Nawy Real Estate operates Africa's largest prop-tech platform, running a transaction-heavy ecosystem across Egypt and the broader MENA region. Founded in 2016, the company has scaled to between 1,001 and 5,000 employees, secured over $57M in funding, and built a product surface that now touches over 100,000 families. The core platform lists 15,000+ properties across 800+ compounds, handling everything from discovery to investment and property management. That's a lot of sensitive user data - financials, identity documents, transaction records - flowing through interconnected systems that also serve brokers, investors, and buyers.
The product stack itself maps out a meaningful attack surface: Nawy Shares handles fractional real estate investment from as little as 5%, requiring secure financial workflows; Nawy Now manages flexible payment plans stretching up to seven years; Nawy Partners exposes broker-facing tooling and APIs. Nawy Unlocked adds property management into the mix. Each of these modules carries its own threat model - from payment fraud and account takeover to API abuse and data exfiltration across a multi-sided marketplace.
The technical domains lean into data-driven platform integration rather than hardware or embedded systems, which means the security work likely centers on application security, infrastructure hardening, cloud posture management, and identity and access controls across a complex, fast-moving codebase. Scaling a prop-tech operation of this size in the MENA region also means navigating region-specific regulatory requirements around data residency and financial compliance - context that shapes how security teams prioritize and operate day to day.





