Vinted Paskelbta šiandien

Payments Information Security Officer

Ko tikimasi

Rodyti dar 3

Ką siūlo

Rodyti dar 10

Pozicijos aprašymas

Santrauką ruošiame – kol kas originalus skelbimo tekstas.

Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third. The Vinted Group is made up of three business units that support this mission:

Vinted Marketplace is Europe's leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.

Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces.

Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.

Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people.

Information about the position

We are looking for a Payments Information Security Officer (ISO) to join our growing Payments Security team in Vilnius as our fourth member. Acting as the 2nd line of defense, our team safeguards Vinted Pay's systems, payments data, and partners in full alignment with Bank of Lithuania regulations, the Digital Operational Resilience Act (DORA), and PCI-DSS standards. In this role, you will take ownership of Vulnerability Management and Security Tooling, lead our Resilience Testing, and partner with product and engineering teams to embed security into the design of our next-generation payment systems.

Drive Vulnerability Management: Own and continuously mature the end-to-end vulnerability management lifecycle across our payment ecosystem, covering code (SAST, SCA), runtime/applications (DAST), and cloud infrastructure. Define and enforce clear vulnerability classification criteria and strict remediation SLAs/SLOs with engineering leads and platform teams. Analyze exposure, prioritize remediation based on real-world exploitability in payment environments, and manage formal risk-acceptance workflows.

Review Product Security & Threat Modeling: Act as the trusted security partner for Payments Product and Engineering teams, conducting proactive architectural reviews and threat modeling on new payment flows, digital wallet features, and checkout services. Champion security-by-design across microservices, ensuring robust API security, strong customer authentication (SCA), tokenization, and strict cryptographic key management practices.

Manage Security Testing & Assurance: Scope, coordinate, and govern third-party penetration testing engagements across payment applications and cloud environments; track remediation actions to verified closure. Spearhead preparations and operational execution for advanced security testing under DORA, including Threat-Led Penetration Testing (TLPT / TIBER-EU/LT) and red teaming exercises. Oversee and triage payments-related bug bounty reports, collaborating with ethical hackers and engineering to resolve valid disclosures swiftly.

Boost Security Tools Efficiency & Define Logging Requirements: Maximize the coverage and operational efficiency of our security tooling stack (e.g., Wiz for cloud security posture and vulnerability management, SIEM, and monitoring tools). Define, standardize, and govern security logging, audit trail, and telemetry requirements across payment services, databases (AWS/GCP), and infrastructure to meet BoL and DORA standards. Optimize detection rules and alerting pipelines to cut down noise, accelerate threat detection, and provide high-fidelity security insights to the team.

Oversee Physical Security: Define, maintain, and audit physical and environmental security policies, standards, and access control procedures for Vinted Pay premises, server rooms, and dedicated secure operational areas. Conduct periodic physical security risk assessments and badge access reviews to ensure ongoing alignment with Bank of Lithuania regulations and DORA resilience expectations.

Panašūs darbai