P&T
·
Espoo, London
·
Fully Remote
Vendor and Outsourcing Manager
About The Role:
- As a Vendor and Outsourcing Manager at Enfuce, you will lead the vendor lifecycle management process, ensuring that all third-party partnerships support our business goals with a strong focus on compliance, service performance, data security, and strategic alignment. While we retain full control of core services such as payment processing and card issuing, you will be responsible for managing partners that support our operations in areas like technology enablement, compliance tooling, customer onboarding support and other non-core services.
- You’ll work cross-functionally with teams across Product, IT and Security, Legal, Risk, and Compliance to ensure that every external relationship meets Enfuce’s rigorous standards for operational resilience, regulatory compliance and service excellence.
- This role reports to the Head of IT and Information Security with dotted-line accountability to Risk and Compliance leadership and regular involvement in regulatory audits and governance forums.
What You'll Be Doing:
- As a Vendor & Outsourcing Manager you will be responsible for ensuring that Enfuce’s third-party partnerships are secure compliant and strategically aligned. You’ll work across the business to manage the full vendor lifecycle and help embed resilience into our outsourced services.
Key Responsibilities:
- Lead and execute due diligence and risk classification for new and existing partners.
- Maintain an up-to-date, audit-ready outsourcing and partner register.
- Evaluate third parties against internal controls and regulatory frameworks, including:
- EBA Guidelines on Outsourcing
- DORA (Digital Operational Resilience Act)
- UK FCA/PRA outsourcing guidance
- PCI DSS, ISO/IEC 27001, GDPR, Fin-FSA and DNB standards
Collaborate with Legal, Risk, and InfoSec to ensure contracts include:
- Audit and access rights
- Subcontractor restrictions
- Data protection clauses
- Exit strategies and SLAs
- Conduct structured vendor risk assessments, periodic audits and performance reviews.
- Act as a primary liaison during regulatory reviews, vendor-related incidents or operational changes.
- Facilitate onboarding and handover processes to internal teams with clearly defined management plans.
- Proactively manage remediation plans and escalation paths in case of vendor performance issues or non-compliance.
- Participate in vendor governance forums and support reporting to executive leadership and regulators.
Successful Vendor Onboarding Includes:
- Coordinating initial risk classification and compliance reviews.
- Ensuring documentation completeness (e.g., contracts, SLAs, DPIAs).
- Validating that all security and technical due diligence steps are completed.
- Aligning onboarding activities with both internal policies and external regulatory expectations.
- Facilitating smooth handover to operational teams with clear vendor management plans.
What you'll bring:
We're looking for someone with the expertise, mindset and regulatory awareness needed to manage vendor relationships in a complex fast-moving environment. Skills & Experience You’ll Need:
- Proven experience in fintech, payments or banking operations particularly in regulated environments.
- In-depth understanding of outsourcing and third-party risk regulations, such as:
- EBA Guidelines on Outsourcing.
- UK FCA/PRA Third-Party Risk Management.
- DNB and Fin-FSA supervisory requirements.
- DORA, GDPR, and PCI DSS.
- Familiarity with vendor risk management frameworks, including classification, risk scoring, and ongoing monitoring.
- Strong cross-functional collaboration skills, with experience working alongside Legal, Procurement, Risk and Compliance and Information Security teams.
- Ability to communicate and negotiate confidently with external vendors and internal stakeholders.
- Detail oriented, organised and able to manage multiple vendors and projects simultaneously in a fast paced environment.
- Conducting structured risk assessments and due diligence based on criticality.
- Ensuring contractual safeguards are in place (e.g. audit rights, data protection, SLAs, exit terms).
- Aligning onboarding processes with regulatory expectations and internal policies.
- Coordinating with IT and Security to validate technical controls and data handling.
- Establishing clear handover plans and performance tracking mechanisms post onboarding.
Skills & Experience:
- Solid experience in vendor/partner management particularly in fintech, payments or regulated financial services.
