Senior Manager Vendor & Outsourcing Steering
Solaris
Seniority
Senior
Model
In-Office
Sector
Salary
€90,000 – €110,000
Contract
Full-Time
As Senior Manager for Vendor and Outsourcing Management, you will drive outsourcing and third-party risk management initiatives within the 1st Line of Defense (1LoD). You will be responsible for the end-to-end lifecycle management of critical ICT and non-ICT service providers, ensuring full compliance with internal risk appetites and external regulatory frameworks including DORA, EBA AI Act, and MaRisk (AT 9).
What you'll do
- Act as the primary risk owner for assigned third-party vendor relationships, identifying, assessing, and mitigating vendor-related risks in alignment with the bank's enterprise risk management framework.
- Ensure all ICT third-party relationships comply with DORA requirements and maintain the bank's Information Register for all ICT third-party arrangements.
- Oversee the entire vendor lifecycle (initiation, due diligence, onboarding, continuous monitoring, and exit strategies) for critical and important outsourcing functions.
- Establish, negotiate, and monitor strict Service Level Agreements (SLAs) and Key Performance Indicators (KPIs). Conduct regular business reviews with key vendors.
- Partner with Legal and Procurement teams to negotiate vendor contracts, ensuring all regulatory clauses are robustly integrated.
- Collaborate with the 2nd Line of Defense to remediate audit findings and ensure vendors have tested Business Continuity and Disaster Recovery plans in place.
- Act as the central point of contact between internal business owners, external vendors, and control functions. Advise senior management on vendor risk exposure.
What you'll need
- Master's or Bachelor's degree in Business Administration, Information Technology, Finance, Law, or a related discipline.
- 7–10 years of experience in Vendor Management, Third-Party Risk Management (TPRM), Procurement, or IT Service Management within financial services/banking.
- Proven track record working directly within a 1st Line of Defense function, taking ownership of operational processes and associated risks.
- Deep, practical understanding of DORA, EBA Guidelines on Outsourcing, and MaRisk (particularly AT 9).
- Extensive experience negotiating complex IT and business process outsourcing (BPO) contracts, including cloud service agreements.
- Demonstrated ability to lead cross-functional initiatives, influence stakeholders without direct authority, and drive a culture of risk awareness.
- Business fluency in German and English (both written and spoken) is mandatory.
- Strong ability to analyze complex vendor risk assessments, SOC reports, and financial health metrics.
Nice to have
- Industry-recognized certifications in risk management, audit, or service management (e.g., CISM, CISA, CRISC, ITIL, or specialized TPRM certifications).
What they offer
- Competitive salary and variable remuneration program.
- Learning & development budget of €1000 per year with transparent growth framework.
- 28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years.
- Home office budget and opportunity to work abroad for up to 12 weeks per year.
- Monthly meal allowance and Deutschland ticket subsidy.
