B

Senior Lead Software Architect

Bajaj Finserv · Pune Division, Maharashtra, India

10–20 yrs experiencefull_timePosted 6 days ago
Apply now →

Job description

**Location Name:** Pune Corporate Office - Mantri **Job Purpose** We are looking for an experienced Application Information Security professional with deep expertise in securing mobile payment applications against advanced fraud threats. The ideal candidate should possess strong technical knowledge of mobile application security, device binding, device fingerprinting, device spoofing, emulator/root/jailbreak detection, anti-tampering techniques, and fraud prevention controls. The individual will work closely with engineering, fraud risk, architecture, and product teams to design, implement, and continuously improve security controls across digital payment applications. **Duties And Responsibilities** Key Responsibilities Mobile Application Security - Define and implement security architecture for Android and iOS applications. - Perform security design reviews for new features and products. - Conduct threat modeling and identify attack vectors in payment journeys. - Recommend security controls aligned with industry best practices. Device Binding & Device Identity - Design and govern robust device binding mechanisms. - Evaluate device fingerprinting technologies and their effectiveness. - Develop strategies for: - First-time device registration - Device change detection - Device re-binding - Multi-device handling - Trusted device lifecycle management - Improve resilience against device cloning and identity theft. Device Spoofing & Fraud Prevention **Must Have Extensive Hands-on Knowledge Of Detecting And Preventing** - Device spoofing - Device cloning - Emulator detection - Virtual environment detection - Rooted device detection - Jailbreak detection - Magisk and root hiding techniques - Hooking frameworks (Frida, Xposed, Substrate) - Dynamic instrumentation attacks - Overlay attacks - Accessibility abuse - Screen sharing and remote control fraud - App cloning - Fake GPS attacks - Certificate bypass attacks - SSL pinning bypass - Reverse engineering - Runtime tampering - Bot-based attacks Design effective controls to mitigate these threats. **Required Qualifications And Experience** Bachelor's or Master's degree in Computer Science, Information Security, or related field. - Professional certifications such as: - Certified Information Systems Security Professional (CISSP) - Certified Information Security Manager (CISM) - Offensive Security Certified Professional (OSCP) - GIAC Mobile Device Security Analyst (GMOB) - Mobile Security certifications are an added advantage. Desired Experience - 7–9 years in Application Security or Product Security. - At least 4–5 years focused on mobile application security. - Experience securing high-scale digital payment or fintech applications. - Hands-on experience designing device binding and anti-device spoofing controls. - Familiarity with modern mobile fraud trends and evolving attack techniques. - Experience working with payment ecosystems handling high transaction volumes.