As Staff / Senior Staff Security Engineer in Vinted Pay, you will be the staff-level security engineer inside our regulated payments business - and the person who makes Vinted Pay's security posture match its growth. Vinted Pay is a rare security problem in the best sense: a fintech scaling across multiple European licences at marketplace speed, where security cannot be a compliance checklist or an isolated engineering task - it has to be built into the core financial architecture. Its attack surface spans multi-region AWS infrastructure, payment pipelines and payment pages, wallets holding members' money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year.
Working at staff / senior staff level as an individual contributor embedded in the Payments Engineering leadership team, you will own the security of that whole estate. Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, SSDLC tooling, compliance), while each business unit owns local execution. Vinted Pay already owns part of its local execution; your job is to lead and scale it - this is not a policy or audit role, it is an engineering role with a mandate: translate regulatory requirements into technical guardrails and drive practical controls alongside Vinted Pay's platform and software engineers. You will work directly with Vinted Pay's Director of Engineering and functionally with the Vinted Security senior team and your security peers in Marketplace, Vinted Go, and Platform.
This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself and setting direction for the security work already under way, and as the function matures you will shape and functionally lead Vinted Pay's security engineering capability.
Nice to have
Nuoroda į skelbimą bus pridėta automatiškai žinutės pabaigoje.