Payments Information Security Officer
39
3967 - 5367 €/mėn.
Prieš mokesčius
Job description:
We are looking for a Payments Information Security Officer (ISO) to join our growing Payments Security team in Vilnius as our fourth member. Acting as the 2nd line of defense, our team safeguards Vinted Pay’s systems, payments data, and partners in full alignment with Bank of Lithuania regulations, the Digital Operational Resilience Act (DORA), and PCI-DSS standards.
In this role, you will take ownership of Vulnerability Management and Security Tooling, lead our Resilience Testing, and partner with product and engineering teams to embed security into the design of our next-generation payment systems.
- Drive Vulnerability Management:
- Own and continuously mature the end-to-end vulnerability management lifecycle across our payment ecosystem, covering code (SAST, SCA), runtime/applications (DAST), and cloud infrastructure.
- Define and enforce clear vulnerability classification criteria and strict remediation SLAs/SLOs with engineering leads and platform teams.
- Analyze exposure, prioritize remediation based on real-world exploitability in payment environments, and manage formal risk-acceptance workflows.
- Review Product Security & Threat Modeling:
- Act as the trusted security partner for Payments Product and Engineering teams, conducting proactive architectural reviews and threat modeling on new payment flows, digital wallet features, and checkout services.
- Champion security-by-design across microservices, ensuring robust API security, strong customer authentication (SCA), tokenization, and strict cryptographic key management practices.
- Manage Security Testing & Assurance:
- Scope, coordinate, and govern third-party penetration testing engagements across payment applications and cloud environments; track remediation actions to verified closure.
- Spearhead preparations and operational execution for advanced security testing under DORA, including Threat-Led Penetration Testing (TLPT / TIBER-EU/LT) and red teaming exercises.
- Oversee and triage payments-related bug bounty reports, collaborating with ethical hackers and engineering to resolve valid disclosures swiftly.
- Boost Security Tools Efficiency & Define Logging Requirements:
- Maximize the coverage and operational efficiency of our security tooling stack (e.g., Wiz for cloud security posture and vulnerability management, SIEM, and monitoring tools).
- Define, standardize, and govern security logging, audit trail, and telemetry requirements across payment services, databases (AWS/GCP), and infrastructure to meet BoL and DORA standards.
- Optimize detection rules and alerting pipelines to cut down noise, accelerate threat detection, and provide high-fidelity security insights to the team.
- Oversee Physical Security:
- Define, maintain, and audit physical and environmental security policies, standards, and access control procedures for Vinted Pay premises, server rooms, and dedicated secure operational areas.
- Conduct periodic physical security risk assessments and badge access reviews to ensure ongoing alignment with Bank of Lithuania regulations and DORA resilience expectations.
Requirements:
- 3+ years of practical experience in information security, IT risk management, or security compliance — ideally within a FinTech, Electronic Money Institution (EMI), payment service provider (PSP), or regulated financial institution.
- Solid understanding of DORA (specifically ICT third-party risk requirements), Bank of Lithuania (BoL) guidelines, PCI-DSS (v4.0), and ISO/IEC 27001.
- Hands-on experience with AppSec/DevSecOps practices (SAST/DAST/SCA), threat modeling methodologies, and enforcing vulnerability remediation SLAs across engineering teams.
- Strong familiarity with cloud environments (AWS / GCP), threat-led testing frameworks (TLPT / TIBER), data encryption standards, and secure SDLC principles.
- Familiarity with modern cloud security platforms (especially Wiz), SIEM solutions, and AWS/GCP cloud environments
- Ability to balance rigorous security controls with practical business velocity, communicating clearly with developers, and leadership in English.
Nice to have
- Relevant industry certifications such as CISA, CISSP, CRISC, CISM, or PCIP / ISA are considered a strong plus.
Company offers:
- The opportunity to benefit from our share options programme
- 25 working days of holiday
- Access to all the tools & tech needed for work
- Home office support: we provide IT workstation equipment and a personal budget of up to €540 for home workplace furniture
- Private health insurance
- Confidential Employee Assistance Program (EAP) for you and your family
- Frequent team-building events
- A personal monthly budget for shopping on Vinted
- A dog-friendly office
- In Vilnius office: Gym & in-house meals at friendly prices
- In Kaunas office: a monthly lunch allowance, and a once-a-week provided in-house lunch and breakfast
Miestas:
Vilnius
Nuotolinis darbas:
Hibridinis
Laikas:
Visa darbo diena
Galioja iki:
01/11/2026
Kandidatavimas vyks Vinted, UAB įmonės puslapyje
Persiųsti