David Gildea: On a mission to democratize data security
Druva’s VP of Generative AI, David Gildea, is using cloud-native thinking and GenAI to strip complexity out of data protection – and put enterprise-grade security within everyone’s reach.
David Gildea’s career has been shaped by a simple, recurring question from customers: Can I just get this data in Excel? As a consultant, he saw first-hand how organizations struggled to access, interpret, and secure their own information. The gap wasn’t just technical; it was human. Spotting patterns across massive datasets was beyond human capacity, and that realization drew Gildea towards artificial intelligence (AI) as a way to make data both usable and secure at scale.
That interest, however, came later. Gildea’s early grounding was in data security and cryptography. Fresh out of college, his first publication focused on enabling people to store their medical data securely on credit cards, allowing doctors anywhere in the world to access personal medical data when needed. While machine learning (ML) and AI played a limited role in testing and validation, they were not central to his work. It was years later that Gildea began to see AI as essential to solving real-world security challenges.
“AI is almost magical. It has the ability to look at vast amounts of data and spot things that humans cannot,” he says.
From cloud to AI: a logical leap
Gildea’s transition from cloud to AI was a natural progression. Working at a startup immersed him in AWS technologies and cloud-native design, and he quickly embraced the cloud's API-driven flexibility. Traditional data centers seemed unnecessary, he felt, while cloud platforms allowed teams to test, iterate, and solve problems faster. This thinking led him to found CloudRanger, a SaaS company focused on protecting customer data in cloud environments. Its cloud-first approach aligned closely with Druva's global data protection mission, eventually leading to an acquisition.
Over time, Gildea, began to see strong parallels between the rise of cloud computing and the adoption of generative AI. “The cloud journey closely mirrors the AI journey. Cloud made it easier to solve customer problems, and AI is doing the same, perhaps even more effectively,” he says. Unlike cloud infrastructure, which still demands technical proficiency, AI has a remarkably low barrier to entry. “Even in my own home, everyone uses AI 10 to 15 times a day. There’s no barrier.”
Druva: uniting simplicity with security
Today, as VP of Product for Generative AI at Druva, Gildea leads the labs team, focused on how products will evolve over the next two to three years. The goal is ambitious: to expand the reach of enterprise-grade data protection and make it accessible across organizations using GenAI.
At Druva, GenAI enables users to interact with complex security systems in plain language. Compliance teams can, for example, directly query Druva for ISO or NIST reviews. AI agents then generate detailed reports highlighting gaps, estimating timelines and costs, and outlining steps for remediation steps— without spreadsheets and complex tooling. “GenAI enables us to hide enormous complexity behind a simple, objective-driven interface,” Gildea says. “Our customers get powerful capabilities without needing deep technical expertise.”
Druva's AI-driven approach also strengthens its core security operations. The company manages thousands of daily backups across workloads such as VMware, EC2, endpoints, Azure, and cloud-native environments. By analyzing vast volumes of backup data, AI identifies meaningful patterns and anomalies, supporting cyber investigations and compliance reviews. Users can prompt the system using frameworks such NIST or MITRE, and quickly generate board-ready reports outlining timelines, fixes, and impact.
The company’s recently launched Managed Detection and Response (MDDR) service takes this a step further, proactively flagging anomalies in backup data, often identifying issues before incidents escalate. “We’ve used AI for years to improve customer experience. Generative AI is critical as it allows us to democratize data security across organizations, instead of restricting it to those working in the backend”.
The challenges of working with AI
One of the biggest challenges Gildea faces is the sheer speed at which AI is evolving, along with rising customer expectations. Today’s customer has first-hand experience with tools like ChatGPT and Gemini, and expects the same level of speed, precision, and clarity from enterprise software. In response, Druva’s tools and services are designed for high accuracy, resolving thousands of customer queries, major and minor, with 68% of customer issues now resolved directly with DruAI.
Security, however, remains non-negotiable. In AI's early and fast-moving stage, Gildea believes shortcuts can quickly become liabilities. Druva therefore adopts a security-first approach, architecting AI systems with the same enterprise-grade protections as its core products. This means prioritizing caution over speed. For instance, the company has delayed full MCP deployment as security specifications are still maturing, despite advances such as AWS Age Gateways. This approach may slow rollout, but ensures vulnerabilities are not passed on to customers and turns security into a long-term competitive advantage.
AI ethics and responsibilities
For Gildea, transparency is the cornerstone of AI ethics. He believes companies must openly disclose how they build, train, and deploy AI systems, creating space for scrutiny and accountability. “Sunlight is the best cleanser,” he says, underscoring the importance of openness in responsible AI development.
Gildea also sees AI as both a powerful opportunity and a growing threat. He urges organizations to adopt it as a line of defense. AI-driven threats are becoming increasingly sophisticated, and he points to emerging malware that can rewrite its own code mid-execution to evade antiviruses. As attacks grow, AI-powered countermeasures will become essential.
At Druva, AI is embedded as a default layer of protection to help customers secure their environments. Gildea notes that data security is a constant cat-and-mouse game that demands immediate action and investment. The best time to act is now before threats become even harder to detect and contain.
On AWS
Druva’s longstanding partnership with AWS is rooted in the founders' early conviction that the future of enterprise software lay in SaaS and cloud-based services. Recognizing AWS as the cloud leader, Druva built directly on the platform from the beginning, integrating new services, such as DynamoDB, S3, EC2, and RDS, as they launched to benefit customers. Today, Druva uses 65-70% of AWS’s services globally, with a presence in most data centers.
The relationship is deeply collaborative, aligning AWS’s global, problem-solving approach with Druva’s focus on data protection and security. Druva provides early feedback, collaborates with AWS product managers and engineers, and actively contributes to AI-related product development. This includes joint initiatives at AWS's Gen AI Innovation Center, where teams co-build MVPs through coding sessions. “It’s a great way to work with Amazon — line by line on the code,” Gildea says.
AI and beyond…
Gildea advises IT leaders to embrace AI's potential, particularly in strengthening data protection. He believes organizations must involve employees across functions in understanding how AI can be used, what tools are available, and the risks and opportunities they introduce. This is key to helping them transition from traditional user experiences to more conversational, AI-driven interactions.
To stay ahead in a fast-moving field , Gildea reads widely, attends industry conferences such as AWS re:Invent, quickly builds minimal viable products (MVPs) using tools like AWS CodeWhisperer, and follows leading voices on LinkedIn. Outside work, he unwinds by golfing with his son, spending time with family, visiting beaches, and hiking to enjoy the outdoors.


