وصف الوظيفة
تعمل شركات BNPL على سلسلة من البائعين وليس على نظام أساسي واحد فقط — فهم يعتمدون على سلسلة من المزودين: موفرو KYC الذين يجريون اختبارات الهوية خلال أجزاء من الألف في الميللي ثانية، وبيانات المكتب الائتماني تغذي قرارات الاكتتاب، ومعالجات تنقل الأموال عند الخروج، ووكالات التحصيل تلاحق المدفوعات الفائتة نيابة عنا. عندما يفشل أي رابط في تلك السلسلة، لا تكون مجرد إزعاج داخلي — بل عميل لا يستطيع إنهاء الدفع، أو قرار ائتماني مبني على بيانات سيئة، أو regulator يسأل لماذا تعطلت خدمة حاسمة بدون إشعار.
بصفتك مدير مخاطر البائعين، ستتولى برنامج مخاطر الطرف الثالث لدينا من البداية حتى النهاية، من الاستبيان الأول للعناية الواجبة إلى يوم خروج بائع من النظام. ستعامل كالشخص الذي يستطيع إبلاغ القيادة، بلغة واضحة، ما هي البائعون الأكثر خطورة ولماذا، وستتأكد من ألا تتحول فشلات البائعين أبدًا إلى إخفاقات للعملاء.
المسؤوليات الرئيسية
العناية الواجبة والتكامل
- إجراء العناية الواجبة مع البائعين الجدد قبل توقيع العقود، بما في ذلك فحوص الصحة المالية، ومراجعة SOC 2 / ISO 27001، وتاريخ الخرق، وتخطيط المُمثلين الفرعيين.
- إصدار تقييم مخاطر واضح لكل بائع محتمل، مع شروط مرفقة بدلاً من مجرد نجاح/فشل، يشمل KYC، التحقق من الهوية، اكتشاف الاحتيال، مكتب الاعتماد الائتماني، معالجة الدفع، إصدار البطاقات، الخدمات المصرفية، وشركاء التحصيل.
- الجلوس داخل عملية التعاقد مع قسم الشؤون القانونية والمشتريات لتأمين الشروط التي تهم: حقوق التدقيق، نوافذ إشعار الخرق، تعهّدات محلية البيانات، بنود المساعدة على الخروج، واتفاقيات مستوى الخدمة المرتبطة بعقوبات فعلية.
تقييم المخاطر والمراقبة المستمرة- امتلاك تقييم مخاطر البائعين عبر محفظة الطرف الثالث النشطة لدينا، مع إعطاء الأولوية للبائعين الحرجين وعاليي المخاطر لإجراء عُروض عميقة سنوية.
- بناء وتشغيل جداول متابعة متعددة الطبقات — ربع سنوية للبائعين الحرجين مثل KYC، معالجة الدفع، والشركاء المصرفيين، سنوية للباقين — تتبع انحراف الرقابة، تغيّر المُمثلين الفرعيين، والتغطية الإعلامية السلبية.
- الحفاظ على سجل مخاطر التركيز والبائعين الحرجين، والاستعداد لشرح نقاط فشل مفردة، مثل تغطية معظم حجم الاكتتاب من قبل مكتب ائتماني واحد، وما هو خطة الطوارئ فعلاً.
الشراكة عبر الأقسام- العمل مع المنتج قبل تشغيل تكاملات البائع الجديدة — أنت في الغرفة عندما يُقيَّم شريك الخروج من عُملة الدفع أو بائع نموذج الاحتيال، وليس بعد توقيع العقد.
• إعداد تقارير مخاطر البائعين للجنة المخاطر والمجلس، وتحويل فجوات الرقابة والاتجاهات الحادثة إلى قرارات يمكن للقيادة العمل بها.
إبعاد وخروج- إدارة عملية الإبعاد للبائعين الخارجين، تأكيد حذف البيانات، وإلغاء الوصول، واستمرارية الانتقال لأي شيء يواجه العميل.
- التأكد من استكمال الالتزامات التنظيمية والتعاقدية عند الخروج وتوثيقها، خاصة للبائعين المصنفين كحرجين أو مهمين.
المهارات والمعرفة والخبرة
- 3–4 سنوات في إدارة مخاطر الطرف الثالث، مخاطر البائعين، أو المخاطر التشغيلية، ويفضل لدى شركة مدفوعات، مقرض، بنك، أو شركة تقنية مالية حيث فشل البائع له عواقب مباشرة على العملاء أو التنظيم.
- معرفة عملية بـ NIST CSF، ISO 27001، SOC 2، وأدوات التقييم القياسية مثل SIG أو CAIQ — تعرف كيف تقرأ تقرير SOC 2 وتحدد ما ينقصه، لا مجرد حفظه.
- الاطلاع على البيئة التنظيمية التي يقع فيها البائعون: قواعد الائتمان الاستهلاكي، التزامات خصوصية البيانات (GDPR/CCPA اعتمادًا على البصمة)، PCI-DSS لأي شيء يلمس بيانات البطاقة، وتوقعات التعهيد/المرونة التشغيلية للأطراف الثالثة الحيوية.
- الراحة في التفاوض مباشرة مع البائعين — لقد رفضت بنسخة MSA القياسية لمعالج، وجعلت بائع احتيال يلتزم بمستوى SLA حقيقي، وتعرف متى تعني عبارة "سيتابع فريقنا القانوني" أن الصفقة يجب أن تسير.
