Search by job, company or skills

Engineering Manager - Security

  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Engineering Manager - Security

Build products and experiences that simplify finance for a billion people.

Location: Bangalore

About Navi

At Navi, our mission is to simplify finance for a billion people, through technology-first products built at scale.

Founded in 2018 by Sachin Bansal and Ankit Agarwal, Navi has grown rapidly across Loans, UPI, Insurance, Mutual Funds and Digital Gold – building products designed around speed, simplicity and customer experience.

Today, millions of customers use Navi for experiences like instant personal loans, fully digital home loan sanctions within minutes, low-cost mutual funds, instant credit lines in minutes and one of India's fastest-growing UPI platforms.

What makes Navi different is the way we build. We move fast, solve real customer problems and give people the ownership to create meaningful impact early in their journey.

Why Explore a Career at Navi

Where Ownership Creates Real Impact

At Navi, ownership starts early. People here are trusted to solve problems, make decisions and drive outcomes that directly shape the products and experiences used by millions of customers every day.

Where Careers Accelerate

Growth at Navi is driven by impact, not tenure. We strongly believe in promoting from within and creating opportunities for people to take on larger responsibilities as they grow. If you consistently raise the bar, you'll find the space to grow quickly here.

Where Great Talent Builds Together

We take pride in building high talent-density teams where ambitious people learn from one another every day. Working on high-scale business and technology problems creates steep learning curves, fast execution cycles and opportunities to make visible impact throughout your journey.

About the Team

Navi's Engineering team builds the backbone of our financial products—spanning lending, payments, insurance, investments, and debt management. We operate as cross-functional teams that work closely with Product, Data, and Business functions to deliver reliable, high-performance systems at scale. Our engineers focus on solving real-world challenges through scalable architecture, automation, and long-term thinking—ensuring every Navi product is built to serve millions efficiently and seamlessly.

About the Role

The Product Security team at Navi partners closely with engineering to embed security into every phase of development. From secure design reviews and threat modeling to rigorous web, mobile & cloud security, we focus on preventing issues before they reach production. Our collaboration with DevOps and adoption of automated tools strengthens our cloud and code security posture. Through initiatives like Security Week and industry engagement, we champion a culture of security awareness across teams. With a focus on continuous improvement, we aim to make security scalable, proactive, and developer-friendly.

What You'll Own

1. Product Security Architecture & Threat Modelling

  • Architect and enforce robust, defensive security controls across our web applications, mobile applications, and cloud-native infrastructure (AWS/OCI).
  • Lead comprehensive threat modelling exercises (e.g., STRIDE) during early product design phases to identify flaws before a single line of code is written.
  • Embed secure coding practices and DevSecOps automated guardrails directly into the CI/CD pipelines.

2. People & Stakeholder Management:

  • Direct day-to-day operations for the security engineering team, providing technical mentorship, conducting performance reviews, and fostering a culture of proactive defense.
  • Liaison with peers and stakeholders to keep everyone updated on progress and drive strategic goals for Navi

3. Full-Spectrum Vulnerability Management (VA/PT)

  • Own the end-to-end Vulnerability Assessment (VA) and Penetration Testing (PT) programs across all production systems, APIs, microservices, and mobile endpoints.
  • Manage Navi's public/private Bug Bounty programs, triaging high-severity vulnerabilities and collaborating with engineering teams for rapid remediation.

4. Offensive Security & Red Teaming

  • Design and execute targeted Red Teaming simulations to test Navi's detection and response capabilities against real-world adversarial tactics.
  • Conduct deep-dive penetration testing and reverse engineering on our Android and iOS applications to prevent client-side tampering, data leakage, and API abuse.

5. Audit Readiness & Technical Compliance

  • Act as the core technical liaison for external security audits, ensuring product architectures align with RBI guidelines, SEBI regulations, PCI-DSS, and ISO 27001.
  • Conduct continuous internal security audits and posture assessments to maintain a perpetual state of compliance across all financial product lines (Loans, UPI, Mutual Funds).

