Engineering Manager, GRC and Assurance
Listed on 2026-09-13
-
Management
Our mission is to make second-hand the first choice, and we're looking for people who want to help us get there. Every day, we work together to help our members buy and sell pre-loved clothing and lifestyle items, giving each piece a second life - or even a third.
The Vinted Group is made up of three business units that support this mission:
Vinted Marketplace is Europe's leading platform for second-hand fashion and a go-to destination for all kinds of pre-loved items, with a growing range of categories. Our platform connects millions of members across 20+ markets, helping great items find a new life.
Vinted Go enhances the shipping experience with a vast network of over 500,000 pick-up and drop-off points, partnering with more than 60 carriers across Europe, with added services like item verification for peace of mind on high-value pieces.
Vinted Pay is the newest part of the Vinted Group, dedicated to bringing secure, reliable payments to buyers and sellers across Europe. Seamlessly integrated into the Vinted app, it helps keep every transaction safe, efficient, and easy for our members.
Founded in 2008 in Lithuania, Vinted began as a way for friends to find new homes for clothes they no longer needed. In 2019, we became Lithuania's first unicorn! Today, our headquarters remain in Vilnius, and we've grown with offices across Europe, supported by a team of over 2,000 people.
We are looking for an Engineering Manager to lead GRC and Assurance in Group Security: a team of seven today, growing even more in 2027. The team owns risk management, compliance and audit liaison, second-line security assurance, AI governance, third-party risk, business continuity and security culture.
Vinted spans three distinct entities:
Marketplace, Vinted Go, and Vinted Payments, our regulated payments institution. That means handling a fast-moving regulatory landscape covering core privacy (GDPR, CCPA), payment licenses, incoming mandates like DORA, NIS2, and the EU AI Act, alongside driving our 2027 ISO 27001 certification. In most companies, governance runs quietly in the background. At Vinted, it’s core architecture.
We are looking for a practitioner rather than a documenter: someone who leads from the front, turns requirements into controls that work, and grows the people around them through hands‑on work.
In this position, you'll- Deliver ISO 27001 by 2027: Own the scope, audits, and a single control set covering NIS2 and DORA (with PCI DSS managed separately).
- Map our compliance stack: Build the master map across all three businesses (what applies, when, and liability) to unblock key decisions.
- Run governance like engineering: Turn controls into code, automate evidence, and serve as the first user for Group Security's new posture platform.
- Lead and grow the team: Manage seven functions, develop specialists on Lead Implementer/Auditor tracks, and add three new hires through early 2027.
- You have run a security governance or compliance function through a certification or a regulator's examination, ISO 27001 or something comparable.
- You think like an engineer about governance: you can say how a control can be automated and how evidence gets collected without a spreadsheet.
- You can hold several regimes in your head at once and tell a real obligation from an assumed one.
- You develop specialists rather than delivering around them, and you will say something is not compliant when nobody wants to hear it.
If you're excited about this role but don't identify with every point above, apply anyway. You might still be the right match.
- The opportunity to benefit from our share options programme
- 25 days of paid annual leave
- Digital mental and emotional health support and Employee Assistant…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).