发布于 2026年9月22日 · 我们于 2026年9月22日 确认该职位仍然有效
这是您的公司吗?Brief info about Vinted
Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third. The Vinted Group is made up of three business units that support this mission: Vinted Marketplace is Europe’s leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life. Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces. Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members. Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people.
Information about the position
As Staff / Senior Staff Security Engineer in Vinted Pay, you will be the staff-level security engineer inside our regulated payments business - and the person who makes Vinted Pay's security posture match its growth. Vinted Pay is a rare security problem in the best sense: a fintech scaling across multiple European licences at marketplace speed, where security cannot be a compliance checklist or an isolated engineering task - it has to be built into the core financial architecture. Its attack surface spans multi-region AWS infrastructure, payment pipelines and payment pages, wallets holding members' money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year. Working at staff / senior staff level as an individual contributor embedded in the Payments Engineering leadership team, you will own the security of that whole estate. Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, SSDLC tooling, compliance), while each business unit owns local execution. Vinted Pay already owns part of its local execution; your job is to lead and scale it - this is not a policy or audit role, it is an engineering role with a mandate: translate regulatory requirements into technical guardrails and drive practical controls alongside Vinted Pay's platform and software engineers. You will work directly with Vinted Pay's Director of Engineering and functionally with the Vinted Security senior team and your security peers in Marketplace, Vinted Go, and Platform. This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself and setting direction for the security work already under way, and as the function matures you will shape and functionally lead Vinted Pay's security engineering capability. In this position, you’ll
Own the Vinted Pay security roadmap end to end: assess the estate, prioritise by real attack paths, and drive risks to closure - a multi-quarter roadmap that shapes how Vinted Pay defends its infrastructure and payment assets, rather than reacting to the next audit. Turn regulation into engineering: map PCI DSS, DORA, and Bank of Lithuania and FCA requirements into practical, automated security controls and engineering guardrails - compliance as a by-product of how Vinted Pay builds, not a parallel workstream. Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count. Own PCI DSS and data protection architecture: payment page isolation, script monitoring, data encryption, and least-privilege access across multi-region environments - and turn those controls into evidence that stands up to assessors and regulators. Lead cross-functional security initiatives across Payments Platform, Payments Engineering, and Group Security, and drive them to delivery - whether execution sits with partner teams or you have to write the code yourself. Act as the technical arm of Vinted Pay's security accountable: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, and represent Vinted Pay in the group's security governance. Embed secure development into Payments engineering so security lands at design time rather than after deployment, and raise the security fluency of Vinted Pay engineers so risk-based decisions happen well without you in the room - security as a delivery enabler, not a gate. About you
Strong hands-on security engineering experience on a real engineering foundation - you have built or run large production systems, and you can threat-model a payment flow, find the attack path yourself, and drive or build the fix. Experience in regulated payments or fintech - you have worked under PCI DSS and a financial regulator (FCA, Bank of Lithuania, CSSF, or equivalent) and know how their requirements become controls engineers actually run. A staff- or principal-level track record - you have defined, led, and delivered major, company-wide technical initiatives, and you set security direction through software design on high-scale, distributed systems rather than from the outside. The range to move across the four archetypes of staff engineering - tech lead, architect, solver, right hand - picking the one the