Staff / Senior Staff Security Engineer, Vinted Pay

United States Digital Space LLC

London

Hybrid

NOK 1,231,000 - 2,129,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Share options program
25 working days holiday
MacBook laptops
Home office budget €540
Employee Assistance Program (EAP)
Medical Insurance
Group Life Insurance
Pension match
Gym membership discount
Lunch benefit

Job summary

Vinted seeks a staff/senior staff Security Engineer for Vinted Pay to scale security across a growing fintech platform. You’ll translate regulatory requirements into practical guardrails, own PCI DSS and data protection architecture, and collaborate with Payments Platform, Engineering, and Group Security to embed secure development.

This hands-on role starts by closing high-impact gaps and grows into leading security initiatives across AWS infrastructure and payment flows.

Qualifications

  • Strong hands-on security engineering experience on a real engineering foundation.
  • Experience in regulated payments or fintech with PCI DSS/FCA exposure.
  • Staff- or principal-level track record delivering major security initiatives.
  • Excellent written and spoken English.

Responsibilities

  • Own the Vinted Pay security roadmap end to end and drive risk closure.
  • Translate regulatory requirements into engineering guardrails and controls.
  • Identify and close operational security blind spots across AWS, payment pipelines, and logging.
  • Own PCI DSS and data protection architecture across multi-region environments.
  • Lead cross-functional security initiatives with Payments Platform, Engineering, and Group Security.
  • Be the technical arm of security accountability and maintain the risk register.

Skills

Security engineering
Regulated payments/fintech
Leadership without authority
English communication
AWS security depth
Threat modelling

Tools

Ruby on Rails
Go
MySQL
Temporal
AWS
SIEM
CSPM (Wiz)

Job description

Brief info about Vinted

Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third.The Vinted Group is made up of three business units that support this mission:


Vinted Marketplace

is Europe’s leading platform for second‑hand fashion and a go‑to destination for all kinds of pre‑loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.


Vinted Go

enhances the shipping experience with a vast network of over 500,000 pick‑up and drop‑off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high‑value pieces.


Vinted Pay

is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.


Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people.


Information about the position

As Staff / Senior Staff Security Engineer in Vinted Pay, you will be the staff-level security engineer inside our regulated payments business - and the person who makes Vinted Pay's security posture match its growth. Vinted Pay is a rare security problem in the best sense: a fintech scaling across multiple European licences at marketplace speed, where security cannot be a compliance checklist or an isolated engineering task - it has to be built into the core financial architecture. Its attack surface spans multi-region AWS infrastructure, payment pipelines and payment pages, wallets holding members' money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year.


Working at staff / senior staff level as an individual contributor embedded in the Payments Engineering leadership team, you will own the security of that whole estate. Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, SSDLC tooling, compliance), while each business unit owns local execution. Vinted Pay already owns part of its local execution; your job is to lead and scale it - this is not a policy or audit role, it is an engineering role with a mandate: translate regulatory requirements into technical guardrails and drive practical controls alongside Vinted Pay's platform and software engineers. You will work directly with Vinted Pay's Director of Engineering and functionally with the Vinted Security senior team and your security peers in Marketplace, Vinted Go, and Platform.


This is a build role with room to grow: you start hands‑on, closing the highest‑impact gaps yourself and setting direction for the security work already under way, and as the function matures you will shape and functionally lead Vinted Pay's security engineering capability.


In this position, you’ll

  • Own the Vinted Pay security roadmap end to end: assess the estate, prioritise by real attack paths, and drive risks to closure - a multi-quarter roadmap that shapes how Vinted Pay defends its infrastructure and payment assets, rather than reacting to the next audit.

  • Turn regulation into engineering: map PCI DSS, DORA, and Bank of Lithuania and FCA requirements into practical, automated security controls and engineering guardrails - compliance as a by-product of how Vinted Pay builds, not a parallel workstream.

  • Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count.

  • Own PCI DSS and data protection architecture: payment page isolation, script monitoring, data encryption, and least-privilege access across multi-region environments - and turn those controls into evidence that stands up to assessors and regulators.

  • Lead cross-functional security initiatives across Payments Platform, Payments Engineering, and Group Security, and drive them to delivery - whether execution sits with partner teams or you have to write the code yourself.

  • Act as the technical arm of Vinted Pay's security accountable: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, and represent Vinted Pay in the group's security governance.

  • Embed secure development into Payments engineering so security lands at design time rather than after deployment, and raise the security fluency of Vinted Pay engineers so risk‑based decisions happen well without you in the room - security as a delivery enabler, not a gate.

About you

  • Strong hands‑on security engineering experience on a real engineering foundation - you have built or run large production systems, and you can threat‑model a payment flow, find the attack path yourself, and drive or build the fix.

  • Experience in regulated payments or fintech - you have worked under PCI DSS and a financial regulator (FCA, Bank of Lithuania, CSSF, or equivalent) and know how their requirements become controls engineers actually run.

