Welcome to the team: Senior Governance, Third-Party Risk & Vendor Manager (m/f/diverse)

Your tasks
1. 3rd Party Risk Coordination & Governance:
- Coordinating that all relevant vendors and services are correctly registered, assessed and maintained in the 3rd party risk platform;
- Guiding and supporting product owners and business stakeholders through the 3rd party risk process (e.g. initial risk assessment, due diligence, periodic reviews), ensuring all required information is provided on time and in good quality;
- Acting as the operational interface to the internal 3rd party risk department: tracking requests, clarifying requirements and coordinating responses and follow-up actions;;
- Monitoring the status of risk assessments and reviews in the platform, proactively following up on delays, missing inputs and required approvals;
- Ensuring documentation consistency and traceability in the 3rd party risk platform to meet internal and regulatory audit requirements;
- Supporting the continuous improvement of workflows, templates and guidance related to 3rd party risk and the platform.
2. Contract Lifecycle & Process Coordination:
- Coordinating the end-to-end contract lifecycle for external providers: from initial request and requirements collection through drafting, review, approval and signature;
- Acting as a central point of contact and “process owner” between Business, Procurement, Legal, 3rd party risk and other functions, ensuring all procedural steps and approvals are followed;
- Consolidating input from product owners (scope, requirements, SLAs, risk/compliance aspects) and ensuring it is reflected in contracts and supporting documentation;
- Tracking and reporting contract status, milestones and dependencies; identifying and resolving bottlenecks, escalating when needed to keep timelines on track;
- Ensuring contracts and related documents are stored, updated and linked correctly (e.g. to the 3rd party risk platform and contract repositories).
3. Stakeholder & Vendor Governance:
- Maintaining transparency on key 3rd party relationships from a governance and process perspective (risk status, contract status, key dates);
- Supporting or coordinating governance meetings with internal stakeholders and, where needed, with vendors on risk, compliance and contractual topics;
- Building strong working relationships with product owners, Procurement, Legal, Risk and Compliance to foster a consistent and efficient way of working.
Your profile
- Understanding of frameworks, standards, and regulatory requirements; ability to identify and address compliance risks.
- Proven experience in managing vendors, monitoring service quality.
- Knowledge and experience in vendor contracting processes, negotiation, and risk protection.
- Proactive in identifying and solving problems; capable of developing innovative solutions.
- Customer-focused approach to delivering results in alignment with stakeholder needs.
- Skilled in analyzing documentation, contract terms, or compliance measures to identify risks and improve processes.
In return, we offer:
- Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
- Luxury package of additional health and dental insurance;
- Food vouchers in the amount of EUR 80 monthly;
- 6 additional annual days off for exceptional circumstances
- Employee assistance program for psychological, financial and legal consultations;
- Multisport card;
- Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
- Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
- Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
- Friendly and supportive multicultural environment, open to new opinions and ideas.
Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.
Our Benefits
Learning Platforms; Children Summer Camp Contribution; Employee assistance program; Food vouchers; 6 Exceptional Days Off; 25 up to 31 annual paid leave; Multisport Card; Health& Dental Insurance; Work-life balance; Work internationally
The company
Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.
As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Senior Governance, Third-Party Risk & Vendor Manager in our Cyber Defense and Base Services team.
Cluster CyberDefense & Base Infrastructure provides 1. LoD activities within the Commerzbank Cyber Security Organization. In addition to these operational topics the cluster also develops and operates a variety of security tools which are used by the operational units SOC and Threat Intelligence.
In the Cluster Organization, business analysts, engineers and product owners work together as a team. The agile methods support the team members in performing their functions by facilitating a rapid and flexible response to changing conditions and customer needs through an iterative approach and the continual development of new solutions resulting into better products, higher quality and more efficient processes.
The Senior Governance, 3rd Party Risk & Vendor Manager plays a central role in managing the governance and coordination of 3rd party relationships. The role focuses on ensuring that all external providers are properly captured and maintained in the 3rd party risk platform and on coordinating the end to end contract process, acting as the key bridge between Business (product owners), Procurement, the 3rd party risk function, and other stakeholders.
This position requires strong experience in 3rd party risk/governance, excellent organisational and coordination skills, and the ability to guide stakeholders through defined processes in a structured and pragmatic way.
Contact
Apply now with your up-to-date CV in English!
Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.

