SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tabby is a BNPL (Buy Now, Pay Later) fintech operating in the Middle East. As Vendor Risk Manager, you will own the third-party risk program end-to-end, from initial due diligence through vendor offboarding. You are responsible for ensuring that vendor failures never cascade into customer failures or regulatory breaches.
Key responsibilities include:
**Due Diligence & Onboarding**: Conduct comprehensive due diligence on new vendors covering financial health, SOC 2/ISO 27001 compliance, breach history, and subprocessor mapping. Issue risk ratings with conditions for KYC, identity verification, fraud detection, credit bureau, payment processing, card issuing, banking, and collections partners. Partner with Legal and Procurement to secure critical contract terms including audit rights, breach notification windows, data localization, exit assistance, and SLA penalties.
**Risk Assessment & Monitoring**: Own vendor risk assessments across the active third-party portfolio, prioritizing critical and high-risk vendors for annual reviews. Build and execute tiered monitoring cadences—quarterly for critical vendors (KYC, payment processing, banking), annual for others—tracking control drift, subprocessor changes, and adverse media. Maintain concentration risk and critical-vendor registers, identifying single points of failure and contingency plans.
**Cross-Functional Partnership**: Engage with Product before new vendor integrations launch. Prepare vendor risk reporting for the Risk Committee and Board, translating control gaps and incident trends into actionable decisions.
**Offboarding & Exit Management**: Manage vendor offboarding, confirming data deletion, access revocation, and transition continuity. Ensure regulatory and contractual exit obligations are met and documented.
Required: 3–4 years in third-party risk, vendor risk, or operational risk at a payments company, lender, bank, or fintech. Working knowledge of NIST CSF, ISO 27001, SOC 2, and assessment tools (SIG, CAIQ). Familiarity with consumer credit rules, data privacy (GDPR/CCPA), PCI-DSS, and operational resilience expectations. Ability to negotiate directly with vendors and translate risk findings for non-risk stakeholders. Strong analytical and communication skills. Full professional English proficiency required; Arabic is a plus.
Nice-to-have: Direct BNPL or consumer credit experience, GRC platform experience (OneTrust, ProcessUnity, Archer), or certifications (CTPRP, CRISC, CISA, CISM).