Ayo Obisesan
Grc Analyst Iii @Parkview Health
Signup · Get unlimited contacts
WORK HISTORY
Grc Analyst Iii @Parkview Health
Fort Wayne, IN, US
Lead third-party risk assessments across clinical, operational, and IT departments, identifying cybersecurity, regulatory, operational, and emerging AI-related risks that may impact patient safety and protected health information (PHI).• Conduct detailed security risk reviews of network-connected medical devices using the MDS2 (Manufacturer Disclosure Statement for Medical Device Security) framework. Evaluate device architecture, authentication controls, encryption standards, remote access capabilities, and patch management processes before deployment, reducing pre-implementation security gaps by approximately 30%.• Assess 80+ vendors annually through structured due diligence processes, including security questionnaires, SOC 2 Type II report analysis, penetration testing reviews, and vulnerability assessments. Provide clear risk ratings and remediation guidance to business owners and leadership.• Partner with Information Security, Compliance, Legal, Privacy, and Clinical Engineering teams to ensure vendors meet HIPAA requirements, Business Associate Agreement (BAA) obligations, and internal policy standards before contract approval.• Maintain and enhance risk registers and executive dashboards, providing biweekly reporting on vendor risk posture, remediation progress, and control effectiveness. Improved visibility into high-risk vendors, contributing to a 25% reduction in unresolved critical findings.• Manage ongoing monitoring of high-risk vendors using security rating platforms, proactively identifying risk score changes, and coordinating timely remediation efforts.• Support internal and external audits by preparing control artifacts, facilitating walkthrough discussions, and drafting management responses. Contributed to successful audit outcomes with no material compliance findings.• Participate in security incidents and vendor escalations, conducting root cause analysis, and ensuring corrective actions are tracked through completion.
ABOUT AYO OBISESAN
Proficient Information Security professional in Risk Management, Audit, and Control with 8+ years of experience in overseeing third party risk assessment, Governance and Compliance Audit and optimizing internal controls against risks, threats, and vulnerabilities, and recommending appropriate security controls to mitigate risks. Areas of expertise include NIST 800 Series, ISO 27001/02, SOX, SSAE16(SOC 1 and 2), HIPAA/HITRUST, PCI-DSS.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.