A New Security Chief for the Social Media Giant
Assaf Keren is taking over as the Chief Information Security Officer of Meta, the company confirmed on Wednesday. He steps into a role that has been vacant since Guy Rosen, Meta’s first CISO, announced his retirement in June after a 13-year run with the company.
Keren’s appointment lands at a pivotal moment. Meta is pouring resources into frontier AI development, and the company’s security posture is being tested on a scale few other organizations can comprehend. Billions of users, one platform, and an attack surface that keeps growing.
From PayPal to Qualtrics to Meta
Keren doesn’t come to Meta without baggage — the good kind. His last stop was Qualtrics, where he served as SVP and Chief Security Officer. He joined the experience management software firm in March 2024, but his roots run deeper in the payments world.
Before Qualtrics, Keren spent nine years at PayPal, climbing through a wide range of leadership roles that eventually landed him in the CISO chair. That mix of payments security and enterprise software experience gives him a rare vantage point — he’s seen both the compliance-heavy world of financial services and the faster-moving enterprise SaaS space.
Why This Hire Matters for AI Security
Keren’s own words hint at where his priorities lie. In a statement announcing the move, he framed the challenge around AI trust infrastructure:
“Building AI at the frontier means building the trust infrastructure for it at the same frontier, with the same seriousness, at a scale that touches billions of people. There are few places in the world where that problem is bigger, harder, or more consequential.”
He added that the role combines everything he’s worked on throughout his career — security, systems, and the human side of earning confidence. That last part matters. Security leadership at Meta isn’t just about firewalls and threat intel; it’s about maintaining user trust in an environment where every misstep becomes front-page news.
The Guy Rosen Legacy
Rosen leaves big shoes to fill. He was appointed Meta’s first CISO in 2022, but his history with the company goes back much further. For years, he led product security and integrity efforts, helping Meta navigate everything from election interference to content moderation crises.
His retirement marks the end of an era. Rosen hasn’t confirmed any plans to join another company, though he’s indicated he’ll stay active as an advisor to leaders and organizations. That’s a loss for Meta’s internal bench, but a gain for the broader security community.
What Security Leaders Can Learn From This Transition
Meta’s CISO handoff offers a few lessons for security teams everywhere:
- Succession planning pays off. Rosen’s departure was announced in June, giving Meta months to find the right replacement rather than scrambling.
- Cross-industry experience is valuable. Keren’s path through payments and SaaS — not just social media — brings a broader threat model perspective.
- AI security is becoming a CISO-level issue. Keren’s focus on AI trust infrastructure signals where the industry is heading.
For those keeping tabs on the broader cybersecurity leadership landscape, this appointment is one of several recent moves worth watching. The industry has seen a wave of high-profile CISO transitions lately, and each one reshapes the competitive dynamics at the top.
The Road Ahead for Meta’s Security Team
Keren inherits a security organization that’s both mature and under constant pressure. Meta operates at a scale where even small vulnerabilities can have outsized impact, and the regulatory environment around data protection and AI is only getting stricter.
His background suggests he’ll take a systems-oriented approach — thinking about security not as a series of isolated controls but as an integrated layer across Meta’s products. That’s exactly the mindset needed for the AI era, where model security, data governance, and application security are increasingly intertwined.
One open question: how will Keren shape Meta’s approach to external security research and disclosure? Rosen was known for maintaining a robust bug bounty program and strong ties with the researcher community. Early signs suggest Keren values that kind of collaboration, but only time will tell if he changes the playbook.
For now, the appointment is official. Keren is in. Rosen is out. And Meta’s security team has a new leader at a moment when the stakes have never been higher.
For more on recent moves in the industry, check out our coverage of other CISO appointments and security leadership changes. You can also follow the latest in enterprise security news and hiring announcements.