Manager Business Risk & Compliance (Mainz, RP, DE, 55131)
About this opportunity
Mainz, Germany | full time | Job ID: 11707
About the role:
As Manager Business Risk & Compliance, you will play a pivotal role in strengthening Cyber and Information Security across BioNTech’s Corporate Functions. Acting as the central interface between Cyber & Information Security (C&IS) and business functions, you will ensure cybersecurity requirements are understood, embedded, and managed effectively across processes, projects, and third-party engagements. You will drive a risk-based and business-oriented security approach by partnering closely with stakeholders while ensuring alignment with internal policies, regulatory requirements, and industry standards.
Your contribution:
Serve as the primary business partner for Corporate Functions, acting as the central contact for cyber and information security topics
Build trusted relationships to embed ISMS requirements into processes, initiatives, projects, and decision-making
Translate governance requirements into practical guidance relevant to Corporate Functions
Support business units in identifying and managing cyber risks while defining mitigation measures
Oversee third-party security risk management, including supplier assessments and contract reviews in collaboration with Procurement, Legal, Data Privacy, and other stakeholders
Manage security oversight of strategic external partners to ensure alignment with BioNTech’s security expectations
Contribute to improving C&IS Governance Frameworks, policies, procedures, and ISMS processes based on emerging risks
Prepare for internal and external audits in information security, including ISO 27001 certification audits
Promote collaboration and accountability to foster a strong security culture
A good match:
University degree in cybersecurity, IT-related fields or equivalent vocational training
Professional experience in cybersecurity or related roles such as IT risk or governance
Strong understanding of information security governance frameworks like ISO 27001 or NIST standards
Experience with third-party risk management and vendor governance processes
Certifications such as CISM, CRISC, CISSP are advantageous
Proficiency in GRC tools integration into business processes
Analytical thinking paired with problem-solving skills
Excellent communication skills; proficiency in English (spoken & written), German is a plus
Your Benefits:
It's our priority to support you:
Your flexibility: flexible hours | vacation account
Your growth: Digital Learning | Performance & talent development | leadership development | Apprenticeships | LinkedIn Learning
Your value: Your voice at the table | Culture on an equal footing | Opportunities to shape & impact | Support for your full potential
Your health and lifestyle: Company bike
Your mobility: Job ticket | Deutschlandticket
Your life phases: Employer-funded pension | Childcare
Apply now - We look forward to your application!
Apply to our Mainz, Germany location by sending us your documents via our online form. For any questions, contact our talent acquisition team on: + 49 (0) 6131-9084-1291 (Monday-Friday from 1 PM to 3 PM CET).
Job ID 11707 (please always specify if you have any questions)
By submitting your application, you acknowledge that a background check will be conducted as part of the recruitment process in accordance with applicable laws and regulations. If you are considered for the position, BioNTech will conduct the background check through our service provider ‘HireRight’. You will be informed accordingly by your BioNTech-Recruiter.
]]>
Job details
How this role compares
Computed from every other active Other / Corporate Functions role in our database, not just this employer's listings.
We don't have enough classified peer data for this role yet, so there's no comparison to show. This happens when a posting's title/category doesn't match any taxonomy rule -- it's excluded rather than compared against the wrong peer group.
Notify me about similar jobs
Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.