- Strong knowledge of third-party risk and outsourcing regulations, including:
- EBA Guidelines, FCA/PRA expectations
- DORA, GDPR, PCI DSS
- DNB and Fin-FSA supervisory requirements
- Familiarity with vendor risk management frameworks, including scoring, tiering, and monitoring.
- Ability to coordinate across cross-functional teams (Legal, InfoSec, Product, Risk, Procurement).
- Strong interpersonal and negotiation skills with internal and external stakeholders.
- Hands-on experience in managing:
- Risk and compliance reviews
- Due diligence documentation
- Technical control validation with IT/Security
- SLAs, contract lifecycle, and offboarding
- Familiarity with vendor risk management (VRM) and GRC tools (e.g. ProcessUnity).
- Comfort working with documentation systems, compliance tracking, and audit tooling.
Why You’ll Love Working At Enfuce
- High autonomy & ownership: We give you the freedom to own your work and trust you to make the best decisions for your projects.
- Top-tier talent: Join a team of industry experts and highly skilled professionals who are as passionate as you are about innovation.
- Unlimited growth potential: We support your ambition with plenty of room for personal and professional growth within the company.
- Flexible, remote work: Work from anywhere up to 30 days, in an environment that values flexibility and work-life balance.
- A supportive culture: You’ll be part of a team that encourages, motivates, and celebrates success together.
Comprehensive benefits package: We take care of our people with great benefits to match the value you bring.
Fair pay and employee stock option:
- We value the input of every employee and want you to tap into the growth we build together. That’s why our salaries are competitive and reassessed regularly, and you have access to an employee stock option program.
Flexible Paid Time Off:
- We offer a flexible paid time off policy, providing up to 5 weeks of annual vacation days and paid family leave (subject to country regulations). Additionally, you can benefit from hybrid or remote work options, promoting a healthy work-life balance.
Regular Fun With Your Team:
- To spend other than work-related time with your teammates, you get a team activity budget for three quarters a year. The fourth quarter is reserved for a company-wide event.
Individual Learning Budget:
- You get a yearly learning budget to use for courses and other relevant learning opportunities that help you develop your skills.
About Enfuce
- Founded in 2016, Enfuce is a female-founded and led company with a unique vision: to bring the brightest minds and the best technology together to break down the barriers to prosperity.
- As a leading global card issuer and payment processor that merges innovation, security, and expertise to create modular, cloud-based payment processing capabilities, Enfuce is one of Finland’s most valuable scaleups, and is the first financial service provider in the world to be PCI-DSS certified while running its service in the public cloud.
- By focusing on collaboration, Enfuce is able to efficiently provide customers with cutting edge features – offering in-house experts and white labelled technology to help companies create scalable payment solutions with ease. Supporting debit, credit, prepaid, gift, fleet, and fuel card programmes in any form – for consumer, commercial, and B2B applications. Enfuce’s no-nonsense approach helps customers create bespoke payment solutions that are flexible, scalable, and secure.
- Holding an Electronic Money Institution (EMI) licence from the Finnish FSA and from the UK’s Financial Conduct Authority (FCA), enabling operations across Europe and the UK, Enfuce’s PCI-DSS certified platform guarantees 99.999% uptime, global scalability, and card scheme connectivity, supporting various card programmes and integration with digital wallets.
- Enfuce has raised €68.5 million in funding rounds, showcasing its industry leadership with recognitions like Visa Fintech Fast Track and Mastercard Lighthouse Development Program participation, as well as winning prestigious awards, such as the 2019 PayTech Award for Best Payments Solution, 2022 FF Award for Mobile Payments and the 2023 FF Award for Authentic ESG. Propelled by the forward-looking vision of its Co-CEOs and Nordic ingenuity, Enfuce is set to expand globally, shaping the future of payment solutions.
Founded in
2016
Co-workers
About 130 and growing!