Staff / Senior Staff Security Engineer, Vinted Pay

Vinted

Greater London

Hybrid

GBP 98,000 - 169,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Share options
25 days holiday
MacBook devices
Home office budget €540
EAP
Medical Insurance
Life and income protection
Pension scheme
Gym discount
Lunch benefit
Team-building events
Personal shopping budget

Job summary

Vinted is looking for a Staff/Senior Staff Security Engineer for Vinted Pay to own security across a multi-region AWS-based payments platform. You'll translate regulatory requirements into practical guardrails, drive technical controls, and lead cross-functional security initiatives with the Payments engineering and group security teams.

You will start hands-on and grow into a broader leadership role, reporting to the Director of Engineering and collaborating with security peers across Vinted.

Qualifications

  • Strong hands-on security engineering on production systems.
  • Experience in regulated payments/fintech and PCI DSS compliance.
  • Staff- or principal-level track record delivering major initiatives.
  • Ability to influence without authority and translate risk into business outcomes.
  • Excellent written and spoken English.
  • Experience with security tooling and observability to improve risk posture.

Responsibilities

  • Own the Vinted Pay security roadmap end to end; translate regulatory requirements into practical controls.
  • Turn regulation into engineering: map PCI DSS, DORA, and local requirements into automated controls.
  • Review AWS infrastructure, payment pipelines, SIEM and vulnerability tooling; fix gaps by priority.
  • Own PCI DSS and data protection architecture across multi-region environments; provide evidence for assessors.
  • Lead cross-functional security initiatives across Payments Platform, Payments Engineering, and Group Security.
  • Maintain risk register and governance; drive mitigation decisions.
  • Embed secure development into Payments engineering to bake security into design.

Skills

Security engineering
Fintech experience
Staff level track
Influence without authority
Observability tooling
AWS security
Privacy engineering
English fluency

Tools

Ruby on Rails
Go
MySQL
Temporal
AWS
Kibana
Grafana
Prometheus
Wiz
SIEM

Job description

Brief info about Vinted

Our mission is to make second-hand the first choice, and we’re looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third.
The Vinted Group is made up of three business units that support this mission:

Vinted Marketplace is Europe’s leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.

Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces.

Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.

Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania’s first unicorn! Today, our headquarters remain in Vilnius, and we’ve grown with offices across Europe, supported by a team of over 2,000 people.

Information about the position

As Staff / Senior Staff Security Engineer in Vinted Pay, you will be the staff-level security engineer inside our regulated payments business - and the person who makes Vinted Pay’s security posture match its growth. Vinted Pay is a rare security problem in the best sense: a fintech scaling across multiple European licences at marketplace speed, where security cannot be a compliance checklist or an isolated engineering task - it has to be built into the core financial architecture. Its attack surface spans multi-region AWS infrastructure, payment pipelines and payment pages, wallets holding members’ money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year.

Working at staff / senior staff level as an individual contributor embedded in the Payments Engineering leadership team, you will own the security of that whole estate. Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, SSDLC tooling, compliance), while each business unit owns local execution. Vinted Pay already owns part of its local execution; your job is to lead and scale it - this is not a policy or audit role, it is an engineering role with a mandate: translate regulatory requirements into technical guardrails and drive practical controls alongside Vinted Pay’s platform and software engineers. You will work directly with Vinted Pay’s Director of Engineering and functionally with the Vinted Security senior team and your security peers in Marketplace, Vinted Go, and Platform.

This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself and setting direction for the security work already under way, and as the function matures you will shape and functionally lead Vinted Pay’s security engineering capability.

In this position, you’ll
  • Own the Vinted Pay security roadmap end to end: assess the estate, prioritise by real attack paths, and drive risks to closure - a multi-quarter roadmap that shapes how Vinted Pay defends its infrastructure and payment assets, rather than reacting to the next audit.
  • Turn regulation into engineering: map PCI DSS, DORA, and Bank of Lithuania and FCA requirements into practical, automated security controls and engineering guardrails - compliance as a by-product of how Vinted Pay builds, not a parallel workstream.
  • Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count.
  • Own PCI DSS and data protection architecture: payment page isolation, script monitoring, data encryption, and least-privilege access across multi-region environments - and turn those controls into evidence that stands up to assessors and regulators.
  • Lead cross-functional security initiatives across Payments Platform, Payments Engineering, and Group Security, and drive them to delivery - whether execution sits with partner teams or you have to write the code yourself.
  • Act as the technical arm of Vinted Pay’s security accountable: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, and represent Vinted Pay in the group’s security governance.
  • Embed secure development into Payments engineering so security lands at design time rather than after deployment, and raise the security fluency of Vinted Pay engineers so risk-based decisions happen well without you in the room - security as a delivery enabler, not a gate.
About you
  • Strong hands-on security engineering experience on a real engineering foundation - you have built or run large production systems, and you can threat-model a payment flow, find the attack path yourself, and drive or build the fix.
  • Experience in regulated payments or fintech - you have worked under PCI DSS and a financial regulator (FCA, Bank of Lithuania, CSSF, or equivalent) and know how their requirements become controls engineers actually run.
  • A staff- or principal-level track record - you have defined, led, and delivered major, company-wide technical initiatives, and you set security direction through software design on high-scale, distributed systems rather than from the outside.
  • The range to move across the four archetypes of staff engineering - tech lead, architect, solver, right hand - picking the one the domain needs together with the Director of Engineering, not the one you prefer.
  • A way of working that engineers respect: evidence over assertions, attack paths over checklists, guardrails over gates.
  • Demonstrated ability to influence without authority and translate technical risk into business consequence for senior audiences, internal and external.
  • Comfortable in our stack – Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling – or eager to learn it, with a real interest in security and privacy as a field and the appetite to keep growing as an engineer and leader.
  • Excellent written and spoken English.
  • Advantage: experience building and running systems at massive scale (2+ million requests per minute), deep knowledge of observability tooling (Kibana, Grafana, Prometheus), and a passion for introducing new practices.
  • Advantage: AWS security depth (IAM, KMS, multi-account and multi-region architecture), or hands-on CSPM (e.g. Wiz) and SIEM engineering.
  • Advantage: privacy engineering experience, or offensive security background or certifications (e.g. OSCP).

