Search by job, company or skills

Security Engineer

Early Applicant
  • Posted 2 days ago
  • Be among the first 10 applicants

Job Description

About Finnable

Finnable is a Bangalore-based digital lending platform focused on making personal loans accessible to India's salaried professionals — quickly, transparently, and responsibly.

The company serves the mid-income salaried segment, especially individuals who may not always have easy access to formal credit despite being disciplined borrowers. Finnable combines digital underwriting, instant approvals, and on-ground verification/collections to create a lending model that is both tech-first and operationally controlled.

Founded by Nitin Gupta and Amit Arora, both seasoned financial services and lending professionals, Finnable has scaled with strong focus on risk, collections, customer trust, and capital discipline.

Key scale markers:

  • 4000 Cr AUM / 500 Cr equity raise led by Z47 and TVS Capital
  • BBB+ credit rating from CARE Ratings in its first-ever rating cycle
  • GNPA of 0.85%, significantly lower than broader industry averages
  • Profitable last year, with minimal equity burn to reach current scale
  • 10L+ app downloads and 4.4/5 app rating
  • 65% of customers are first-time personal loan borrowers
  • Ambition to serve 1M+ customers over the next 4 years and expand the loan book to 10,000 Cr

The company is now entering its next phase of growth — expanding products, deepening technology, strengthening risk and collections infrastructure, and building the organisation required to support a much larger lending platform

Job role: Security Engineer

Location: Bengaluru

Reports to: CISO

Role Summary

We are looking for a Security Engineer to work closely with product, engineering, DevOps, cloud, IT, and AI teams to strengthen the security of applications and technology infrastructure. The role will primarily focus on Application Security, with responsibilities across Cloud Security, AI Security, vulnerability management, DevSecOps, and Incident Response.

Key Responsibilities

  • Perform security reviews of product features, APIs, web applications, backend services, and AI-enabled features
  • Conduct threat modeling for new features, architecture changes, AI/LLM integrations, and high-risk releases
  • Support application security testing including SAST, DAST, dependency scanning, secrets scanning, and manual security testing
  • Track vulnerabilities from identification through remediation, retesting, and closure
  • Review authentication, authorization, session management, input validation, API security, and data protection controls
  • Partner with engineering teams to improve secure coding practices and integrate security checks into CI/CD pipelines
  • Review cloud security configurations including IAM permissions, network controls, storage access, secrets management, encryption, and logging
  • Support identification and remediation of cloud misconfigurations and security risks across AWS/cloud environments
  • Review AI/LLM implementations for risks such as prompt injection, sensitive data exposure, insecure model/API integrations, excessive permissions, and unsafe output handling
  • Assess security and privacy risks associated with third-party AI platforms, models, plugins, APIs, and data shared with AI services
  • Support secure handling of AI prompts, training/context data, credentials, model outputs, and access controls
  • Assist in triaging and investigating application, cloud, AI, identity, and infrastructure-related security incidents
  • Support incident containment, root cause analysis, corrective actions, and improvement of security controls
  • Review security of third-party integrations, APIs, SDKs, and product-related vendors
  • Support security documentation, metrics, audit evidence, and security awareness activities

Required Qualifications

  • 2 - 3 years of experience in application security, product security, cloud security, or security engineering
  • Strong understanding of OWASP Top 10 and common web/API vulnerabilities
  • Exposure to SAST, DAST, dependency scanning, secrets scanning, or container security tools
  • Knowledge of authentication, authorization, sessions, tokens, and secure API design
  • Experience with vulnerability management and remediation tracking
  • Understanding of SDLC, CI/CD, DevSecOps, and secure development practices
  • Familiarity with AWS security services such as IAM, CloudTrail, GuardDuty, Security Hub, WAF, or AWS Config
  • Understanding of security risks associated with AI/LLM-based applications, including prompt injection data leakage, insecure integrations, and access-control risks
  • Understanding of security incident investigation, log analysis, and root cause analysis
  • Good analytical, communication, and stakeholder coordination skills

Preferred Qualifications

  • Experience with Burp Suite or similar application security testing tools
  • Exposure to SIEM/security monitoring and incident response tools
  • Familiarity with AI/LLM security concepts and frameworks such as OWASP Top 10 for LLM Applications
  • Exposure to security reviews of GenAI applications, AI APIs, RAG implementations, agents, or third-party AI platforms
  • Familiarity with secure code review and Infrastructure-as-Code security
  • Scripting knowledge such as Python/Bash
  • Experience in fintech, payments, NBFC, or regulated environments

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153433493

Similar Jobs

Bengaluru, India

Skills:

Cloud securityIncident ResponseSecurity ArchitectureSIEM and vulnerability toolsRisk managementOWASP and secure engineering practices

Bengaluru, India

Skills:

DASTIso 27001GcpDockerIamSiemOwasp Top 10KubernetesAWSZero Trust architectureNIST CSFSOARSOC2SCASAST

Bengaluru, India

Skills:

Splunk Grafana Nagios Zabbix ThousandEyesLinux Unix Windows AdministrationBCP High Availability ResiliencyChange Incident Problem Major Incident Management ServiceNowShell Python Scripting AutomationStrong Troubleshooting Analytical Problem-Solving SkillsServiceNow Jira ConfluenceProduction Support Rotational On-Call SupportKPI KRI Monitoring Operational ExcellenceSQL MySQL PostgreSQL Oracle KnowledgeCloud Fundamentals Azure AWS GCPVulnerability Remediation Patch ManagementAgile Scrum ITIL Practices

Bengaluru, India

Skills:

reporting metrics policy development NetworkingIpsIncident ResponseIamFirewallsIdsSiemCismSecurity Assessmentsinformation protectionSOARVendor ManagementSecurity ImplementationIdentity Management SystemsRisk ManagementissapSystem Design IntegrationVulnerability ScansCisspOt SecurityTraining Awareness

Bengaluru, India

Skills:

threat modeling Azure CloudApplication SecurityVulnerability AssessmentsOwasp Top 10Penetration TestingSdlcAWSpublic cloud infrastructuresoftware risk managementsecurity policies and procedures

Beware of Scammers

We don’t charge money for job offers