About this role
Job title: Manager Business Risk & Compliance
About the role
As Manager Business Risk & Compliance, you will play a pivotal role in strengthening Cyber and Information Security across BioNTech’s Corporate Functions. Acting as the central interface between Cyber & Information Security (C&IS) and business functions, you will ensure cybersecurity requirements are understood, embedded, and managed effectively across processes, projects, and third-party engagements. You will drive a risk-based and business-oriented security approach by partnering closely with stakeholders while ensuring alignment with internal policies, regulatory requirements, and industry standards.
Your contribution
- Serve as the primary business partner for Corporate Functions, acting as the central contact for cyber and information security topics
- Build trusted relationships to embed ISMS requirements into processes, initiatives, projects, and decision-making
- Translate governance requirements into practical guidance relevant to Corporate Functions
- Support business units in identifying and managing cyber risks while defining mitigation measures
- Oversee third-party security risk management, including supplier assessments and contract reviews in collaboration with Procurement, Legal, Data Privacy, and other stakeholders
- Manage security oversight of strategic external partners to ensure alignment with BioNTech’s security expectations
- Contribute to improving C&IS Governance Frameworks, policies, procedures, and ISMS processes based on emerging risks
- Prepare for internal and external audits in information security, including ISO 27001 certification audits
- Promote collaboration and accountability to foster a strong security culture
A good match
- University degree in cybersecurity, IT-related fields or equivalent vocational training
- Professional experience in cybersecurity or related roles such as IT risk or governance
- Strong understanding of information security governance frameworks like ISO 27001 or NIST standards
- Experience with third-party risk management and vendor governance processes
- Certifications such as CISM, CRISC, CISSP are advantageous
- Proficiency in GRC tools integration into business processes
- Analytical thinking paired with problem-solving skills
- Excellent communication skills; proficiency in English (spoken & written), German is a plus
Your Benefits It's our priority to support you:
- Your flexibility: flexible hours | vacation account
- Your growth: Digital Learning | Performance & talent development | leadership development | Apprenticeships | LinkedIn Learning
- Your value: Your voice at the table | Culture on an equal footing | Opportunities to shape & impact | Support for your full potential
- Your health and lifestyle: Company bike
- Your mobility: Job ticket | Deutschlandticket
- Your life phases: Employer-funded pension | Childcare