6. AI-Driven Security & Guardrails

  • Build and integrate AI-powered security tooling to accelerate vulnerability detection.
  • Design and implement stringent security guardrails for Navi's in-house AI/ML models, proactively mitigating LLM-specific vulnerabilities (e.g., prompt injection, data poisoning).
  • What Makes You a Great Fit

    • Spanning over 8 years in comparable positions, with a minimum of 2 years in people management and strategic leadership roles.
    • Establishes robust relationships with both direct reports and colleagues across the organization. Fosters talent within the team and elevates technical standards during recruitment.
    • Identifies impactful and pragmatic security solutions, from immediate wins to long-term investments.
    • Proficient in setting and communicating priorities for themselves and the team, ensuring efficient execution.
    • Mobile & Web Mastery: Deep knowledge of Web and Mobile (Android/iOS) security concepts, runtime protection, reverse engineering, and the OWASP Top 10 / OWASP Mobile Top 10 frameworks.
    • Offensive Skillset: Proven track record of conducting comprehensive Vulnerability Assessments (VA) and executing Red Teaming scenarios utilizing industry-standard frameworks (e.g., MITRE ATT&CK).
    • Cloud & Infrastructure Proficiency: Advanced knowledge of securing cloud architectures (AWS/OCI), container security (Docker, Kubernetes), IAM, and Zero-Trust networking principles.
    • Automation & Scripting: Strong proficiency in languages like Python, Go, or Bash to build custom security tooling, exploit scripts, and automate vulnerability scanning.
    • Compliance Audit Exposure (Good to Have): Hands-on experience preparing product architectures and technical evidence for strict regulatory and compliance audits (RBI, PCI-DSS, SOC2).
    • Emerging Tech: Familiarity with modern AI security risks (e.g., OWASP Top 10 for LLMs)

    The Navi OS

    The Navi OS is our Operating System for how we work every day. Success at Navi is defined by living these core values.

    Start with the customer

    Master the details

    Act with urgency

    Own the outcome

    Build for a decade, not a day

    Win as one

    We hire talented individuals who already show these strengths, because those who share these values thrive at Navi and grow with the organisation.

    To read more about the Navi OS, visit navi.com/our-values.

    Life at Navi

    Life at Navi is fast-paced, ambitious and deeply collaborative. Beyond work, teams come together through sports, celebrations, offsites, music jams, team outings and many more shared experiences that make the journey exciting and memorable.

    We believe people do their best work when they feel supported, through flexible leave policies, strong health and wellness benefits, free financial, legal and medical consultations, ESOPs and a workplace designed for both productivity and well-being.

    Whether it's the sports turf, gym, focus zone or nap rooms, the campus is built to make everyday work more enjoyable.

    If you'd like to know more about life at Navi, our culture and employee benefits, head to our careers page: navi.com/careers/life-at-navi.

    If solving meaningful problems, building at scale and

    growing alongside ambitious teams excites you,

    Navi could be the place for you.

    More Info

    Job Type:
    Industry:
    Employment Type:

    About Company

    Job ID: 151741067

    Similar Jobs

    Bengaluru, India

    Skills:

    Incident ResponseAPI securityApplication SecurityVulnerability ManagementData ProtectionSiemautomationcloud infrastructure securitysecure architecture reviewSOARendpoint controls

    Bengaluru, India

    Skills:

    Iso 27001Distributed SystemsPythonAWSJavacloud securityGcpSystem DesignIamAzureendpoint vulnerability managementAPI-driven integrationsGothird-party security solutionsmodern security principlesarchitecturecloud-native architecturesNIST 800-53DevSecOps practicessecurity frameworkszero trustinfrastructure-as-codesecurity platformsCI CD pipelinesdefense-in-depthidentity-first security

    Bengaluru

    Skills:

    Machine LearningNetwork SecuritySocHipaaPythonOltp