Live opening · Posted 6 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Navi
At Navi, our mission is to simplify finance for a billion people, through technology-first products built at scale.
Founded in 2018 by Sachin Bansal and Ankit Agarwal, Navi has grown rapidly across Loans, UPI, Insurance, Mutual Funds and Digital Gold – building products designed around speed, simplicity and customer experience.
Today, millions of customers use Navi for experiences like instant personal loans, fully digital home loan sanctions within minutes, low-cost mutual funds, instant credit lines in minutes and one of India’s fastest-growing UPI platforms.
What makes Navi different is the way we build. We move fast, solve real customer problems and give people the ownership to create meaningful impact early in their journey.
Why Explore a Career at Navi?
Where Ownership Creates Real Impact
At Navi, ownership starts early. People here are trusted to solve problems, make decisions and drive outcomes that directly shape the products and experiences used by millions of customers every day.
Where Careers Accelerate
Growth at Navi is driven by impact, not tenure. We strongly believe in promoting from within and creating opportunities for people to take on larger responsibilities as they grow. If you consistently raise the bar, you’ll find the space to grow quickly here.
Where Great Talent Builds Together
We take pride in building high talent-density teams where ambitious people learn from one another every day. Working on high-scale business and technology problems creates steep learning curves, fast execution cycles and opportunities to make visible impact throughout your journey.
About the Role
We are seeking a highly skilled Mobile Security Engineer to defend Navi’s digital-first financial
applications against sophisticated client-side threats. In this hands-on, specialized role, you will focusdeeply on our Android and iOS ecosystems. You will act as both the ultimate adversary and protector utilizing advanced reverse engineering to break our mobile apps, evaluating and hardening Runtime Application Self-Protection (RASP) mechanisms, and neutralizing client-side exploits before they Impact our users. The ideal candidate possesses a deep understanding of mobile OS internals, thrives on tearing down compiled binaries, and is passionate about building impenetrable defenses for apps handling sensitive financial data.
What You’ll Own
Deep-Dive Reverse Engineering:
Conduct advanced static and dynamic analysis, reverse engineering, and penetration testing on Navi’s Android and iOS applications.
RASP Implementation & Evasion Testing:
Evaluate, deploy, and fine-tune Runtime Application Self-Protection (RASP).
Actively attempt to bypass anti-tampering, anti-debugging, root/jailbreak detection, and hooking defenses.
Client-Side Exploit Research & Mitigation:
Investigate and develop mitigations for advanced client-side threats, including overlay attacks, memory hooking, deep link abuse.
Monitor the mobile threat landscape to proactively defend against zero-day vulnerabilities targeting mobile banking and UPI applications.
Secure Mobile Architecture & Threat Modeling:
Collaborate closely with mobile engineering (Android/iOS) teams to design secure architectures from the ground up.
Lead threat modeling exercises for mobile features and SDKs, ensuring alignment with the OWASP Mobile Application Security Verification Standard (MASVS).
DevSecOps & Automation:
Build custom scripts and tools to automate mobile security scanning (SAST/DAST) directly into the mobile CI/CD pipelines.
Triage mobile-specific Security findings, reproduce complex exploits, and provide actionable remediation guidance to developers.
What Makes You a Great Fit
Experience: 4-8 years of dedicated experience in Application Security, explicitly focused on Mobile Security, Reverse Engineering, and Penetration Testing.
Reverse Engineering Mastery: Expert-level proficiency with mobile dynamic instrumentation and reverse engineering frameworks (e.g., Frida, Objection, Ghidra, IDA Pro, Hopper, Radare2, Magisk).
Client-Side & RASP Expertise: Deep understanding of mobile OS internals (Android/iOS), keychain/keystore security, memory management, and practical experience bypassing or configuring RASP and obfuscation tools.
Code Fluency: Strong ability to read, analyze, and review code in Java, Kotlin, Swift, Objective-C, and C/C++.
Automation & Scripting: Proficiency in Python or Bash to write custom exploit scripts, automate dynamic testing, or build security tooling.
Security Frameworks: Thorough knowledge of the OWASP Mobile Top 10 and OWASP MASVS.
The Navi OS
The Navi OS is our Operating System for how we work every day. Success at Navi is defined by living these core values.
Start with the Customer
Master the Details
Act with Urgency
Own the Outcome
Build for a Decade - Not a Day
Win as One
We hire talented individuals who already show these strengths, because those who share these values thrive at Navi and grow with the organisation.
To read more about the Navi OS, visit navi.com/our-values
Life at Navi
Life at Navi is fast-paced, ambitious and deeply collaborative. Beyond work, teams come together through sports, celebrations, offsites, music jams, team outings and many more shared experiences that make the journey exciting and memorable.
We believe people do their best work when they feel supported, through flexible leave policies, strong health and wellness benefits, free financial, legal and medical consultations, ESOPs and a workplace designed for both productivity and well-being.
Whether it’s the sports turf, gym, focus zone or nap rooms, the campus is built to make everyday work more enjoyable.
If you’d like to know more about life at Navi, our culture and employee benefits, head to our careers page: navi.com/careers/life-at-navi
If solving meaningful problems, building at scale and growing alongside ambitious teams excites you,
Navi could be the place for you.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.