Overview
As a Staff/Senior Staff Security Engineer in Vinted Pay, you will harden the security posture of our fintech payments platform at scale. You’ll translate complex regulatory requirements into practical, automated controls and embed security into core architecture across multi-region AWS environments. You’ll own end-to-end security roadmapping, drive threat-based prioritization, and lead cross-functional initiatives with Engineering and Group Security. This role blends hands-on engineering with strategic leadership to enable secure growth and regulatory compliance. If you’re motivated by building secure, scalable payment systems, this is a unique opportunity to shape security at the heart of a
Pay / Benefits
- share options programme
- 25 working days of holiday
- Newest MacBook models
- Home office support with up to 540 for furniture
- Confidential Employee Assistance Program
- Comprehensive Medical Insurance
Responsibilities
- Own the Vinted Pay security roadmap end to end, prioritizing risks and driving multi-quarter delivery
- Turn PCI DSS, DORA, and local regulatory requirements into automated security controls and guardrails
- Perform deep technical reviews of AWS infrastructure, payment pipelines, SIEM, and vulnerability tooling, fixing high-exposure gaps
- Own PCI DSS and data protection architecture with isolation, monitoring, encryption, and least-privilege access
- Lead cross-functional security initiatives across Payments Platform and Engineering, coordinating with partner teams
- Act as the technical arm of security accountability, maintaining risk registers and governance representations
- Embed secure development practices into Payments engineering to achieve risk-based security at design time
Key requirements
- Hands-on security engineering experience on large production systems
- Experience in regulated payments or fintech with PCI DSS and regulatory exposure
- Staff- or principal-level track record defining and delivering major technical initiatives
- Ability to translate technical risk into business impact and influence without authority
- Proficiency in Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling (or willingness to learn)
- Excellent written and spoken English
- Advantage: experience at massive scale, observability tooling, AWS security depth, CSPM/SIEM, privacy engineering, offensive security
- evidence-based decision making
- influence without authority
- cross-functional collaboration
- Ruby on Rails
- Go
- MySQL
…
