Job Description
Cyber Security M&A Risk Manager (m/f/d)
LOCATION

LOCATION

COMPANY

COMPANY

JOB FIELD

JOB FIELD


JOB TYPE


JOB TYPE

JOB ID


JOB ID


FLEXIBLE WORK OPTIONS


FLEXIBLE WORK OPTIONS

LOCATION

LOCATION


COMPANY

COMPANY


JOB FIELD

JOB FIELD


JOB TYPE

JOB TYPE


JOB ID

JOB ID


FLEXIBLE WORK OPTIONS

FLEXIBLE WORK OPTIONS

WELCOME TO BASF

At BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF´s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people working and learning together. Become part of our team and develop the future with us - in a global team that embraces diversity and equal opportunities.

You will be a part of our Cyber Governance, Risk and Compliance Team, which manages the Cyber Security Framework for the whole BASF Group. In this role, you will work closely with Corporate M&A, Legal, Data Privacy, IT, business units, and transaction teams to assess and manage cyber security risks in Corporate M&A Projects (Investments/Divestitures).

RESPONSIBILITIES

  • Analyzing investments and divestitures from a cyber security perspective throughout the M&A lifecycle, from initial assessment and due diligence through signing, closing, integration, or separation, as well as participation in Post-Merger Audits.
  • Identifying, assessing, and prioritizing cyber security risks of target companies, joint ventures, and divested businesses, and defining appropriate controls and mitigation measures based on the transaction context.
  • Evaluating the cyber security posture of relevant organizations, systems, assets, infrastructure, applications, cloud services, data, third parties, and operational technology, where applicable, using a risk-based approach.
  • Collaborating closely with Corporate M&A, Legal, Data Privacy, IT, business representatives, and external advisors to ensure that cyber security considerations are reflected in transaction decisions and contractual arrangements.
  • Facilitating cyber security due diligence assessments, risk workshops, threat analyses, and targeted vulnerability assessments to identify material risks, dependencies, and potential deal impacts.
  • Maintaining deal-specific cyber security risk registers and associated risk treatment plans, including clear ownership, priorities, target dates, and escalation of material or residual risks.
  • Providing cyber security GRC guidance for Day-1 readiness, integration, carve-out and separation activities, transition service arrangements, and the implementation or transfer of required security controls.

QUALIFICATIONS

  • Bachelor’s degree in Business Management, Information Technology, Cyber Security, or a related field
  • 4-7 years of relevant work experience
  • Experience in cyber security, particularly in cyber security governance, risk management, and compliance and Project Management; experience in M&A, investments, divestitures, or corporate transactions is highly desirable
  • Strong understanding of cyber security risk management principles and the ability to translate technical findings into business, financial, contractual, and transaction-related risk implications
  • Experience with cyber security due diligence, risk assessments, threat modeling, vulnerability assessments, and the evaluation of complex IT, cloud, third-party, and operational technology environments
  • Knowledge of relevant laws, regulations, and industry standards related to cyber security, including their application within international transactions
  • Experience in project management, M&A integration or separation, transition service arrangements, or cyber security remediation programs is a plus.
  • Passion for working in an international, cross-functional, and transaction-driven environment, including the ability to manage sensitive information and competing priorities
  • Experience in Communications with Senior Management and defend Due Diligence findings
  • Excellent communication and interpersonal skills, with the ability to work effectively with interdisciplinary teams and present cyber security risks clearly to technical stakeholders, business leaders, and decision-makers
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor, or comparable qualifications are a plus
  • Confident communication in English, both spoken and written.

WHAT WE OFFER

  • A secure work environment because your health, safety and wellbeing is always our top priority.
  • Flexible work schedule and Home-office options, so that you can balance your working life and private life.
  • Learning and development opportunities
  • 25 holiday days per year
  • 5 additional days (readjustment)
  • A collaborative, trustful and innovative work environment
  • Being part of an international team and work in global projects
  • Relocation assistance to Madrid provided

At BASF, the chemistry is right

Because we are counting on innovative solutions, sustainable actions, connected thinking and on you, become a part of our formula for success and develop the future with us - in a global team that embraces diversity and equal opportunities irrespective of gender, age, origin, sexual orientation, disability or belief.At BASF, we are committed to upholding and ensuring compliance with company standards related to quality, environment, health, safety, and energy, in line with our global guidelines.We actively promote a culture of prevention and continuous improvement, encouraging collaboration in initiatives related to quality, environmental protection, health, safety, and energy performance.We foster responsible energy use, promoting efficiency in daily operations and supporting the identification of improvement projects and energy-saving opportunities
 

Madrid, ESP
BASF Digital Solutions S.L.
Digitalization
Permanent
144664
IT and Digitalization
Spain
Work model:  Hybrid