Description

About the role

Third-party risk management isn’t a register maintenance exercise. As we scale across 50+ markets in ride-hailing, delivery, micromobility, and financial services, our network of third parties keeps growing, and so does our regulatory exposure. We’re looking for a Senior Outsourcing Manager to own outsourcing and TPRM for Bolt end to end, and help extend that framework across the wider Group.

 

You’ll own outsourcing and third-party risk management for pur  end to end, with a mandate to build and run, not maintain. You’ll design the classification framework, own the vendor lifecycle from due diligence to exit, and ensure Bolt’s most regulated entity can stand behind every arrangement in front of a supervisor.

 

You’ll report into the Director of Procurement and serve as the senior voice on third-party risk for the us, risk and technology functions. You’ll also advise other Bolt Group entities as they mature their own outsourcing governance, where group-wide consistency is needed.

Main tasks and responsibilities

  • Own and evolve the outsourcing and third-party risk framework, including the classification methodology that determines which regulatory requirements apply to each arrangement.
  • Run pre-outsourcing due diligence end to end (risk assessment, sanctions screening, GDPR assessment, conflict of interest checks), own exit strategy design and testing for Critical Function arrangements, and lead ongoing monitoring and re-assessment across the vendor portfolio.
  • Own the outsourcing/vendor register and governance platform, ensuring both are accurate, current, and inspection-ready.
  • Partner with Legal on contracting, embedding required clauses (audit rights, sub-outsourcing controls, exit provisions, incident notification) across new and existing arrangements.
  • Ensure Bolt stays fully aligned with DORA, EBA/GL/2019/02, and related RTS/ITS obligations, supporting engagement with EFSA as needed.
  • Advise other group entities on adapting the framework to their own arrangements, and serve as the senior voice on third-party risk for the Management Board, CRO, and CPTO.

About you

  • Proven track record owning outsourcing, third-party, or vendor risk management inside a regulated EMI, bank, or payment institution.
  • Deep technical command of DORA and EBA outsourcing requirements, including ICT service provider classification and Critical Function determination.
  • Strong experience building or substantially overhauling a governance framework, not just operating one already in place.
  • Comfortable owning a register and GRC platform directly, including the data discipline that keeps both audit-ready.
  • Commercial fluency and the presence to advise the Management Board and CRO directly, explaining a classification decision to a regulator and a business owner in language each one understands.
  • Experience with EBA/CP/2025/12, LogicGate or a comparable GRC platform, standing up a TPRM function from the ground up, or extending a single entity’s risk framework across a multi-entity group are a plus.

Why you’ll love it here:

  • Accelerate your professional growth with unique career opportunities.
  • Enjoy a rewarding salary and stock options, knowing that as we  succeeds, so do you.
  • Take care of your physical and mental health with our wellness perks.
  • Celebrate 5 years  with a 1-month paid sabbatical to recharge.
  • Connect with colleagues at annual company events and smaller team gatherings.
  • Balance flexibility and in-person collaboration with our hybrid model, including at least 12 monthly in-office days.

 

 

Are you interested in this position?

Apply by clicking on the “Apply Now” Button below!

#JobsHubEstonia #GlobalRecrument
#CareerOpportunities #HiringNow
#JobSeekersNetwork #EstoniaJobs
#RecruitmentServices #EmploymentPortal