About the Role
We are seeking a highly skilled Mobile Security Engineer to defend Navi’s digital-first financial
applications against sophisticated client-side threats. In this hands-on, specialized role, you will focus
deeply on our Android and iOS ecosystems. You will act as both the ultimate adversary and protector
- utilizing advanced reverse engineering to break our mobile apps, evaluating and hardening Runtime
Application Self-Protection (RASP) mechanisms, and neutralizing client-side exploits before they
impact our users.
The ideal candidate possesses a deep understanding of mobile OS internals, thrives on tearing down
compiled binaries, and is passionate about building impenetrable defenses for apps handling
sensitive financial data.
What you'll own
Deep-Dive Reverse Engineering:
- Conduct advanced static and dynamic analysis, reverse engineering, and penetration
testing on Navi’s Android and iOS applications.
- RASP Implementation & Evasion Testing:
- Evaluate, deploy, and fine-tune Runtime Application Self-Protection (RASP).
- Actively attempt to bypass anti-tampering, anti-debugging, root/jailbreak detection,
and hooking defenses.
- Client-Side Exploit Research & Mitigation:
- Investigate and develop mitigations for advanced client-side threats, including
overlay attacks, memory hooking, deep link abuse.
- Monitor the mobile threat landscape to proactively defend against zero-day
vulnerabilities targeting mobile banking and UPI applications.
- Secure Mobile Architecture & Threat Modeling:
- Collaborate closely with mobile engineering (Android/iOS) teams to design secure
architectures from the ground up.
- Lead threat modeling exercises for mobile features and SDKs, ensuring alignment
with the OWASP Mobile Application Security Verification Standard (MASVS).
- DevSecOps & Automation:
- Build custom scripts and tools to automate mobile security scanning (SAST/DAST)
directly into the mobile CI/CD pipelines.
- Triage mobile-specific Security findings, reproduce complex exploits, and provide
actionable remediation guidance to developers.
What Makes You a Great Fit
- Experience: 1-5 years of dedicated experience in Application Security, explicitly focused on
Mobile Security, Reverse Engineering, and Penetration Testing.
- Reverse Engineering Mastery: Expert-level proficiency with mobile agile instrumentation
and reverse engineering frameworks (e.g., Frida, Objection, Ghidra, IDA Pro, Hopper, Radare2,
Magisk).
- Client-Side & RASP Expertise: Deep understanding of mobile OS internals (Android/iOS),
keychain/keystore security, memory management, and practical experience bypassing or
configuring RASP and obfuscation tools.
- Code Fluency: Strong ability to read, analyze, and review code in Java, Kotlin, Swift,
Objective-C, and C/C++.
- Automation & Scripting: Proficiency in Python or Bash to write custom exploit scripts,
automate dynamic testing, or build security tooling.
- Security Frameworks: Thorough knowledge of the OWASP Mobile Top 10 and OWASP
MASVS.
📌 SDE III - Mobile Security (India)
🏢 Navi
📍 India