23 Aug
|
Finnable
|
Bengaluru
23 Aug
Finnable
Bengaluru
About Finnable
Finnable is a Bangalore-based digital lending platform focused on making personal loans accessible to India’s salaried professionals — quickly, transparently, and responsibly.
The company serves the mid-income salaried segment, especially individuals who may not always have easy access to formal credit despite being disciplined borrowers. Finnable combines digital underwriting, instant approvals, and on-ground verification/collections to create a lending model that is both tech-first and operationally controlled.
Founded by Nitin Gupta and Amit Arora , both seasoned financial services and lending professionals, Finnable has scaled with solid focus on risk, collections, customer trust, and capital discipline.
Key scale markers:
· ₹4000 Cr AUM / ₹500 Cr equity raise led by Z47 and TVS Capital
· BBB+ credit rating from CARE Ratings in its first-ever rating cycle
· GNPA of 0.85%, significantly lower than broader industry averages
· Profitable last year, with minimal equity burn to reach current scale
· 10L+ app downloads and 4.4/5 app rating
· 65% of customers are first-time personal loan borrowers
· Ambition to serve 1M+ customers over the next 4 years and expand the loan book to ₹10,000 Cr The company is now entering its next phase of growth — expanding products, deepening technology, strengthening risk and collections infrastructure, and building the organisation required to support a much larger lending platform.
Location: Bengaluru
Reports to: CISO
Role Summary
We are looking for a Security Engineer to work closely with product, engineering, DevOps, cloud, IT, and AI teams to strengthen the security of applications and technology infrastructure. The role will primarily focus on Application Security, with responsibilities across Cloud Security, AI Security, vulnerability management, DevSecOps, and Incident Response.
Key Responsibilities
· Perform security reviews of product features, APIs, web applications, backend services, and AI-enabled features.
· Conduct threat modeling for new features, architecture changes, AI/LLM integrations, and high-risk releases.
· Support application security testing including SAST, DAST, dependency scanning, secrets scanning, and manual security testing.
· Track vulnerabilities from identification through remediation, retesting, and closure.
· Review authentication, authorization, session management, input validation, API security, and data protection controls.
· Partner with engineering teams to improve secure coding practices and integrate security checks into CI/CD pipelines.
· Review cloud security configurations including IAM permissions, network controls, storage access, secrets management, encryption, and logging.
· Support identification and remediation of cloud misconfigurations and security risks across AWS/cloud environments.
· Review AI/LLM implementations for risks such as prompt injection, sensitive data exposure, insecure model/API integrations, excessive permissions, and unsafe output handling.
· Assess security and privacy risks associated with third-party AI platforms, models, plugins, APIs, and data shared with AI services.
· Support secure handling of AI prompts, training/context data, credentials, model outputs, and access controls.
· Assist in triaging and investigating application, cloud, AI, identity, and infrastructure-related security incidents.
· Support incident containment, root cause analysis,
corrective actions, and improvement of security controls.
· Review security of third-party integrations, APIs, SDKs, and product-related vendors.
· Support security documentation, metrics, audit evidence, and security awareness activities.
Required Qualifications
· 2 - 3 years of experience in application security, product security, cloud security, or security engineering.
· Strong understanding of OWASP Top 10 and common web/API vulnerabilities.
· Exposure to SAST, DAST, dependency scanning, secrets scanning, or container security tools.
· Knowledge of authentication, authorization, sessions, tokens, and secure API design.
· Experience with vulnerability management and remediation tracking.
· Understanding of SDLC, CI/CD, DevSecOps, and secure development practices.
· Familiarity with AWS security services such as IAM, CloudTrail, GuardDuty, Security Hub, WAF, or AWS Config.
· Understanding of security risks associated with AI/LLM-based applications, including prompt injection, data leakage, insecure integrations, and access-control risks.
· Understanding of security incident investigation, log analysis, and root cause analysis.
· Good analytical, communication, and stakeholder coordination skills.
Preferred Qualifications
· Experience with Burp Suite or similar application security testing tools.
· Exposure to SIEM/security monitoring and incident response tools.
· Familiarity with AI/LLM security concepts and frameworks such as OWASP Top 10 for LLM Applications.
· Exposure to security reviews of GenAI applications, AI APIs, RAG implementations, agents, or third-party AI platforms.
· Familiarity with secure code review and Infrastructure-as-Code security.
· Scripting knowledge such as Python/Bash.
· Experience in fintech, payments, NBFC, or regulated environments.
📌 Security Engineer (Bengaluru)
🏢 Finnable
📍 Bengaluru