Kevin Cummings

Security Risk and Compliance Analyst Iii Affiliate Information Security Lead @University of Rochester Medicine

Webster, NY, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Jan 2022 — Present

Security Risk and Compliance Analyst Iii Affiliate Information Security Lead @University of Rochester Medicine

View department →

Rochester, NY, US

Serve as the HIPAA Security Official for the URMC Affiliated Hospitals.Provide support for legal and regulatory security compliance efforts.Create and conduct compliance audits.Participate in the information security governance process including communication of updated security policies.Provide security communication, training, and awareness to the Affiliate Hospitals

EDUCATION

1995 — 1998

Monroe Community College

Associates Degree in Applied Science, Computer Information Systems

SKILLS

IT OperationsVendor ManagementProactive MonitoringIncident ManagementDisaster RecoveryIsae 3402Service DeliveryIT AuditIso 9000Quality AuditingHp ProductsActive DirectoryUnixInformation SecurityProject ManagementProcess ManagementInformation TechnologyProcess ImprovementIT ManagementData CenterNetworkingHpPmpSlaSecurity OperationsPeople ManagementBusiness Process ImprovementService ManagementService DeskSecuritySystem AdministrationCustomer ServiceIT OutsourcingSecurity AuditsItilSoc 1WindowsAixSarbanes-Oxley ActContract Management

ABOUT KEVIN CUMMINGS

Over 25 years in Information Technology with the ability to hit the ground running with little supervision.11 years experience in managing compliance initiatives related to IT Controls.11 years as a Security professional handling Regulatory audits/attestation including SOX-404/ITGC, SSAE-16/18, PCI, HIPAA, and ISAE-3402. Reviewed and remediated user and application information access accounts quarterly, ensuring accounts were needed and restricted appropriately based on function. Managed all aspects of multiple IT security remediation initiatives.• Heavily involved in all facets of security and audit, including frameworks, standards, procedures, training and awareness, audit control narratives, mapping audits to standards, and more.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.