Staff / Senior Staff Security Engineer, IT
Job description:
As a Staff / Senior Staff Security Engineer you will be the first dedicated security engineer inside Vinted's IT organisation - and the person who makes the security of how Vinted works match the security of what Vinted builds. Most real-world breaches start where people meet technology: a phished identity, a compromised laptop, an over-privileged SaaS integration, a device nobody knew was on the network. Every employee, contractor and community support agent at Vinted works through what IT provides - including the thousands of agents at partner sites who act on members' accounts every day - so the attack surface you will own is the whole extended workforce.
Working at staff /senior staff level as an individual contributor embedded in IT, you will own the security of both halves of IT's estate. The hardware: the managed device fleet, peripherals, office infrastructure, and the network hardware and verification equipment IT deploys in warehouses and electronics verification centres. The software: workforce identity, the SaaS and business-application portfolio, and the integrations, automations and AI tooling that connect them.
Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, vulnerability management framework and so on), while each unit owns local execution. IT's local execution is what you will build - this is an engineering role with a mandate, not a policy or audit function. You will work day to day with IT's engineering teams and the Director of IT, and functionally with the Vinted Security team and your security peers embedded in Platform, Marketplace, Vinted Go and Vinted Pay.
This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself, and as the practice matures you will shape and functionally lead IT's security engineering capability.
- Own the IT security roadmap end to end: threat-model the workplace estate, prioritise by real attack paths and drive risks to closure, keeping IT resilience to external attack at the standard Vinted holds itself to.
- Be a pragmatic evangelist for all things security: raise the security fluency of IT engineers and the wider workforce so risk-based decisions happen well without you in the room - security as a service people want to use, not a gate.
- Make every device Vinted issues or operates trustworthy by default: hardened, managed baselines across the Mac-first fleet and its Windows and Linux edges, least privilege on endpoints, endpoint detection and response, and device trust as a condition of access - covering the full lifecycle from procurement to return.
- Secure workforce identity as the perimeter: phishing-resistant authentication, joiner-mover-leaver automation, role-based and privileged access, four-eyes controls on high-risk actions, and time-bound access for contractors and the community support agents working from partner sites - built on the group's identity standards and engineered into how IT provisions, not bolted on afterwards.
- Own the security of the SaaS and business-application estate: configuration baselines, OAuth and API integrations, data flows between systems, shadow IT and shadow AI - so that adding a tool never silently adds an attack path.
- Secure the network and hardware in Vinted's physical sites: office networks, secure remote access, and the standard IT builds for warehouses and electronics verification centres - where phones, consoles and laptops under test, verification devices and site infrastructure meet - owning the boundary with Vinted Go's security team.
- Engineer security into how IT builds: automation and security solutions that enable resilience and align with business objectives - not just improving today's posture, but continuously identifying and closing the next gap.
- Build compliance as a code: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, represent IT in Vinted security governance, and build it in a way that evidence is integral part of the process.
Requirements:
- Deep hands-on experience securing a corporate IT estate at scale - endpoints and device management, workforce identity and access, SaaS and business applications - and you can find the attack path through it yourself and drive or build the fix.
- An engineering mindset applied to IT: you automate, you script (Python, Go or similar), you manage identity and infrastructure as code, and you build controls as products for the people who use them - secure defaults over tickets and checklists.
- The ability to build a security practice from scratch inside an IT or infrastructure organisation: create clarity, pick the few things that matter, and build machinery in a low-maturity environment.
- Comfortable on both sides of the IT/OT boundary: you have secured networks and devices in physical sites - warehouses, labs, verification or repair centres - not only offices, or you are eager to.
- A way of working that engineers respect: evidence over assertions, attack paths over checklists, automation over policies.
- Demonstrated ability to influence without authority and translate technical risk into business consequence for senior audiences.
- Excellent written and spoken English.
Nice to have
- Advantage: depth in our stack - Okta, Jamf, Google Workspace, Atlassian, Workato - or their equivalents.
- Advantage: hardware and device security depth - firmware and secure boot, device attestation, peripheral and USB threats, EDR engineering.
- Advantage: offensive security background or certifications (e.g. OSCP), detection engineering on identity and endpoint telemetry, or ISO 27001 / NIS2 implementation experience in workplace scope.
Company offers:
- The opportunity to benefit from our share options programme
- 25 working days of holiday
- Access to all the tools & tech needed for work
- Home office support: we provide IT workstation equipment and a personal budget of up to 540 for home workplace furniture
- Private health insurance
- Confidential Employee Assistance Program (EAP) for you and your family
- Frequent team-building events
- A personal monthly budget for shopping on Vinted
- A dog-friendly office
- In Vilnius office: Gym & in-house meals at friendly prices
- In Kaunas office: a monthly lunch allowance, and a once-a-week provided in-house lunch and breakfast