Company logo hidden

Vendor Risk Manager

Unlock employer Riyadh, Saudi Arabia Direct to Company 1 hour ago · 15 Sep 2026

Financial

  • Estimate: $60k - $100k*
  • Zero income tax location

Accessibility

  • Office Only
  • Apply from abroad
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional
  • Arabic: Preferred
Explore more jobs:

Position

About the Role
BNPL businesses don't run on a single core system — they rely on a chain of vendors: KYC providers conducting identity checks, bureau data informing underwriting decisions, processors facilitating payments at checkout, and collections agencies managing missed payments. A failure at any point in this chain can lead to significant customer inconveniences, flawed credit decisions, or regulatory scrutiny.
As the Vendor Risk Manager, you will manage the entire third-party risk program from due diligence to vendor offboarding. Your role will be crucial in identifying and communicating the risks associated with each vendor, ensuring that vendor failures do not translate into customer failures.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Key Responsibilities
Due Diligence & Onboarding

  • Conduct comprehensive due diligence on new vendors before contract execution, including financial assessments, SOC 2 / ISO 27001 reviews, breach histories, and subprocessor mappings.
  • Assign clear risk ratings to every prospective vendor, detailing conditions rather than providing binary pass/fail ratings across various categories such as KYC, fraud detection, and payment processing.
  • Collaborate with Legal and Procurement during the contracting phase to negotiate essential terms including audit rights, data localization commitments, and Service Level Agreements (SLAs) with real penalties.

Risk Assessment & Ongoing Monitoring

  • Manage vendor risk assessments for the existing third-party portfolio, focusing on critical and high-risk vendors for annual deep-dive evaluations.
  • Develop and implement tiered monitoring timelines — quarterly for critical vendors (KYC, payment processors) and annually for other vendors — to track control drift and changes in subprocessors.
  • Maintain comprehensive registers of concentration risk and critical vendors, clearly identifying single points of failure and contingency plans for crucial services.

Cross-Functional Partnership

  • Engage with Product teams before the launch of new vendor integrations, ensuring your involvement during the evaluation of new partners and fraud models.
  • Prepare vendor risk reporting for the Risk Committee and Board, translating control gaps and incident trends into actionable insights for leadership.

Offboarding & Exit Management

  • Oversee the offboarding process for terminated vendors, ensuring data deletion, access revocation, and continuity for customer-facing services.
  • Verify compliance with regulatory and contractual exit obligations, especially for vendors classified as critical.

Skills, Knowledge & Expertise

  • 3–4 years of experience in third-party risk management, vendor risk, or operational risk, particularly in payments, lending, banking, or fintech sectors.
  • Proficient in frameworks such as NIST CSF, ISO 27001, SOC 2, and familiar with assessment tools like SIG or CAIQ.
  • Knowledgeable about the regulatory environment surrounding consumer credit, data privacy (GDPR/CCPA), PCI-DSS, and operational resilience standards.
  • Skilled in vendor negotiations, capable of addressing issues in standard Master Service Agreements (MSAs).
  • Proven ability to communicate risk findings to stakeholders not versed in risk management, articulating the potential implications of vendor choices.
  • Strong analytical capabilities to interpret vendor performance and control data for operational decision-making.
  • Excellent communication and interpersonal skills, able to effectively engage across all organizational levels.
  • Full professional proficiency in English is required; knowledge of Arabic is a plus.

Nice to Have

  • Experience in BNPL or consumer credit, particularly with bureau data and collections agencies.
  • Familiarity with GRC platforms like OneTrust, ProcessUnity, or Archer for managing assessments and vendor inventories.
  • Relevant certifications such as CTPRP, CRISC, CISA, or CISM.
Apply Direct

Jobs you might like   View all jobs

About Financial Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct