Emmanuel K. Prempeh, Bsc., Cisa, Cism Email and Phone Number
• TPRM Subject matter expert (SME) and licensed Third-Party compliance manager with 10+ years expertise in Vendor Risk Management.• IT Security and Compliance Analyst with experience implementing/assessing HITRUST, ISO 27001 , SOC, HIPAA, NIST 800-53 and PCI DSS controls.• In-depth knowledge of risk assessment methodologies, privacy regulatory standards (GDPR, CCPA etc.) and ability to manage projects with cross functional teams.• Extensive working knowledge of FISMA, NIST SP 800 series, HITRUST and SOX.• Great team player and passionate about improving security posture of organizations.
Humana
View- Website:
- humana.com
- Employees:
- 45742
-
HumanaLoganville, Ga, Us -
Third-Party Risk ManagerHumana Mar 2023 - PresentLouisville, Kentucky, UsGoal: Manage and mature Humana’s TPRM program towards a robust and effective risk management system where stakeholders can identify, evaluate, mitigate and monitor risks associated with services or goods provided by Humana’s Third-Parties.GRC Tools/Platforms: OneTrust, RSA Archer, Icertis, aSSIST, Bitsight, Blackite, Ms. Suite, Monday.com.• Manage Vendor risk due diligence across TPRM life cycle; Onboarding, Ongoing and Offboarding.• Review completed Inherent Risk Questionnaire (IRQ), SIG Questionnaire, Information Security Agreements (ISAs), and other supporting evidence documentation.• Assess details of controls in independent audit reports such as SOC 2 Type 2, HITRUST, ISO 27001, HIPAA, PCI DSS, Pen-Test etc.• Conduct ongoing assessments, performance monitoring, and real time analysis of threat intelligence reports on third-parties with Bitsight, Black kite, Advisen etc.• Negotiate Information Security Agreements (ISAs), ensuring key security controls and critical provisions are consistent with the scope of engagement.• Participate in project to re-design, implement and mature Humana’s TPRM program to improve vendor management ecosystem, facilitate stakeholder engagement and reduce vendor noncompliance.• Write and present detailed risk assessment report to internal risk team and senior management every week. -
Third-Party Risk AnalystMufg Jun 2021 - Feb 2023Chiyoda-Ku, Tokyo, JpCollaborate with security and legal teams to re-structure and develop MUFG’s TPRM Program to comply with federal and state regulatory requirements and emerging threats.GRC Tools/Platforms: ServiceNow, PRIVA, Assist, Coupa, Security Scorecard Blackite, Ms. Suite, Slack.• Collaborated with legal and security teams to draft TPRM policy, review workflow, and implement controls consistent with industry standards and risk-based approach to vendor risk assurance.• Examined and evaluated internal controls in key technology risk areas to ensure compliance with internal policies and applicable framework, procedures, and regulations.• Conducted detailed vendor risk screening, and worked with key stakeholders to identify and evaluate risk before continuing operations with third-parties.• Conducted assessment and re-assessment of vendors periodically and monitored their security practices and compliance with contractual obligations.• Reviewed technologies, processes, documentation and data to identify gaps in the effectiveness of automated tools, security controls and operational standards.• Evaluated internal controls in key technology risk areas to ensure compliance with policies and applicable rules, laws and regulations. -
Senior Information Security AnalystAthenahealth Feb 2018 - May 2021Boston, Massachusetts, Us.Assisted to write TPRM policy and procedures, ensuring vendor risk due diligence is consistent with industry standards and emerging threats.• Coordinated multiple third-party due diligence activities from onboarding to offboarding while training team members on industry best practices and regulatory requirements.• Conducted vendor risk assessments including reviewing Inherent Risk Questionnaire (IRQs), Tiering, running security intelligence reports, and reviewing SIG questionnaire.• Analyzed policy documents, reviewed artifacts, evaluated responses to Questionnaire, and followed up on findings.• Monitored status of each third-party security posture and due diligence activity and communicated details to stakeholders.• Participated in HITRUST, ISO, HIPAA, SOC II, and PCI DSS assessments and advised stake stakeholders on emerging security threats. -
Grc AnalystNextgen Healthcare Jan 2013 - Jan 2018Remote First, Us• Conducted HIPAA audits, served on security controls review committee, and performed general third-party risk due diligence.• Prepared test plans for internal risk assessments, and collaborated with external assessors to facilitate evidence gathering during annual audits.• Reviewed completed security questionnaire and artifacts and tracked issues identified with supporting mitigation measures.• Conducted periodic reassessment of vendors and monitored third-party security practices in line with contractual obligations.• Coordinated the preparation and assessment of controls and artifacts for HITRUST, SOC II, HIPAA and PCI DSS external audits.
Emmanuel K. Prempeh, Bsc., Cisa, Cism Education Details
-
Georgia Gwinnett CollegeBiochemistry
Frequently Asked Questions about Emmanuel K. Prempeh, Bsc., Cisa, Cism
What company does Emmanuel K. Prempeh, Bsc., Cisa, Cism work for?
Emmanuel K. Prempeh, Bsc., Cisa, Cism works for Humana
What is Emmanuel K. Prempeh, Bsc., Cisa, Cism's role at the current company?
Emmanuel K. Prempeh, Bsc., Cisa, Cism's current role is Third Party Risk Manager / GRC Analyst.
What schools did Emmanuel K. Prempeh, Bsc., Cisa, Cism attend?
Emmanuel K. Prempeh, Bsc., Cisa, Cism attended Georgia Gwinnett College.
Who are Emmanuel K. Prempeh, Bsc., Cisa, Cism's colleagues?
Emmanuel K. Prempeh, Bsc., Cisa, Cism's colleagues are Tania Pancorbo, Jessica Pegeese, Abisek Diyali, Caroline Kauffmann, Matt Parker, Cssr, Desiree Jackson, Angela Williams-Thewes.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial