Zalando Payments
fintech
SeniorSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Security Engineer at Zalando Payments. Skills: Information Security, Risk Management, GRC. Own and evolve Information Security Management System. Drive ZPS Security Controls Framework”
What You'll Achieve.
Ensuring security is embedded, measurable, and auditable; Ensuring control effectiveness is demonstrated
Industry & Context.
What They're Looking For.
Must Have
5+ years of working experience in Information Security, Risk, or GRC, Understand frameworks and regulations such as DORA, PCI DSS, ISO 27001, or GDPR, Experience designing or assessing security controls, GRC engineering mindset, Able to challenge constructively as a second line of defense, Communicate clearly with both technical and non technical stakeholders
Nice to Have
Ideally in regulated environments such as fintech or payments
What You'll Do.
Own and evolve Information Security Management System
Drive ZPS Security Controls Framework
Independently verify security controls
Apply GRC engineering mindset
Collaborate with first line Engineering teams
Support internal and external audits
How You'll Work.
Team & Collaboration
Collaborate with first line Engineering teams; Collaborate effectively with engineering and security teams
Communication Scope
Communicate clearly with both technical and non technical stakeholders
Full Job Description
****THE ROLE & THE TEAM******** The Information Security team at Zalando Payments acts as the second line of defense, owning the Information Security Management System and providing independent oversight of security risks and controls. As a regulated e-money and payments institution, we operate under frameworks such as DORA, PCI DSS, GDPR, and BaFin expectations, ensuring security is embedded, measurable, and auditable. In this role, you will help define and maintain security policies, standards, and the ZPS Security Controls Framework, while independently verifying control design and effectiveness across cloud, infrastructure, and application domains. You will work closely with first line Engineering teams, while maintaining the independence required to challenge and strengthen the overall security posture. We are evolving towards a modern, scalable GRC model focused on automated evidence collection and continuous control monitoring. You will play a key role in driving this transformation, combining governance expertise with a technical mindset. You will also support internal and external audits, regulatory readiness, and management reporting, ensuring control effectiveness is demonstrated in a structured and data driven way. ****INCLUSIVE BY DESIGN**** If you think you have what it takes, we encourage you to apply even if you don't meet every single requirement. You may just be the right candidate for this or other roles! At Zalando, our vision is to be the leading pan-European ecosystem for fashion and lifestyle e-commerce – one that thrives on diversity and is truly inclusive by design. We believe that diverse teams fuel innovation and creativity, and we actively seek out talent from all backgrounds. We actively seek to reduce bias in our hiring and employment processes, focusing on your qualifications, skills, and contributions. To support this, we kindly ask that you refrain from including personal details such as your photo, age, or marital status in your CV,
Applying for this Senior Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Zalando Payments?
Real rants from real employees. Read before you apply.