MVB Bank

Chief Information Security Officer (CISO)


PayCompetitive
LocationRemote
Employment typeFull-Time

This job is now closed

  • Job Description

      Req#: CHIEF001958

      ABOUT US

      Here at MVB, our company culture defines the environment in which Team Members thrive. Our culture impacts a wide range of elements, including our purpose, values, expectations and goals that support growth and engagement – it is the secret sauce of our organization!

      Our values live at the core of all that we do – Trust, Commitment, Teamwork, Adaptive, Respect, Love and Caring are our foundation for success. We are committed to fostering an environment focused on diversity, equity and inclusion, and we welcome Team Members from all walks of life. Join Team MVB today!

      MVB Financial Corp. (“MVB Financial” or “MVB”), the innovative financial holding company of MVB Bank, Inc., is publicly traded on The Nasdaq Capital Market® under the ticker “MVBF.” Through its subsidiary, MVB Bank, Inc., (“MVB Bank”) and the bank’s subsidiaries, MVB provides services to individuals and corporate clients in the Mid-Atlantic region, as well as to Fintech, Payment and Gaming clients throughout the United States. For more information about MVB, please visit www.mvbbanking.com.

      This role can be based remotely.

      Candidates must reside in one of the following states: West Virginia, Virginia, Texas, Florida, Ohio, Pennsylvania, Maryland, Washington D.C., New York, New Jersey, Arkansas, Alabama, Arizona, Delaware, Indiana, North Carolina, Georgia.

      ABOUT THE ROLE

      The Chief Information Security Officer (CISO) position is responsible for establishing and maintaining a company-wide information security management program to ensure that information assets are adequately protected. Additionally, this position will assess current cyber security capabilities, identify opportunities to fortify current capabilities, and lead the efforts to implement the actions needed to elevate the organization’s security capabilities. The CSIO will also maintain a corporate-wide security awareness strategy and coordinate centralized technologies and reporting to support vulnerability and fraud awareness, prevention, and detection.

      WHAT YOU’LL DO

      • Lead team in the risk analysis for corporate functional and technical areas relevant to information security.
      • Co-Chair of the Technology Council to ensure proper IT governance in place and that senior leadership is aware of real-world threats, mitigation protections as well as KPI reporting to document the health of the security program.
      • Make recommendations to management on enhancements to existing and new security hardware, software or related tools. Assist in evaluating, planning, configuration, and implementation of new/existing security applications/tools.
      • Facilitate audit coordination with external auditors, regulators as well as internal teams.
      • Implement, monitor, and support security software/systems that will help ensure compliance with regulatory, industry, and corporate policies and procedures. This includes but is not limited to all network related infrastructure, application, database, storage, log management/correlation, secure password storage/retrieval, vulnerability management, etc.
      • Ensure security best practices are identified and integrated into all facets of the project including network, system designs/configuration, and implementations.
      • Identify and recommend potential areas where existing data security policies and procedures require change, or where a supplement is required to mitigate key security risks. Partner with various business areas to enhance security policies/procedures.
      • Facilitate internal and external penetration testing and audit participation with internal and external parties.
      • Recommend and enforce technical service level standards and procedures for information security.
      • Familiar with DLP solutions and protection strategies of corporate information assets.
      • Responsible for the BCM program that will establish alternative security measures to allow for business resiliency while protecting the company’s assets.
      • Leads the Incident Response Team in the identification, response, investigation, and remediation of potential breaches and events surrounding security.
      • Responsible for executing programs for user awareness, compliance monitoring, and security compliance; maintaining information security devices and software; monitoring compliance procedures; and resolving security policy issues.
      • Identifying, evaluating and reporting on information security risks in a manner that meets compliance and regulatory requirements (i.e.: Personally Identifiable Information (PII), Payment Card Industry (PCI), Data Privacy, GLBA, etc.).
      • Ensuring that all information security policies, processes, and procedures are well defined, documented, communicated and published appropriately.
      • Oversee the third-party risk management program, building relationships with 3rd party providers of IT infrastructure and security monitoring tools to ensure assets are being properly protected.

      EDUCATION & WORK EXPERIENCE

      • Bachelor’s degree in business administration or a technology-related field, or equivalent work or education related experience.
      • 15 years of experience in information security with at least 5 years in a senior level role with previous people leadership experience.
      • Knowledge and understanding of relevant legal and regulatory requirements such as Personally Identifiable Information (PII) Protection, CCPA, and Payment Card Industry (PCI)/Data Security Standard requirements.
      • Demonstrated ability to lead and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals.
      • Experience with Financial Institutions, national security and privacy regulations desired.
      • Must hold at least one professional security management certification such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials, is desired.
      • Knowledge of common information technology management frameworks such as ISO/IEC 27001, ITIL, COBIT, PCI, FFIEC, GLBA, CSF, and NIST.
      • Project management, financial/budget management, and resource management skills
      • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.

      BENEFITS AT MVB

      MVB Financial Corp., (“MVB”) offers an excellent selection of benefits for regular, part-time and full-time Team Members, including:

      • Medical, Dental and Vision Insurance
      • Health Savings Account (HSA), Health Reimbursement Account (HRA) & Flexible Spending Accounts (FSA)
      • Short- and Long-Term Disability Plan
      • Group Life Insurance
      • 401K Salary Deferral Plan
      • Wellness Program
      • Education & Tuition Expense Reimbursement
      • PTO and Unique Vacation Purchase Program
      • Nationwide Pet Insurance Coverage

      #LI-Remote

      We encourage you to submit an application even if you haven’t performed every job duty listed above, as your skills may be transferrable. MVB is looking for ambitious individuals with related knowledge, understanding and abilities who are willing to learn and grow. What we care about most is allowing you to develop and, in return, you help us become a stronger, more diverse and well-rounded organization.

      Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

      The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)

  • About the company

      MVB is your trusted partner on the financial frontier, powering your potential and helping you reach your financial goals.