Vinted

Staff / Senior Staff Security Engineer, IT

Vinted Kaunas, Kaunas County, Lithuania · €96K–€159K/yr

Software Development · 1,001-5,000 employees

6 h ago
security Principal (10+ yrs) Full-time Lithuania
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will own the end-to-end IT security roadmap, including threat modeling the workplace estate and driving risk mitigation. Additionally, you will build and lead IT's security engineering capability, ensuring secure defaults for devices, identity, and SaaS integrations.

What they look for

Security engineering Threat modeling Identity and access management Endpoint security SaaS security Network security Automation Python Go Infrastructure as code Risk management Compliance Incident response Vulnerability management Security architecture Cloud security

Requirements

The role requires deep hands-on experience in securing corporate IT estates, including endpoints, identity, and SaaS applications. You must possess an engineering mindset with proficiency in automation, scripting, and building security controls as products.

Benefits

Share options programme 25 working days of holiday Home office support Private health insurance Employee Assistance Program Team-building events Monthly shopping budget Dog-friendly office Gym In-house meals Lunch allowance Workation policy Individual learning budget

Full description

Brief info about Vinted

Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life – or even a third. The Vinted Group is made up of three business units that support this mission:

Vinted Marketplace is Europe’s leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.

Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces.

Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.

Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people.

Information about the position

As a Staff / Senior Staff Security Engineer you will be the first dedicated security engineer inside Vinted's IT organisation - and the person who makes the security of how Vinted works match the security of what Vinted builds. Most real-world breaches start where people meet technology: a phished identity, a compromised laptop, an over-privileged SaaS integration, a device nobody knew was on the network. Every employee, contractor and community support agent at Vinted works through what IT provides - including the thousands of agents at partner sites who act on members' accounts every day - so the attack surface you will own is the whole extended workforce.

Working at staff /senior staff level as an individual contributor embedded in IT, you will own the security of both halves of IT's estate. The hardware: the managed device fleet, peripherals, office infrastructure, and the network hardware and verification equipment IT deploys in warehouses and electronics verification centres. The software: workforce identity, the SaaS and business-application portfolio, and the integrations, automations and AI tooling that connect them.

Vinted Security runs a federated model: the central team sets thresholds and provides core services (pentesting, threat intelligence, vulnerability management framework and so on), while each unit owns local execution. IT's local execution is what you will build - this is an engineering role with a mandate, not a policy or audit function. You will work day to day with IT's engineering teams and the Director of IT, and functionally with the Vinted Security team and your security peers embedded in Platform, Marketplace, Vinted Go and Vinted Pay.

This is a build role with room to grow: you start hands-on, closing the highest-impact gaps yourself, and as the practice matures you will shape and functionally lead IT's security engineering capability.

In this position, you’ll

  • Own the IT security roadmap end to end: threat-model the workplace estate, prioritise by real attack paths and drive risks to closure, keeping IT resilience to external attack at the standard Vinted holds itself to.
  • Be a pragmatic evangelist for all things security: raise the security fluency of IT engineers and the wider workforce so risk-based decisions happen well without you in the room - security as a service people want to use, not a gate.
  • Make every device Vinted issues or operates trustworthy by default: hardened, managed baselines across the Mac-first fleet and its Windows and Linux edges, least privilege on endpoints, endpoint detection and response, and device trust as a condition of access - covering the full lifecycle from procurement to return.
  • Secure workforce identity as the perimeter: phishing-resistant authentication, joiner-mover-leaver automation, role-based and privileged access, four-eyes controls on high-risk actions, and time-bound access for contractors and the community support agents working from partner sites - built on the group's identity standards and engineered into how IT provisions, not bolted on afterwards.
  • Own the security of the SaaS and business-application estate: configuration baselines, OAuth and API integrations, data flows between systems, shadow IT and shadow AI - so that adding a tool never silently adds an attack path.
  • Secure the network and hardware in Vinted's physical sites: office networks, secure remote access, and the standard IT builds for warehouses and electronics verification centres - where phones, consoles and laptops under test, verification devices and site infrastructure meet - owning the boundary with Vinted Go's security team.
  • Engineer security into how IT builds: automation and security solutions that enable resilience and align with business objectives - not just improving today's posture, but continuously identifying and closing the next gap.
  • Build compliance as a code: maintain the risk register, prepare mitigation-or-acceptance decisions against centrally set thresholds, represent IT in Vinted security governance, and build it in a way that evidence is integral part of the process.

About you

  • Deep hands-on experience securing a corporate IT estate at scale - endpoints and device management, workforce identity and access, SaaS and business applications - and you can find the attack path through it yourself and drive or build the fix.
  • An engineering mindset applied to IT: you automate, you script (Python, Go or similar), you manage identity and infrastructure as code, and you build controls as products for the people who use them - secure defaults over tickets and checklists.
  • The ability to build a security practice from scratch inside an IT or infrastructure organisation: create clarity, pick the few things that matter, and build machinery in a low-maturity environment.
  • Comfortable on both sides of the IT/OT boundary: you have secured networks and devices in physical sites - warehouses, labs, verification or repair centres - not only offices, or you are eager to.
  • A way of working that engineers respect: evidence over assertions, attack paths over checklists, automation over policies.
  • Demonstrated ability to influence without authority and translate technical risk into business consequence for senior audiences.
  • Excellent written and spoken English.
  • Advantage: depth in our stack - Okta, Jamf, Google Workspace, Atlassian, Workato - or their equivalents.
  • Advantage: hardware and device security depth - firmware and secure boot, device attestation, peripheral and USB threats, EDR engineering.
  • Advantage: offensive security background or certifications (e.g. OSCP), detection engineering on identity and endpoint telemetry, or ISO 27001 / NIS2 implementation experience in workplace scope.

If this role excites you but you don't tick every box, we'd still like to hear from you.

Work perks

  • The opportunity to benefit from our share options programme
  • 25 working days of holiday
  • Access to all the tools & tech needed for work
  • Home office support: we provide IT workstation equipment and a personal budget of up to €540 for home workplace furniture
  • Private health insurance
  • Confidential Employee Assistance Program (EAP) for you and your family
  • Frequent team-building events
  • A personal monthly budget for shopping on Vinted
  • A dog-friendly office
  • In Vilnius office: Gym & in-house meals at friendly prices
  • In Kaunas office: a monthly lunch allowance, and a once-a-week provided in-house lunch and breakfast

Working at Vinted

Workation policy

Better balance holidays with workdays by working remotely! Up to 90 days per year in the EU, of these, 21 days can be spent globally. For non-EU citizens, it's 21 days worldwide. This can be combined with time off for vacation or personal time.

Individual learning budget

Each year, you’ll be given a learning budget (starting at €3,000), and a total of up to 10 working days over a 2-year period to support your personal and professional development.

Hybrid work

Our hybrid model, with 2 recommended office days a week, gives you and your team the flexibility to decide if and when you want to work from home, and when to catch up in person.

Equal opportunity

We welcome applications from everybody, regardless of your background, identity, or life experiences. Job openings come with guides, not checklists. If you’re excited about a role, but don’t identify with every point in the ‘About you’ section, apply anyway – you might still be the perfect match!

The gross monthly salary range for this position is:

€8.008—€13.275 EUR

Similar roles