System Analyst

Bajaj Finance · Pune

  • Experience7–9 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted24 Sept 2026

About Bajaj Finance

Bajaj Finance is hiring in Pune in financial services. This role looks for around 7+ years of experience.

Skills

  • mobile application security
  • device binding
  • device fingerprinting
  • device spoofing detection
  • emulator detection
  • root detection
  • jailbreak detection
  • anti-tampering
  • fraud prevention controls
  • threat modeling
  • reverse engineering
  • SSL pinning
  • dynamic instrumentation
  • Android
  • iOS
  • digital payment applications
  • payment ecosystems

The role

An application security engineer at a financial services company designs mobile application security and protects digital payment applications through device binding, fraud prevention controls, and threat modeling. The role applies reverse engineering and mobile security practices to strengthen payment journeys.

Full job description

Job Purpose

We are looking for an experienced Application Information Security professional with deep expertise in

securing mobile payment applications against advanced fraud threats. The ideal candidate should possess

strong technical knowledge of mobile application security, device binding, device fingerprinting, device

spoofing, emulator/root/jailbreak detection, anti-tampering techniques, and fraud prevention controls.

The individual will work closely with engineering, fraud risk, architecture, and product teams to design,

implement, and continuously improve security controls across digital payment applications.

Duties and Responsibilities

Key Responsibilities

Mobile Application Security

Define and implement security architecture for Android and iOS applications.

Perform security design reviews for new features and products.

Conduct threat modeling and identify attack vectors in payment journeys.

Recommend security controls aligned with industry best practices.

Device Binding Device Identity

Design and govern robust device binding mechanisms.

Evaluate device fingerprinting technologies and their effectiveness.

Develop strategies for:

o First-time device registration

o Device change detection

o Device re-binding

o Multi-device handling

o Trusted device lifecycle management

Improve resilience against device cloning and identity theft.

Device Spoofing Fraud Prevention

Must have extensive hands-on knowledge of detecting and preventing:

Device spoofing

Device cloning

Emulator detection

Virtual environment detection

Rooted device detection

Jailbreak detection

Magisk and root hiding techniques

Hooking frameworks (Frida, Xposed, Substrate)

Dynamic instrumentation attacks

Overlay attacks

Accessibility abuse

Screen sharing and remote control fraud

App cloning

Fake GPS attacks

Certificate bypass attacks

SSL pinning bypass

Reverse engineering

Runtime tampering

Bot-based attacks

Design effective controls to mitigate these threats.

Required Qualifications and Experience

Preferred Qualifications

Bachelor''s or Master''s degree in Computer Science, Information Security, or related field.

Professional certifications such as:

o Certified Information Systems Security Professional (CISSP)

o Certified Information Security Manager (CISM)

o Offensive Security Certified Professional (OSCP)

o GIAC Mobile Device Security Analyst (GMOB)

o Mobile Security certifications are an added advantage.

Desired Experience

79 years in Application Security or Product Security.

At least 45 years focused on mobile application security.

Experience securing high-scale digital payment or fintech applications.

Hands-on experience designing device binding and anti-device spoofing controls.

Familiarity with modern mobile fraud trends and evolving attack techniques.

Experience working with payment ecosystems handling high transaction volumes.