  • A staff- or principal-level track record - you have defined, led, and delivered major, company‑wide technical initiatives, and you set security direction through software design on high‑scale, distributed systems rather than from the outside.

  • The range to move across the four archetypes of staff engineering - tech lead, architect, solver, right hand - picking the one the domain needs together with the Director of Engineering, not the one you prefer.

  • A way of working that engineers respect: evidence over assertions, attack paths over checklists, guardrails over gates.

  • Demonstrated ability to influence without authority and translate technical risk into business consequence for senior audiences, internal and external.

  • Comfortable in our stack - Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling - or eager to learn it, with a real interest in security and privacy as a field and the appetite to keep growing as an engineer and leader.

  • Excellent written and spoken English.

  • Advantage: experience building and running systems at massive scale (2+ million requests per minute), deep knowledge of observability tooling (Kibana, Grafana, Prometheus), and a passion for introducing new practices.

  • Advantage: AWS security depth (IAM, KMS, multi-account and multi-region architecture), or hands‑on CSPM (e.g. Wiz) and SIEM engineering.

  • Advantage: privacy engineering experience, or offensive security background or certifications (e.g. OSCP).

If this role excites you but you don't tick every box, we'd still like to hear from you.


Work perks

  • The opportunity to benefit from our share options programme

  • 25 working days of holiday

  • Newest MacBook models

  • Home office support: we provide IT workstation equipment and a personal budget of up to €540 for home workplace furniture

  • Confidential Employee Assistance Program (EAP) for you and your family

  • Comprehensive Medical Insurance

  • Group Life and Income Protection Insurance

  • A matched pension scheme up to a set limit

  • Access to a discounted gym membership plan

  • Lunch benefit per working day

  • Frequent team‑building events

  • A personal monthly budget for shopping on Vinted

Working at VintedWorkation policy

Better balance holidays with workdays by working remotely! Up to 90 days per year in the EU, of these, 21 days can be spent globally. For non‑EU citizens, it's 21 days worldwide. This can be combined with time off for vacation or personal time.


Individual learning budget

Each year, you’ll be given a learning budget (starting at €3,000), and a total of up to 10 working days over a 2-year period to support your personal and professional development.


Hybrid work

Our hybrid model, with 2 recommended office days a week, gives you and your team the flexibility to decide if and when you want to work from home, and when to catch up in person.


Equal opportunity

We welcome applications from everybody, regardless of your background, identity, or life experiences. Job openings come with guides, not checklists. If you’re excited about a role, but don’t identify with every point in the ‘About you’ section, apply anyway – you might still be the perfect match!


The annual gross salary range for this position is:


£97,800-£169,100 GBP

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineering Manager, GRC and Assurance
Engineering Manager, GRC and Assurance

Vinted • Oslo

Hybrid
NOK 1,083,000 - 1,425,000
Share options
25 days paid annual leave
Newest MacBook models
+8
Senior Backend Engineer II, Engineering Experience
Senior Backend Engineer II, Engineering Experience

Vinted • Oslo

Hybrid
NOK 928,000 - 1,255,000
Share options
25 days annual leave
New MacBook models
+10
Maintenance Operative, VintedGo
Maintenance Operative, VintedGo

Vinted • Oslo

On-site
NOK 281,000 - 346,000
25 jours ouvrés de congés
MacBook et outils modernes
Programme d’aide aux employés (EAP)
+4
Senior Staff Security Engineer — Fintech Payments
Senior Staff Security Engineer — Fintech Payments

United States Digital Space LLC • London

Hybrid
NOK 1,231,000 - 2,129,000
Share options program
25 working days holiday
MacBook laptops
+7
Senior Security Consultant
Senior Security Consultant

10x Banking • London

Hybrid
NOK 1,141,000 - 1,521,000
Remote-enabled working
Private health insurance
Pension scheme
+2
FinOps Manager
FinOps Manager

Valarian Technologies Limited • London

On-site
NOK 887,000 - 1,395,000
Equity
Competitive salary
Pension
+5
Senior Back-End Engineer - Ledger Platform
Senior Back-End Engineer - Ledger Platform

iwoca • London

On-site
GBP 80,000 - 110,000
Flexible working hours
Medical insurance from Vitality
Private GP service
+4
Head of Operations & Systems
Head of Operations & Systems

Odin • London

Hybrid
NOK 1,511,000 - 1,889,000
Private health insurance
Wellness budget
Parental leave
+4
Security Engineer
Security Engineer

StackOne • London

Hybrid
NOK 1,141,000 - 1,648,000
Share options (EMI)
Lunch budget London office
Private health insurance
Senior Data Analyst
Senior Data Analyst

Vipps • Oslo

On-site
NOK 900,000 - 1,100,000
Flexibility to work from home two days