If this role excites you but you don’t tick every box, we’d still like to hear from you.

Work perks
  • The opportunity to benefit from our share options programme
  • 25 working days of holiday
  • Newest MacBook models
  • Home office support: we provide IT workstation equipment and a personal budget of up to €540 for home workplace furniture
  • Confidential Employee Assistance Program (EAP) for you and your family
  • Comprehensive Medical Insurance
  • Group Life and Income Protection Insurance
  • A matched pension scheme up to a set limit
  • Access to a discounted gym membership plan
  • Lunch benefit per working day
  • Frequent team-building events
  • A personal monthly budget for shopping on Vinted
Working at Vinted

Workation policy

Better balance holidays with workdays by working remotely! Up to 90 days per year in the EU, of these, 21 days can be spent globally. For non-EU citizens, it’s 21 days worldwide. This can be combined with time off for vacation or personal time.

Individual learning budget

Each year, you’ll be given a learning budget (starting at €3,000), and a total of up to 10 working days over a 2-year period to support your personal and professional development.

Hybrid work

Our hybrid model, with 2 recommended office days a week, gives you and your team the flexibility to decide if and when you want to work from home, and when to catch up in person.

Equal opportunity

We welcome applications from everybody, regardless of your background, identity, or life experiences. Job openings come with guides, not checklists. If you’re excited about a role, but don’t identify with every point in the ‘About you’ section, apply anyway – you might still be the perfect match!

The annual gross salary range for this position is:

£97,800—£169,100 GBP

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff / Senior Staff Security Engineer, Vinted Pay
Staff / Senior Staff Security Engineer, Vinted Pay

Vinted group. • Greater London

Hybrid
GBP 150,000 - 190,000
Share options programme
25 working days of holiday
Home office budget and equipment
+2
Director of Product, AML & Fraud Prevention
Director of Product, AML & Fraud Prevention

Vinted • Greater London

Hybrid
GBP 106,000 - 143,000
Share options programme
25 days of paid annual leave
Newest MacBook models
+2
Strategic Finance Manager (Payments & Commercial)
Strategic Finance Manager (Payments & Commercial)

Vinted • Greater London

On-site
GBP 90,000 - 140,000
Share options
25 days annual leave
MacBook models
+3
Strategic Finance Manager (Payments & Commercial)
Strategic Finance Manager (Payments & Commercial)

Vinted group. • Greater London

Hybrid
GBP 120,000 - 190,000
Learning budget
Hybrid work
Gym discount
+2
Director of Product, AML & Fraud Prevention
Director of Product, AML & Fraud Prevention

Vinted group. • Greater London

On-site
GBP 120,000 - 180,000
Hybrid work model
Learning budget
Pension & insurance
+1
Electronics Testing Specialist
Electronics Testing Specialist

Vinted • Greater London

On-site
GBP 27,000 - 29,000
25 days leave
Mental health support
Lunch allowance
+5
Electronics Testing Specialist
Electronics Testing Specialist

Vinted group. • Greater London

Hybrid
GBP 32,000 - 42,000
25 days paid annual leave
Mindletic mental health support app
Frequent team-building events
+3
Senior Staff Security Engineer – FinTech Payments (Hybrid)
Senior Staff Security Engineer – FinTech Payments (Hybrid)

Vinted • Greater London

Hybrid
GBP 98,000 - 169,000
Share options
25 days holiday
MacBook devices
+9
Fintech Payments Security Architect (Staff)
Fintech Payments Security Architect (Staff)

Vinted group. • Greater London

Hybrid
GBP 150,000 - 190,000
Share options programme
25 working days of holiday
Home office budget and equipment
+2
Senior People Partner
Senior People Partner

Vitesse • City Of London

Hybrid
GBP 90,000 - 120,000