img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

Tabby | تابي is seeking a Vendor Risk Manager to join their team in Riyadh, Saudi Arabia. This full-time role involves managing the end-to-end third-party risk program, from initial due diligence to vendor offboarding. The Vendor Risk Manager will provide leadership with insights into high-risk vendors and ensure that vendor failures do not impact customers, particularly within the context of BNPL businesses that rely on a chain of vendors for critical operations.

Key Responsibilities

  • Conduct due diligence on new vendors, including financial health checks, SOC 2 / ISO 27001 review, breach history, and subprocessor mapping, before contract signing.
  • Issue clear risk ratings for prospective vendors, with specific conditions for various partner types such as KYC, identity verification, fraud detection, credit bureau, payment processing, card issuing, banking, and collections.
  • Collaborate with Legal and Procurement to secure essential contractual terms like audit rights, breach notification windows, data localization commitments, exit assistance clauses, and SLAs with penalties.
  • Manage vendor risk assessments across the active third-party portfolio, prioritizing critical and high-risk vendors for annual deep-dive reviews.
  • Establish and execute tiered monitoring cadences (quarterly for critical vendors; annually for others) to track control drift, subprocessor changes, and adverse media.
  • Maintain the concentration risk and critical-vendor register, and develop contingency plans for single points of failure.
  • Work with Product teams on new vendor integrations, participating in the evaluation of new checkout partners or fraud model vendors.
  • Prepare vendor risk reporting for the Risk Committee and Board, translating control gaps and incident trends into actionable insights.
  • Oversee the offboarding process for exited vendors, ensuring data deletion, access revocation, and transition continuity for customer-facing services.
  • Confirm that regulatory and contractual exit obligations are met and documented, especially for critical or important vendors.

Qualifications and Experience

  • 3–4 years of experience in third-party risk management, vendor risk, or operational risk, preferably within a payments company, lender, bank, or fintech where vendor failure has direct customer or regulatory consequences.
  • Working knowledge of NIST CSF, ISO 27001, SOC 2, and standardized assessment tools like SIG or CAIQ; ability to critically review SOC 2 reports and identify gaps.
  • Familiarity with the regulatory landscape affecting vendors, including consumer credit rules, data privacy obligations (GDPR/CCPA depending on footprint), PCI-DSS for card data, and outsourcing/operational resilience expectations for critical third parties.
  • Strong analytical skills to interpret vendor performance and control data for operational decision-making.
  • Excellent communication and interpersonal skills for effective interaction across all organizational levels.

Required Skills

  • Comfort in direct negotiation with vendors, including pushing back on standard MSAs, securing real SLAs from fraud vendors, and understanding when to escalate issues.
  • Ability to communicate risk findings effectively to non-risk professionals, explaining complex issues to commercial leads.

Preferred Qualifications

  • Direct BNPL or consumer credit experience, specifically with bureau data, alternative credit scoring vendors, or collections agencies.
  • Hands-on experience with a GRC platform such as OneTrust, ProcessUnity, or Archer for assessment workflows and vendor inventory.
  • CTPRP, CRISC, CISA, or CISM certification.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia, requiring 2-5 years of relevant experience. The role operates within a dynamic fintech environment where vendor risk directly impacts customer experience and regulatory compliance.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة