System Analyst
Bajaj Finance · Pune
- Experience7–9 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted24 Sept 2026
About Bajaj Finance
Bajaj Finance is hiring in Pune in financial services. This role looks for around 7+ years of experience.
Skills
- mobile application security
- device binding
- device fingerprinting
- device spoofing detection
- emulator detection
- root detection
- jailbreak detection
- anti-tampering
- fraud prevention controls
- threat modeling
- reverse engineering
- SSL pinning
- dynamic instrumentation
- Android
- iOS
- digital payment applications
- payment ecosystems
The role
An application security engineer at a financial services company designs mobile application security and protects digital payment applications through device binding, fraud prevention controls, and threat modeling. The role applies reverse engineering and mobile security practices to strengthen payment journeys.
Full job description
Job Purpose
We are looking for an experienced Application Information Security professional with deep expertise in
securing mobile payment applications against advanced fraud threats. The ideal candidate should possess
strong technical knowledge of mobile application security, device binding, device fingerprinting, device
spoofing, emulator/root/jailbreak detection, anti-tampering techniques, and fraud prevention controls.
The individual will work closely with engineering, fraud risk, architecture, and product teams to design,
implement, and continuously improve security controls across digital payment applications.
Duties and Responsibilities
Key Responsibilities
Mobile Application Security
Define and implement security architecture for Android and iOS applications.
Perform security design reviews for new features and products.
Conduct threat modeling and identify attack vectors in payment journeys.
Recommend security controls aligned with industry best practices.
Device Binding Device Identity
Design and govern robust device binding mechanisms.
Evaluate device fingerprinting technologies and their effectiveness.
Develop strategies for:
o First-time device registration
o Device change detection
o Device re-binding
o Multi-device handling
o Trusted device lifecycle management
Improve resilience against device cloning and identity theft.
Device Spoofing Fraud Prevention
Must have extensive hands-on knowledge of detecting and preventing:
Device spoofing
Device cloning
Emulator detection
Virtual environment detection
Rooted device detection
Jailbreak detection
Magisk and root hiding techniques
Hooking frameworks (Frida, Xposed, Substrate)
Dynamic instrumentation attacks
Overlay attacks
Accessibility abuse
Screen sharing and remote control fraud
App cloning
Fake GPS attacks
Certificate bypass attacks
SSL pinning bypass
Reverse engineering
Runtime tampering
Bot-based attacks
Design effective controls to mitigate these threats.
Required Qualifications and Experience
Preferred Qualifications
Bachelor''s or Master''s degree in Computer Science, Information Security, or related field.
Professional certifications such as:
o Certified Information Systems Security Professional (CISSP)
o Certified Information Security Manager (CISM)
o Offensive Security Certified Professional (OSCP)
o GIAC Mobile Device Security Analyst (GMOB)
o Mobile Security certifications are an added advantage.
Desired Experience
79 years in Application Security or Product Security.
At least 45 years focused on mobile application security.
Experience securing high-scale digital payment or fintech applications.
Hands-on experience designing device binding and anti-device spoofing controls.
Familiarity with modern mobile fraud trends and evolving attack techniques.
Experience working with payment ecosystems handling high transaction volumes.