Meta taps Assaf Keren as CISO, replacing Guy Rosen after 13 years
A high-profile security seat flips at Meta, with a new CISO coming from Qualtrics and PayPal.

Meta has hired Assaf Keren as its next chief information security officer, filling the vacancy created when Guy Rosen announced his departure in June after 13 years. Keren joins from Qualtrics, where he spent two years as chief security officer, and previously held the same title at PayPal.
Meta is staffing its information security leadership with a straight-up swap: Assaf Keren is joining as the company’s next chief information security officer, stepping into a vacancy created when Guy Rosen announced his departure in June after 13 years at Meta.
Keren comes to Meta from software platform Qualtrics, where he spent two years as chief security officer. Before that, he held the same title at PayPal. In other words, Meta is not just hiring “a security exec.” It is moving in someone who already owned the security job in two different large, high-risk, data-centric companies.
If you lead security, you know this role is never really about dashboards. It is about making tradeoffs under pressure, and doing it in a world where the attack surface grows faster than the org chart. A CISO’s decisions affect everything from identity and access controls to incident response, from vendor risk to internal access for teams that want to move quickly. When a company changes this seat, the most consequential question is not whether the new leader is qualified. It is whether the new leader will reinforce the current strategy, recalibrate it, or pull hard toward a different set of priorities.
The timing matters for another reason: security leadership transitions often come with internal whiplash. Rosen left after 13 years, which suggests the role was shaped by long-running institutional habits. A tenure that long usually means mature processes, but it can also mean the organization optimizes for what has worked before. Bringing in Keren from Qualtrics, and previously PayPal, signals that Meta expects a mix of continuity and fresh enforcement. In practice, that can mean tightening controls in areas that are vulnerable during periods of rapid change, or revisiting how security policies get translated into engineering reality.
There is also an industry reality behind this move. Companies like Meta operate at massive scale, and that scale draws both attackers and regulators. Even when a company does not say “regulatory pressure” out loud, security leadership is where those pressures land. The security function tends to be the bridge between legal obligations, technical implementation, and risk decisions that the board has to live with. So a CISO hire is not a staff improvement. It is a governance signal.
Qualtrics and PayPal are instructive reference points for that governance signal. The source says Keren spent two years as chief security officer at Qualtrics, and previously held the same title at PayPal. Both are businesses built on handling sensitive information and supporting digital workflows, which typically means security teams manage not just threats, but also data handling boundaries, third-party access, and identity systems that must work for real people and real operations. When a CISO has that background, boards often expect stronger execution on operational security: making sure controls are not just designed, but actually used.
For Meta, filling Rosen’s vacancy is also a reminder that leadership in security is highly visible even when it is not celebrated. The public tends to notice outcomes: breaches, downtime, fraud, or the lack of those disasters. Behind the scenes, the CISO role is where the org invests in prevention, detection, and response readiness. A change at the top can change how quickly the company escalates issues internally, how it evaluates vendors, and how it sets risk tolerances for projects that are trying to ship.
For peers, this is a useful “watch the chair” moment. If you run a security function or sit on a board, you know transitions can reveal what leadership values: continuity versus transformation, or operational hardening versus broader cultural change. Meta’s move suggests the company is prioritizing experienced, cross-company security leadership. The CISO seat is now filled by someone who has already done the job at both Qualtrics and PayPal, and who arrives with familiarity with security leadership responsibilities across different product and risk environments.
At the end of the day, what matters is how fast the new CISO can align the security organization with Meta’s current threat landscape and engineering priorities. Rosen’s exit after 13 years created an opening. Keren’s hiring, from Qualtrics and previously PayPal, looks designed to close that gap with minimal disruption and a strong execution baseline. For decision-makers, that means the next chapter of Meta’s security posture will be shaped by Keren’s priorities and how effectively the organization can translate them into day-to-day security reality.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Etched reaches $10.3B valuation with inference chips, investors bet on no-GPU AI speedups
Etched says its chips and memory components speed up inference on any AI model without GPUs. Here’s why the valuation matters.

AI image fraud could cost $40B next year; international standards may finally unify defenses
A $40 billion threat is pushing the standards debate from scattered labs to something buyers can actually enforce.

Lego turns Donkey Kong barrels into a playable Nintendo arcade machine you can actually build
A new Lego Nintendo set lets you stage Donkey Kong cabinet glory, with build-and-play mechanics that move past display-only fun.