- القدرة على ترجمة نتائج المخاطر لأشخاص لا يفكرون بمصطلحات المخاطر، بما في ذلك شرح لقيادة تجارية سبب عدم جدوى استخدام بائع KYC أرخص وتأخير الانضمام الذي سيحدث بعد ستة أشهر.
- مهارات تحليلية قوية مع القدرة على تفسير أداء البائعين وبيانات الرقابة لدعم القرارات التشغيلية.
- مهارات اتصال وتفاعل بين الأشخاص ممتازة، مع القدرة على التفاعل بفعالية عبر جميع مستويات المنظمة.
- إتقان كامل للغة الإنجليزية مطلوب؛ العربية ميزة إضافية.
من المستحب وجوده:- خبرة مباشرة في BNPL أو الائتمان الاستهلاكي — عملت مع بيانات المكتب الائتماني، أو تقييمات ائتمانية بديلة
- أو مع وكلاء التحصيل تحديداً.
- خبرة عملية مع منصة GRC مثل OneTrust، ProcessUnity، أو Archer لتقييم سير العمل وجرد البائعين.
- أية شهادات مثل CTPRP، CRISC، CISA، أو CISM.
مرشح مفضل
سنوات الخبرة
5+ سنوات
الدرجة
درجة البكالوريوس / دبلومة متقدمة
Job description
BNPL businesses don't run on a single core system — they run on a chain of vendors: KYC providers doing identity
checks in milliseconds, bureau data feeding underwriting decisions, processors moving money at checkout, and
collections agencies chasing missed payments on our behalf. When any link in that chain fails, it isn't an internal
inconvenience — it's a customer who can't check out, a credit decision made on bad data, or a regulator asking why
a critical service went down with no warning.
As Vendor Risk Manager, you will own our third-party risk program end to end, from the first due diligence
questionnaire to the day a vendor is offboarded. You will be the person who can tell leadership, in plain terms,
which vendors carry the most risk and why, and you will make sure vendor failures never become customer failures.
Key Responsibilities
Due Diligence & Onboarding
- Run due diligence on new vendors before contracts are signed, including financial health checks, SOC 2 / ISO 27001 review, breach history, and subprocessor mapping.
- Issue a clear risk rating for every prospective vendor, with conditions attached rather than a simple pass or
fail, covering KYC, identity verification, fraud detection, credit bureau, payment processing, card issuing,
banking, and collections partners. - Sit inside the contracting process with Legal and Procurement to secure the terms that matter: audit rights,
breach notification windows, data localization commitments, exit assistance clauses, and SLAs tied to real penalties.
Risk Assessment & Ongoing Monitoring- Own vendor risk assessments across our active third-party portfolio, prioritizing critical and high-risk vendors for annual deep-dive reviews.
- Build and run tiered monitoring cadences — quarterly for critical vendors such as KYC, payment processing, and banking partners, annual for the rest — tracking control drift, subprocessor changes, and
adverse media. - Maintain the concentration risk and critical-vendor register, and be ready to explain single points of failure, such as one bureau covering the majority of underwriting volume, and what the contingency plan actually
is.
Cross-Functional Partnership- Work with Product before new vendor integrations go live — you're in the room when a new checkout partner or fraud model vendor is being evaluated, not brought in after the contract is signed.
• Prepare vendor risk reporting for the Risk Committee and Board, translating control gaps and incident
trends into decisions leadership can act on.
Offboarding & Exit Management- Manage the offboarding process for exited vendors, confirming data deletion, access revocation, and transition continuity for anything customer-facing.
- Ensure regulatory and contractual exit obligations are met and documented, particularly for vendors
classified as critical or important.
Skills, Knowledge & Expertise
- 3–4 years in third-party risk management, vendor risk, or operational risk, ideally at a payments company, lender, bank, or fintech where vendor failure has direct customer or regulatory consequences.
- Working knowledge of NIST CSF, ISO 27001, SOC 2, and standardized assessment tools like SIG or
CAIQ — you know how to read a SOC 2 report and spot what's missing, not just file it away. - Familiarity with the regulatory landscape vendors sit inside: consumer credit rules, data privacy obligations
(GDPR/CCPA depending on footprint), PCI-DSS for anything touching card data, and
outsourcing/operational resilience expectations for critical third parties. - Comfort negotiating directly with vendors — you've pushed back on a processor's standard MSA, gotten a
fraud vendor to commit to a real SLA, and know when “our legal team will follow up” means the deal
needs to walk. - Ability to translate risk findings for people who don't think in risk terms, including explaining to a
commercial lead why a cheaper KYC vendor isn't worth the onboarding delay it will cause six months later. - Strong analytical skills with the ability to interpret vendor performance and control data to support
operational decisions. - Excellent communication and interpersonal skills, with the ability to interact effectively across all levels of
the organization. - Full professional proficiency in English required; Arabic is a plus.
Nice to have:- Direct BNPL or consumer credit experience — you've worked with bureau data, alternative credit scoring
- vendors, or collections agencies specifically.
- Hands-on experience with a GRC platform such as OneTrust, ProcessUnity, or Archer for assessment
- workflows and vendor inventory.
- CTPRP, CRISC, CISA, or CISM certification.
Preferred candidate
Years of experience
5+ years
Degree
Bachelor's degree / higher diploma