David Griffin

David Griffin Email and Phone Number

Chief Information Security Officer at CIBC U.S. @ Caesars Entertainment
United States
David Griffin's Location
Greater Chicago Area, United States, United States
About David Griffin

- Over 20 years of experience in Information Security.- Specialties include: Information Security, Security Architecture, Security Engineering, Security Operations, Network Security, Endpoint Security, Security Management, Identity & Access Management, Project Management, Program Management- Certified Information Systems Security Professional (CISSP), June 2001.

David Griffin's Current Company Details
Caesars Entertainment

Caesars Entertainment

View
Chief Information Security Officer at CIBC U.S.
United States
Website:
caesars.com
Employees:
18041
David Griffin Work Experience Details
  • Caesars Entertainment
    Caesars Entertainment
    United States
  • Cibc U.S.
    Chief Information Security Officer, Us Region
    Cibc U.S. Aug 2020 - Present
    Chicago, Il, Us
    Directly responsible for the oversight and management of these operational functions:• Information Security Services Management (Network Security, Application Security, Endpoint & Data Protection, Identity & Access Management and Cyber Operations and Resilience)• Security Strategy, Governance and Communications• Security Program and Portfolio Management• Risk and Advisory Services • Third Party Governance Office (Strategy and Governance, Pre-contract due diligence, Post-contract services, Information Security control group and continuous monitoring)Additional responsibilities include US Board, Regulatory and Executive Committee quarterly updates on the state of the information security program. This includes global and regional security issues that impact global and regional CIBC businesses.
  • Transunion
    Senior Director, Us Information Security Officer
    Transunion Jul 2019 - Aug 2020
    Chicago, Illinois, Us
    TransUnion stores over 30+ petabytes of data containing over 1 billion consumer records, serving 65,000 business customers and 35+ Million consumers across 38 offices in over 30 countries.Information Security Officers are embedded within each lines of business to help them manage their Information Security risks. Directly accountable for establishing and managing the Information Security Officer (ISO) program in the US. This includes:- Managing all Regional and Business Unit (BU) ISOs within the US, including Healthcare, Public Sector, Financial Services, B2C, Fraud and Alternative Data BUs.- Conducting BU specific Security Councils consisting of BU executive management team.- Working in conjunction with the GRC team to define common control framework, map security controls to framework, facilitate effectiveness testing and drive security projects to address any gaps.- Participating in a cross functional team to build common enterprise risk management framework to advise BU's of risk posture.- Helping ensure BU's meet regulatory or audit requirements including PCI, HIPAA, HITRUST, FISMA, SOX and SSAE 18. - Assisting BU's in building Security into new products and services.- Maintaining BU specific security controls.- Providing Information Security Support through M&A process.- Ensuring Security is incorporated into the Sales Cycle (contract reviews, RFPs, customer audits).
  • Transunion
    Senior Director Of Global Security Architecture, Engineering And Operations
    Transunion Mar 2016 - Jul 2019
    Chicago, Illinois, Us
    Accountable for the following Global Information Security departments:- Network Security Engineering – Network-centric security controls such as Web Proxies, Web Application Firewalls, Intrusion Prevention Systems, Network Access Control, Network Visibility tools and Distributed Denial-of-Service (DDoS) protection.- Endpoint and Data Security Engineering – Security controls residing on servers and end-user devices including Anti-Malware, Endpoint Detection and Response (EDR), Encryption, Data Loss Prevention and File Integrity Monitoring software.- Identity & Access Management Engineering – Provisioning of credentials and entitlements, entitlement approval workflow, annual entitlement attestations, Privileged Access Management and Multi-factor Authentication.- Security Architecture – Development of Information Security Strategy and 3-Year Roadmap, Project Advisory and Support, participation on the Enterprise Architecture Committee, review and approve security deviations, and creation of the Enterprise Cloud Security Strategy.- Security Operations – Level 1-3 operations to support 14 Global Security Services, including service request fulfillment, break/fix, service monitoring, change management, incident management, and monthly metrics reporting.Additional Duties Include:- Overall Portfolio Manager for Global Information Security Projects. Responsible for delivery of 10-20 strategic projects annually.- Providing Audit / Regulatory Compliance Support – PCI, SOX, Customer Audits, SSAE, HIPAA, HITRUST.- Information Security Demand and Resource Capacity Management.- Managing annual CAPEX and OPEX budgets.- Hiring and Recruiting.
  • Transunion
    Director Of Security Architecture And Engineering
    Transunion Mar 2011 - Mar 2016
    Chicago, Illinois, Us
    Overall Portfolio Manager for Global Information Security Projects. Responsible for delivery of 10-20 strategic projects annually. Highlights include:- Establishment of an enterprise-wide Identity Management system – The system detects adds/changes/terminations in centralized HR system to drive provisioning events. This includes creation of initial credentials and birthright entitlements, ability to request and facilitate approvals for additional entitlement requests, annual attestation of entitlements, and disablement of all access upon separation. This system automated tasks performed manually by operations staff to now perform over 2000 straight-through provisioning events monthly. This resulted in a 66% reduction of I&AM operations tickets and increased customer satisfaction scores by over 20%.- Deployment of Web Application Firewalls in all global locations to protect external facing applications. This enabled proactive blocking of application layer attacks as a first layer of defense.- Replacement of a commercial File Integrity Monitoring software with open source software resulting in over $200K annual saving while providing an even higher level of security control.- Deployment of Endpoint Detection and Response tool across over 30,000+ endpoints that now provides IT asset visibility and key forensic investigation capabilities. - Replacement of legacy US-centric Data Loss Prevention system with a deployment covering country specific policies for all global locations.Launched inaugural Security Operations Center (SOC) in 2011 including:- Deployment of Security Information and Event Management system.- Physical SOC design and build-out.- Staffing of 24x5 Security Analysts with on-call support.- Identified and Training Computer Security Incident Response Team (CSIRT).- Established Vulnerability Management program.- Instituted first Application Security capability to provide static and dynamic code scanning.
  • Accenture
    Senior Manager
    Accenture Jun 1998 - Mar 2011
    Dublin 2, Ie
    Security Capability Specialty Lead for Delivery Centers of North America - January 2010 to March 2011Responsible for building the security capability within the Accenture Technology Solutions (ATS) organization. Key responsibilities include:• Developing growth plan for security, including identifying skills to hire and target locations.• Opening and maintaining open position requests for security with recruiting.• Conducting skills and confirming interviews for security candidates.• Leading group operations, including resource staffing , reporting metrics and people development.• Tracking ATS Security demand and supporting opportunities.• Developing staffing guidelines and the onsite/offshore delivery model for security.• Building Certification and Accreditation (C&A) specialization group in Federal practice.Communications & High Tech (C&HT) Operating Group Security Lead for North America - FY2006, FY2008Responsible for tracking and supporting all security opportunities within the C&HT operating group. Key responsibilities included:• Running bi-weekly sales and pipeline call.• Attending account planning sessions for specific C&HT clients. • Identifying opportunities and offerings to take to clients.• Qualifying opportunities, supporting proposals, creating financial models, and developing resource plans.North America Oracle Security Lead - FY2007In charge of creating an Oracle security delivery capability, including tracking pipeline and sales as well as creation of assets to help accelerate Oracle I&AM deployments. Security Training & Skills Lead, FY2003-F2005Responsible for people development activities for the security group, including defining training curriculum, approving training requests, managing the people development budget and skills tracking.
  • Accenture
    Senior Manager
    Accenture Jun 1998 - Mar 2011
    Participated in many client engagements as a member of the Accenture’s Global Technology Consulting Security Specialty. Engagement experience includes the following:Data Loss Prevention Implementation - Delivery lead responsible for the design and build of a data loss prevention capability for a global leader in credit and information management. This included implementation of RSA's DLP Suite to protect data in motion and data at rest, integration of BlueCoat Proxy and outbound Email traffic, and development of operational processes and procedures.Product Data Management Project - Information Assurance Lead responsible for the design and build of infrastructure security components to support a common product data management solution for an Aerospace and Defense company. Key technologies included Layer 3 and Layer 7 firewalls, intrusion prevention, multi-factor authentication, server hardening and security information & event management tools. Identity & Access Management Project – Responsible for the delivery of an Identity & Access Management solution for a leading Aerospace and Defense company. Managed a mixed off-shore and on-shore team to deliver of the core infrastructure components of the Oracle Identity & Access Management Suite, including Oracle Access Manager, Oracle Identity Manager, Oracle Identity Federation and Oracle Internet Directory. eAuthentication Project – Program Manager responsible for the design and build of an enterprise identity & access management solution. The eAuthentication solution was created using CA (Netegrity) Siteminder for authentication, CA (Netegrity) IdentityMinder for identity management, and Microsoft Active Directory as the credential and policy store. The project supported over 70 integrated applications with over 80,000 customers and employees credentials issued. Based on web services, the identity management service provided user self-registration, profile management and delegated administration.

