Dave Gordon

Dave Gordon Email and Phone Number

Senior Manager, Cybersecurity @ McKinsey & Company
Philadelphia, PA, US
Dave Gordon's Location
Greater Philadelphia, United States, United States
Dave Gordon's Contact Details

Dave Gordon personal email

About Dave Gordon

Compassionate and realistic leader in the IT security, risk, and compliance space. Led development and operations of multiple security, compliance, and audit programs for products and services in healthcare, wellness, and insurance industries while contending with significant legal and regulatory requirements. Very interested in privacy and security policy and governance, the structure and effectiveness of the individuals and teams responsible for those functions, and post-acquisition integration of new businesses. Specialties: Information Security, IT Risk, Privacy, HIPAA, HITRUST, NIST 800-53, Audit, GRC, Data Breach Management, Secure Application Development

Dave Gordon's Current Company Details
McKinsey & Company

Mckinsey & Company

View
Senior Manager, Cybersecurity
Philadelphia, PA, US
Website:
mckinsey.com
Employees:
38962
Dave Gordon Work Experience Details
  • Mckinsey & Company
    Senior Manager, Cybersecurity
    Mckinsey & Company
    Philadelphia, Pa, Us
  • Mckinsey & Company
    Head Of Information Security - Social, Healthcare, And Public Entities Practice
    Mckinsey & Company Oct 2022 - Present
    Us
    Lead cyber team for McKinsey’s global Social, Healthcare, and Public Entities practice (SHaPE.) Responsible for program vision, roadmap, and management, including secure product design and maintenance, control implementation and compliance, organizational governance, and risk. Intimate collaborations with engineering, risk, privacy, and legal, both at Firm and practice levels. Drive practice audits (e.g., HITRUST, ISO 27001, CMS, NHS) and regularly engage with client leadership and Firm senior partners. Additional scope with highly regulated United States Government (USG) practice (e.g., NIST 800-53, 800-171, and CSF)
  • Covera Health
    Senior Director, Security And Compliance
    Covera Health Sep 2020 - Oct 2022
    New York, Ny, Us
    Lead security and compliance program for sophisticated radiology artificial intelligence and analytics startup, including privacy, audit, and patient safety. Design and execute strategy from policy drafting to control selection to solution implementation, as well as counsel leadership, teams, clients, partners, and auditors on Covera's technical and operational risks.
  • Welltok, Inc.
    Director, Security And Compliance
    Welltok, Inc. Jan 2019 - Sep 2020
    Denver, Co, Us
    Led a strong, distributed team responsible for all security, audit, and compliance efforts at Welltok, an enterprise healthcare SaaS company featured in Forbes Cloud 100 three years running and considered Business Insider’s Most Valuable Colorado startup. Some of our successes and responsibilities included leading annual HITRUST, SOC 2 Type 2, ISO 27001 audits as well as HIPAA, HITECH, and client assessments; establishing, communicating, and enforcing technical and administrative policies, procedures, and standards across 10 disparate product and service offerings; driving a powerful and relevant suite of security tools and services across cloud (AWS), on-premise, and user endpoints; and integrating security and privacy guidance into product and engineering decisions and designs.
  • Welltok, Inc.
    Business Security Liaison
    Welltok, Inc. Sep 2017 - Jan 2019
    Denver, Co, Us
    Provided specialized security and compliance support for largest clients, as well as assisting with multiple audits and assessments (HITRUST, SOC 2, AUP). Worked with Director and CISO to implement revisions to enterprise security, risk, and compliance policies and standards across enterprise each year (HITRUST CSF; NIST 800-53, 800-63, 800-66). Also contributed to security-related product features and architecture, including multifactor authentication (MFA), CAPTCHA, logging standards as well as standard SecOps - incident response, log review, third party assessments, workforce authorizations, etc.
  • Freelance
    Cyber Security Consultant
    Freelance Jan 2017 - Aug 2020
    Various consultations around IT risk management with a focus on privacy-related regulations and frameworks, e.g., HIPAA, 23 NYCRR 500, GDPR, and their implications for system configuration and design in AWS/Azure.
  • Aetna - Global Security
    Information Security Manager
    Aetna - Global Security 2014 - 2016
    Hartford, Connecticut, Us
    - Created subsidiary third party risk program spanning +20 LOBs with differentiated legal and technology portfolios - Produced and distributed weekly KPIs, ad hoc reports to Aetna CSO (dir. report to COO) - Identified major liabilities in enterprise third party risk policies and controls; contributed to revisions - Discovered and challenged multiple record discrepancies in third party risk tracking and reporting system - Conducted +200 privacy and security reviews (e.g., SIG, BSIMM, SOC II, etc.) of third parties - Led multiple audit response and remediation efforts for iTriage, bswift, and My Aetna LOBs
  • Carnegie Mellon University
    Research Assistant
    Carnegie Mellon University 2010 - 2014
    Pittsburgh, Pa, Us
    - Published and presented original research on multi-jurisdictional data governance and system design- Taught and supported graduate and undergraduate courses in privacy, technology, and law- Secured research funding via National Science Foundation (NSF) IGERT, the Institute for Information Infrastructure Protection (U.S. DHS), and Hewlett-Packard Innovation Research Program
  • Microsoft
    Doctoral Research Internship
    Microsoft 2013 - 2013
    Redmond, Washington, Us
    - Reviewed both B2C and B2B products and sites for compliance with Microsoft Privacy Standard - Presented original research on inadequacy of browser and OS just-in-time (JIT) notifications - Researched implications of California, Colorado, and EU laws on Smart Grid data privacy using methods from own work
  • Noein Inc.
    Software Engineer
    Noein Inc. 2008 - 2010
    Williamsville, Ny, Us
    - Analyzed and refactored legacy client applications handling PHI to address efficiency and compliance issues - Developed and tested rich web apps in PHP, Lisp, Python, Ruby, and Javascript - Translated designers’ mockups into well-structured CSS/HTML templates - Drove marketing and communications for Local Express product line (SEO service) - Led and built projects using Symfony and Drupal frameworks

