Payments Information Security Officer

  • Kaunas
  • Vilnius
  • Engineering
  • Multiple locations, Lithuania
  • Vinted Pay

Brief info about Vinted 

Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third.
The Vinted Group is made up of three business units that support this mission:

Vinted Marketplace is Europe’s leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.

Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces.

Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.

Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people. 

Information about the position 

We are looking for a Payments Information Security Officer (ISO) to join our growing Payments Security team in Vilnius as our fourth member. Acting as the 2nd line of defense, our team safeguards Vinted Pay’s systems, payments data, and partners in full alignment with Bank of Lithuania regulations, the Digital Operational Resilience Act (DORA), and PCI-DSS standards.

In this role, you will take ownership of Vulnerability Management and Security Tooling, lead our Resilience Testing, and partner with product and engineering teams to embed security into the design of our next-generation payment systems.

In this position, you’ll 

  • Drive Vulnerability Management:
    • Own and continuously mature the end-to-end vulnerability management lifecycle across our payment ecosystem, covering code (SAST, SCA), runtime/applications (DAST), and cloud infrastructure.
    • Define and enforce clear vulnerability classification criteria and strict remediation SLAs/SLOs with engineering leads and platform teams.
    • Analyze exposure, prioritize remediation based on real-world exploitability in payment environments, and manage formal risk-acceptance workflows.
  • Review Product Security & Threat Modeling:
    • Act as the trusted security partner for Payments Product and Engineering teams, conducting proactive architectural reviews and threat modeling on new payment flows, digital wallet features, and checkout services.
    • Champion security-by-design across microservices, ensuring robust API security, strong customer authentication (SCA), tokenization, and strict cryptographic key management practices.
  • Manage Security Testing & Assurance:
    • Scope, coordinate, and govern third-party penetration testing engagements across payment applications and cloud environments; track remediation actions to verified closure.
    • Spearhead preparations and operational execution for advanced security testing under DORA, including Threat-Led Penetration Testing (TLPT / TIBER-EU/LT) and red teaming exercises.
    • Oversee and triage payments-related bug bounty reports, collaborating with ethical hackers and engineering to resolve valid disclosures swiftly.
  • Boost Security Tools Efficiency & Define Logging Requirements:
    • Maximize the coverage and operational efficiency of our security tooling stack (e.g., Wiz for cloud security posture and vulnerability management, SIEM, and monitoring tools).
    • Define, standardize, and govern security logging, audit trail, and telemetry requirements across payment services, databases (AWS/GCP), and infrastructure to meet BoL and DORA standards.
    • Optimize detection rules and alerting pipelines to cut down noise, accelerate threat detection, and provide high-fidelity security insights to the team.
  • Oversee Physical Security:
    • Define, maintain, and audit physical and environmental security policies, standards, and access control procedures for Vinted Pay premises, server rooms, and dedicated secure operational areas.
    • Conduct periodic physical security risk assessments and badge access reviews to ensure ongoing alignment with Bank of Lithuania regulations and DORA resilience expectations.

About you 

  • Experience: 3+ years of practical experience in information security, IT risk management, or security compliance — ideally within a FinTech, Electronic Money Institution (EMI), payment service provider (PSP), or regulated financial institution.
  • Regulatory & Standards Knowledge: Solid understanding of DORA (specifically ICT third-party risk requirements), Bank of Lithuania (BoL) guidelines, PCI-DSS (v4.0), and ISO/IEC 27001.
  • Vulnerability & Product Security: Hands-on experience with AppSec/DevSecOps practices (SAST/DAST/SCA), threat modeling methodologies, and enforcing vulnerability remediation SLAs across engineering teams.
  • Technical Grasp: Strong familiarity with cloud environments (AWS / GCP), threat-led testing frameworks (TLPT / TIBER), data encryption standards, and secure SDLC principles.
  • Tooling & Cloud Proficiency: Familiarity with modern cloud security platforms (especially Wiz), SIEM solutions, and AWS/GCP cloud environments
  • Pragmatic Mindset: Ability to balance rigorous security controls with practical business velocity, communicating clearly with developers, and leadership in English.
  • Certifications (Bonus): Relevant industry certifications such as CISA, CISSP, CRISC, CISM, or PCIP / ISA are considered a strong plus.

Work perks 

  • The opportunity to benefit from our share options programme
  • 25 working days of holiday
  • Access to all the tools & tech needed for work
  • Home office support: we provide IT workstation equipment and a personal budget of up to €540 for home workplace furniture
  • Private health insurance
  • Confidential Employee Assistance Program (EAP) for you and your family
  • Frequent team-building events
  • A personal monthly budget for shopping on Vinted
  • A dog-friendly office
  • In Vilnius office: Gym & in-house meals at friendly prices
  • In Kaunas office: a monthly lunch allowance, and a once-a-week provided in-house lunch and breakfast

Working at Vinted 

Individual Learning Budget

We invest in your professional growth! As part of our commitment to continuous learning, we offer an annual learning budget to support your personal and career development through courses, certifications, workshops and more.

Hybrid Work

We’ve adopted a hybrid workplace model where 2 days in the office are recommended but not enforced. It’s up to you and your team to decide on the exact days you’ll spend working together in person.

Equal Opportunity

The Vinted Group is committed to building an inclusive workplace where people from all walks of life feel a sense of belonging. We welcome applications from people of all backgrounds, identities and life experiences. At Vinted, all applicants are treated fairly without regard to their race, age, religion or belief, sex, national origin, citizenship, gender identity, sexual orientation, disability, or any other protected characteristic.

The salary range for this position is €3,967 - €5,367 gross per month.

The gross monthly salary range for this position is:
€3.967—€5.367 EUR

Submit your application

About you
Links
Additional information
Show resume text area
Show cover attachment

Are you legally authorised to work in the location you are applying to?

Your privacy takes top priority, which is why you can trust Vinted with the personal information you choose to share with us – it will only be used for recruitment purposes. 

Our Job Applicant Privacy Policy contains everything you need to know about how we use, store and collect this data, and your rights. Take a moment to read it before submitting your application: https://careers.vinted.com/privacy-policy.

We’d like to contact you about future opportunities at Vinted. But for this, you’ll need to consent to Vinted storing some of your personal data for up to 2 years – this includes your CV, email address, full name, and any other information you may have provided. Read our Job Applicant Privacy Policy if you’d like to learn more: https://careers.vinted.com/privacy-policy.

You can withdraw your consent at any time – just contact privacy.hr@vinted.com.

Select “Yes” if you give Vinted your consent to store your information for contacting you about future opportunities. Select “No” if you do not give Vinted your consent to store your information for contacting you about future opportunities.

Engineering job offers
We’re making second-hand first choice worldwide
Showing 20 out of 47
Find out about new positions at Vinted first

For information on how Vinted, UAB processes your personal data and how to withdraw your consent, read our Privacy Policy.