Staff / Senior Staff Security Engineer, Vinted Pay
Job description:
As Staff / Senior Staff Security Engineer in Vinted Pay, you will be the staff-level security engineer inside our regulated payments business - and the person who makes Vinted Pay's security posture match its growth. Vinted Pay is a rare security problem in the best sense: a fintech scaling across multiple European licences at marketplace speed, where security cannot be a compliance checklist or an isolated engineering task - it has to be built into the core financial architecture. Its attack surface spans multi-region AWS infrastructure, payment pipelines and payment pages, wallets holding members' money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year.
Working at staff / senior staff level as an individual contributor embedded in the Payments Engineering leadership team, you will own the security of that whole estate. Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, SSDLC tooling, compliance), while each business unit owns local execution. Vinted Pay already owns part of its local execution; your job is to lead and scale it - this is not a policy or audit role, it is an engineering role with a mandate: translate regulatory requirements into technical guardrails and drive practical controls alongside Vinted Pay's platform and software engineers. You will work directly with Vinted Pay's Director of Engineering and functionally with the Vinted Security senior team and your security peers in Marketplace, Vinted Go, and Platform.
This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself and setting direction for the security work already under way, and as the function matures you will shape and functionally lead Vinted Pay's security engineering capability.
- Own the Vinted Pay security roadmap end to end: assess the estate, prioritise by real attack paths, and drive risks to closure - a multi-quarter roadmap that shapes how Vinted Pay defends its infrastructure and payment assets, rather than reacting to the next audit.
- Turn regulation into engineering: map PCI DSS, DORA, and Bank of Lithuania and FCA requirements into practical, automated security controls and engineering guardrails - compliance as a by-product of how Vinted Pay builds, not a parallel workstream.
- Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count.
- Own PCI DSS and data protection architecture: payment page isolation, script monitoring, data encryption, and least-privilege access across multi-region environments - and turn those controls into evidence that stands up to assessors and regulators.
- Lead cross-functional security initiatives across Payments Platform, Payments Engineering, and Group Security, and drive them to delivery - whether execution sits with partner teams or you have to write the code yourself.
- Act as the technical arm of Vinted Pay's security accountable: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, and represent Vinted Pay in the group's security governance.
- Embed secure development into Payments engineering so security lands at design time rather than after deployment, and raise the security fluency of Vinted Pay engineers so risk-based decisions happen well without you in the room - security as a delivery enabler, not a gate.
Requirements:
- Strong hands-on security engineering experience on a real engineering foundation - you have built or run large production systems, and you can threat-model a payment flow, find the attack path yourself, and drive or build the fix.
- Experience in regulated payments or fintech - you have worked under PCI DSS and a financial regulator (FCA, Bank of Lithuania, CSSF, or equivalent) and know how their requirements become controls engineers actually run.
- A staff- or principal-level track record - you have defined, led, and delivered major, company-wide technical initiatives, and you set security direction through software design on high-scale, distributed systems rather than from the outside.
- The range to move across the four archetypes of staff engineering - tech lead, architect, solver, right hand - picking the one the domain needs together with the Director of Engineering, not the one you prefer.
- A way of working that engineers respect: evidence over assertions, attack paths over checklists, guardrails over gates.
- Demonstrated ability to influence without authority and translate technical risk into business consequence for senior audiences, internal and external.
- Comfortable in our stack - Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling - or eager to learn it, with a real interest in security and privacy as a field and the appetite to keep growing as an engineer and leader.
- Excellent written and spoken English.
Nice to have
- Advantage: experience building and running systems at massive scale (2+ million requests per minute), deep knowledge of observability tooling (Kibana, Grafana, Prometheus), and a passion for introducing new practices.
- Advantage: AWS security depth (IAM, KMS, multi-account and multi-region architecture), or hands-on CSPM (e.g. Wiz) and SIEM engineering.
- Advantage: privacy engineering experience, or offensive security background or certifications (e.g. OSCP).
Company offers:
- The opportunity to benefit from our share options programme
- 25 working days of holiday
- Access to all the tools & tech needed for work
- Home office support: we provide IT workstation equipment and a personal budget of up to 540 for home workplace furniture
- Private health insurance
- Confidential Employee Assistance Program (EAP) for you and your family
- Frequent team-building events
- A personal monthly budget for shopping on Vinted
- A dog-friendly office
- In Vilnius office: Gym & in-house meals at friendly prices
- In Kaunas office: a monthly lunch allowance, and a once-a-week provided in-house lunch and breakfast