Senior Manager Vendor & Outsourcing Steering
Job description
About the role
You will act as the primary risk owner for critical third-party vendor relationships, identifying, assessing, and mitigating vendor-related risks in alignment with the bank's enterprise risk management framework. You will ensure all ICT third-party relationships comply with DORA requirements, maintaining the bank's Information Register for all ICT third-party arrangements and ensuring appropriate contractual provisions are implemented and monitored. You will oversee the entire vendor lifecycle (initiation, due diligence, onboarding, continuous monitoring, and exit strategies) for critical and important outsourcing functions according to applicable guidelines. You will establish, negotiate, and monitor strict Service Level Agreements (SLAs) and Key Performance Indicators (KPIs), conducting regular business reviews with key vendors to drive performance and resolve operational issues. You will partner with Legal and Procurement teams to negotiate vendor contracts, ensuring all regulatory clauses (e.g., audit rights, sub-outsourcing restrictions, data protection, and exit plans) are robustly integrated. You will collaborate closely with the 2nd Line of Defense (Risk, Compliance, InfoSec) to remediate audit findings, ensuring vendors have tested and proven Business Continuity and Disaster Recovery plans in place. You will act as the central point of contact between internal business owners, external vendors, and 2nd/3rd line control functions, advising senior management on vendor risk exposure and strategic sourcing decisions.
Key facts
What you'll do
Perform 1st Line of Defense Ownership for assigned third-party vendor relationships, identifying, assessing, and mitigating vendor-related risks in alignment with the bank's enterprise risk management framework.
Ensure full compliance with DORA requirements for all ICT third-party relationships, maintaining the bank's Information Register for all ICT third-party arrangements and ensuring appropriate contractual provisions are implemented and monitored.
Oversee the complete outsourcing lifecycle, including initiation, due diligence, onboarding, continuous monitoring, and exit strategies for critical and important outsourcing functions according to applicable guidelines.
Establish, negotiate, and monitor strict Service Level Agreements (SLAs) and Key Performance Indicators (KPIs), conducting regular business reviews with key vendors to drive performance and resolve operational issues.
Partner with Legal and Procurement teams to negotiate vendor contracts, embedding robust regulatory clauses related to audit rights, sub-outsourcing restrictions, data protection, and exit plans.
Collaborate closely with the 2nd Line of Defense (Risk, Compliance, InfoSec) to remediate audit findings and ensure vendors maintain tested and proven Business Continuity and Disaster Recovery plans.
Act as the central point of contact between internal business owners, external vendors, and 2nd/3rd line control functions, advising senior management on vendor risk exposure and strategic sourcing decisions.
Monitor vendor performance against SLAs and KPIs, escalating issues as required and driving continuous improvement initiatives across critical vendor ecosystems.
Coordinate due diligence activities for new vendors, assessing financial stability, operational resilience, and regulatory compliance before onboarding.
Maintain detailed records of all vendor interactions, assessments, and decisions to ensure audit readiness and transparency across the vendor ecosystem.
Support the implementation of emerging regulatory frameworks, including the EBA AI Act and Outsourcing related regulation MaRisk (AT 9), ensuring proactive adaptation of controls.
Lead cross-functional initiatives to enhance vendor risk management practices, influencing stakeholders without direct authority and promoting a culture of risk awareness.
Requirements
Master's or Bachelor's degree in Business Administration, Information Technology, Finance, Law, or a related discipline.
7-10 years of experience in Vendor Management, Third-Party Risk Management (TPRM), Procurement, or IT Service Management within the financial services/banking sector.
Proven track record working directly within a 1st Line of Defense function, taking ownership of operational processes and the associated risks.
Deep, practical understanding of European and German banking regulations regarding outsourcing and IT security. Specifically: DORA, EBA Guidelines on Outsourcing, MaRisk (particularly AT 9).
Extensive experience in negotiating complex IT and business process outsourcing (BPO) contracts, including cloud service agreements (SaaS, PaaS, IaaS).
Demonstrated ability to lead cross-functional initiatives, influence stakeholders without direct authority, and drive a culture of risk awareness across the organization.
Strong analytical and problem-solving skills, with the ability to interpret regulatory requirements and translate them into actionable controls for vendor relationships.
Excellent communication and presentation skills, enabling clear and concise reporting to senior management and stakeholders at all levels.