SlipstreamJobsFresh Startup & VC-Backed Jobs

Vendor Delivery Manager

Deblock - Porto, Portugal - Hybrid - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Deblock is a regulated EMI and crypto-asset service provider building out operational resilience capabilities. This role focuses on strengthening and scaling the third-party and ICT risk framework that governs vendor selection, assessment, and monitoring under DORA and broader regulatory expectations. You will work cross-functionally with Compliance, Risk, Technology, and Operations teams to translate regulatory requirements into practical, day-to-day controls. The role requires balancing supervisory rigor with pragmatism—the framework must withstand regulatory scrutiny while accommodating a fast-growing organization. Key Responsibilities: Mapping and Understanding Dependencies: Identify critical and important functions and the provider dependencies behind them, including substitutability and exit planning. Maintain a complete and current register of outsourcing and ICT third-party arrangements with all information regulators expect. Vendor Assessment and Governance: Conduct due diligence on providers across operational, ICT, compliance, and financial risk dimensions. Challenge assessments where evidence doesn't support conclusions. Ensure contractual arrangements include DORA-required provisions and clear governance before go-live. Ongoing Monitoring and Reporting: Track provider performance, incidents, and concentration risk. Escalate issues that require management decision. Build KRIs, dashboards, and reporting that give management and the board a realistic view of third-party exposure rather than compliance artifacts. Framework Evolution: Develop and evolve policies, procedures, and governance standards to keep processes repeatable as the company scales. Support the wider DORA implementation program, including incident and resilience testing obligations. Requirements: The posting does not explicitly state years of experience, educational qualifications, or specific certifications required. However, the role implicitly requires: strong understanding of DORA and third-party risk frameworks; experience in vendor due diligence and risk assessment across operational, ICT, compliance, and financial dimensions; familiarity with regulatory expectations for EMIs and crypto-asset service providers; ability to work cross-functionally and translate regulatory requirements into operational controls; and demonstrated capability to balance compliance rigor with business pragmatism in a growth environment.

Similar roles