Vendor Delivery Manager

DeblockPorto, PortoOn-siteFull-timeMid level, 2–5 yearsListed 8 hours ago

Apply now

About this role

Deblock is building out its operational resilience capability, and third-party and ICT risk sits at the centre of it.
In this role you'll strengthen and scale the framework that governs how we select, assess and monitor the providers our services depend on, under DORA, and the wider regulatory expectations that apply to a regulated EMI and crypto-asset service provider.

You'll work across Compliance, Risk, Technology and Operations, turning regulatory requirements into controls that people actually run day to day. The work rewards someone who can hold a supervisor's perspective and a pragmatic one at the same time: the framework has to stand up to scrutiny and survive contact with a company that is still growing fast.

We want to revolutionise the FinTech industry. Create a new paradigm. And we need the best minds to do it 🧠 🚀

🧑‍💻 What You'll Be Working On

- Strengthening our third-party and ICT risk framework, and the policies, procedures and governance standards that sit underneath it
- Running due diligence on providers across operational, ICT, compliance and financial risk, and challenging assessments where the evidence doesn't hold
- Owning the register of outsourcing and ICT third-party arrangements, and the regulatory information it has to carry
- Monitoring provider performance, incidents and concentration risk on an ongoing basis, and escalating what matters
- Building the KRIs, dashboards and reporting that give management and the board a real view of third-party exposure
- Mapping critical or important functions and the dependencies behind them, including exit strategies and substitutability
- Supporting DORA implementation across contractual requirements, the register of information, and incident and resilience testing obligations

Requirements

Assuming you want this section pushed further from the original shape — here it is restructured under themes, which changes how it reads on the page more than any amount of reworded bullets.

🧑‍💻 What You'll Be Working On

Understanding what we depend on

- Mapping our critical and important functions and the provider dependencies sitting behind them, including substitutability and exit planning
- Keeping the register of outsourcing and ICT third-party arrangements complete, current and carrying the information regulators expect to find in it

Deciding who we work with

- Assessing providers across operational, ICT, compliance and financial risk before we commit — and pushing back when the evidence doesn't support the conclusion
- Making sure contractual arrangements carry the provisions DORA requires, and that new arrangements clear governance before they go live

Watching what happens next

- Tracking provider performance, incidents and concentration risk once arrangements are running, and escalating what genuinely needs a decision
- Turning that into KRIs and reporting that give management and the board a real picture of third-party exposure rather than a compliance artefact

Making it hold

Evolving the policies, procedures and governance standards that keep all of the above repeatable as we grow

Supporting the wider DORA programme, including the register of information and incident and resilience testing obligations

Benefits

- Competitive salary and a stock options sign-on bonus
- The best tech for your job
- 30 days of paid holidays
- Possibility to work from home in a hybrid setting
- Ability to work abroad for 4 months a year