David Griffin Skills

Information Security Cissp Security Identity Management Integration Information Security Management Security Architecture Design Vulnerability Management It Strategy Security Management Computer Security Enterprise Software It Management Enterprise Architecture Firewalls Management Sdlc Encryption Team Management Team Leadership Information Security Policy Identity And Access Management Security Strategy Data Loss Prevention Technical Leadership Dlp Vulnerability Assessment Intrusion Detection Directory Services Program Management Leadership Project Management Network Security Risk Management Risk Assessment Information Technology Strategy Threat And Vulnerability Management

David Griffin Education Details

  • The University Of Iowa Tippie College Of Business
    The University Of Iowa Tippie College Of Business
    Mis

Frequently Asked Questions about David Griffin

What company does David Griffin work for?

David Griffin works for Caesars Entertainment

What is David Griffin's role at the current company?

David Griffin's current role is Chief Information Security Officer at CIBC U.S..

What is David Griffin's email address?

David Griffin's email address is dg****@****ion.com

What is David Griffin's direct phone number?

David Griffin's direct phone number is +131298*****

What schools did David Griffin attend?

David Griffin attended The University Of Iowa Tippie College Of Business.

What skills is David Griffin known for?

David Griffin has skills like Information Security, Cissp, Security, Identity Management, Integration, Information Security Management, Security Architecture Design, Vulnerability Management, It Strategy, Security Management, Computer Security, Enterprise Software.

Who are David Griffin's colleagues?

David Griffin's colleagues are Gopal Ven, Darlene Sproles, Amanda Lagunas, Chris Partida, Anne Carroll, Allen Crane, Jennifer Dixon.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.