 (Web & Mobile)

  • HTTP Request Lifecycle

  • Authentication vs Authorization

  • Session Management

  • SQL Injection Techniques

  • Cross-Site Scripting

  • API Security

  • Python Scripting

  • REST API Testing

  • Burp Suite Practical Usage

  • Network Fundamentals

  • Basic Mobile Application Architecture

Being able to demonstrate previous security projects, bug bounty reports, automation scripts, or penetration testing labs can significantly strengthen your profile.


📝 Keywords for Resume

Python • Application Security • Penetration Testing • Vulnerability Assessment • VAPT • OWASP Top 10 • Burp Suite • OWASP ZAP • REST APIs • GraphQL • API Security • SQL Injection • Cross-Site Scripting • IDOR • Mobile Security • Android Security • iOS Security • MobSF • Nmap • Postman • SAST • DAST • TCP/IP • DNS • HTTP • Secure Coding • Git • Automation • Cybersecurity


💡 Final Perspective

For candidates looking to begin a career in cybersecurity within the fintech industry, this position offers meaningful exposure to real-world application security challenges. The combination of penetration testing, security automation, developer collaboration, and large-scale production systems makes it a strong opportunity for engineers who want to build long-term expertise in product security.


The above article is written by me, a person interested in technology, automobiles, modern gadgets, movies, music, and clean aesthetics.

Top companies

Disclaimer

This job listing is shared for informational purposes only. We are not affiliated with the hiring company. All applications must be submitted through the official company website.

Recent Postings

JJOBS