Dave Gordon Skills

Perl Data Analysis Java Linux Python Computer Science Javascript Mysql Subversion Php Software Engineering Management Data Privacy Html Apache Css Security Qualitative Research Requirements Analysis Privacy Compliance Data Modeling Quantitative Research Html 5 Jquery Operating Systems Singing Acting Node.js It Audit Hipaa Amazon Web Services Microsoft Azure Git Kali Linux Policy Analysis It Compliance

Dave Gordon Education Details

  • Carnegie Mellon University
    Carnegie Mellon University
    Engineering And Public Policy
  • Carnegie Mellon University
    Carnegie Mellon University
    Engineering And Public Policy
  • University At Buffalo
    University At Buffalo
    Consulting
  • Suny Geneseo
    Suny Geneseo
    Computer Science
  • Suny Geneseo
    Suny Geneseo
    Music

Frequently Asked Questions about Dave Gordon

What company does Dave Gordon work for?

Dave Gordon works for Mckinsey & Company

What is Dave Gordon's role at the current company?

Dave Gordon's current role is Senior Manager, Cybersecurity.

What is Dave Gordon's email address?

Dave Gordon's email address is da****@****ail.com

What schools did Dave Gordon attend?

Dave Gordon attended Carnegie Mellon University, Carnegie Mellon University, University At Buffalo, Suny Geneseo, Suny Geneseo.

What skills is Dave Gordon known for?

Dave Gordon has skills like Perl, Data Analysis, Java, Linux, Python, Computer Science, Javascript, Mysql, Subversion, Php, Software Engineering, Management.

Who are Dave Gordon's colleagues?

Dave Gordon's colleagues are Ryosuke Tane, Sirui Wang, Jennifer Connors, Caitlin Crotty, Megan Dweck, Jonathan Moore, Mariola T..

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.