The handover at the top of Meta security
Meta confirmed on July 23 that Assaf Keren will serve as its next Chief Information Security Officer, taking over from Guy Rosen, who announced his retirement in June after 13 years at the company. Rosen was Meta's first CISO, formally appointed to the role in 2022 after years leading product security and integrity work that touched everything from account safety to platform abuse. He plans to stay involved as an advisor to leaders and organizations. Succession at the security helm of a company that operates some of the largest systems on the internet is always consequential, and the choice of successor tells you how the company reads its next threat cycle.
The signal in this transition is the profile of the incoming leader. Rosen grew up inside Meta's product and integrity organization, where the core problem was protecting a social platform and its users from abuse at scale. Keren comes from a different lineage entirely, one rooted in enterprise software and payments security. Meta reaching outside its own integrity culture for a CISO with deep enterprise credentials suggests the company now defines the role around protecting infrastructure, data, and AI systems that enterprise and regulatory scrutiny will judge by enterprise standards. That is a meaningful reframing of what the top security job at Meta is supposed to be.
Who Assaf Keren is
Keren joins from Qualtrics, where he served as senior vice president and chief security officer after arriving in March 2024. Before Qualtrics he spent nine years at PayPal in a series of leadership roles, including CISO, building and running security for a payments company where a breach translates directly into lost money and regulatory exposure. That is a career shaped by high-stakes, heavily regulated environments in which security failures carry immediate financial and compliance consequences. It is a very different school than the one that produced Meta's founding security leadership, and Meta clearly wanted that difference in the seat.
The relevance for other technology leaders is that Keren's resume reads like the archetype enterprises now recruit for their own top security roles. Companies want CISOs who have operated where auditors, financial regulators, and enterprise customers set the bar, because those are the pressures every AI-forward business is starting to feel. Meta selecting a leader from SaaS and payments, rather than promoting from within its integrity ranks, validates a hiring pattern already visible across the industry. The security executives moving into the most demanding jobs are the ones who learned their craft where the cost of failure was measured in dollars and sanctions rather than only in reputation.
Why the enterprise-security background matters here
Meta is no longer only a consumer social company. It runs a large advertising business, a growing enterprise and developer surface, and one of the most ambitious frontier AI programs in the world. Each of those exposes it to the kind of risk that enterprise security teams have spent decades learning to manage: data governance, third-party exposure, insider threat, and the compliance obligations that follow when you handle other organizations' information. Hiring a CISO who built payments-grade security programs is a way of importing that discipline wholesale rather than growing it slowly from within a product-integrity organization that was optimized for a different set of problems.
This is where the move becomes instructive for peers. The competencies that once lived in separate worlds, consumer trust and safety on one side and enterprise security and compliance on the other, are converging fast. An AI platform serving billions of people has to satisfy both at once. Meta's decision to unify that under a leader from the enterprise side is a bet that the harder, more transferable skill set is the regulated-enterprise one. For any CxO building an AI product that will eventually face procurement questionnaires and audits, that bet is worth noting when you decide who to put in charge of your own security function.
AI trust as the explicit mandate
Keren was direct about how he sees the job, saying that building AI at the frontier means building the trust infrastructure for it at the same frontier, with the same seriousness, at a scale that touches billions of people. That framing collapses the artificial boundary between AI safety and information security. In his telling they are one program, funded and staffed together, because a frontier model deployed to billions of users is simultaneously a safety problem and a security problem. The distinction that many organizations still maintain, with a responsible-AI team on one side and a security team on the other, does not survive contact with that scale.
For technology leaders, the phrase trust infrastructure is the part to internalize. It reframes AI security as a foundational layer you build deliberately, with the same rigor you apply to identity, encryption, and network controls, rather than a policy document bolted on after a model ships. Meta putting its most senior new security hire on record with that definition gives cover to CISOs elsewhere who are arguing for exactly this consolidation inside their own companies. When the largest AI operators say safety and security are the same job, it becomes easier to win the internal budget fight to staff and fund them as one.
What CISOs elsewhere should read into it
The practical lesson is about org design. If Meta, with its enormous internal security and integrity talent pool, decided the next CISO should come from enterprise SaaS and payments, that is a data point about the skills the era rewards. The leaders who can speak to auditors, satisfy enterprise procurement, and reason about AI risk in the same breath are scarce and increasingly sought after. Companies planning their own security leadership succession should widen the aperture beyond internal candidates who know the product and consider outsiders who bring regulated-industry discipline, because that discipline is what AI deployment at scale now demands from the top security seat.
There is also a continuity lesson in how Meta handled the exit. Rosen announced his retirement in June, the successor was named in July, and the outgoing leader is staying on as an advisor. That is a clean, telegraphed transition of a critical function, which is how security leadership changes should be run and often are not. Abrupt CISO departures rattle boards, customers, and regulators, and they leave gaps that adversaries probe. The orderly choreography here is a reminder that succession planning for the security chair deserves the same care organizations give to the CEO and CFO, because the role now carries comparable stakes.
The roadmap implication
For enterprise technology leaders, the immediate takeaway is to revisit how your own organization draws the line between AI governance and security. Meta's new CISO is on record treating them as a single trust program, and the companies you buy AI from will increasingly organize the same way. If your responsible-AI function and your security function still report through separate leaders with separate budgets, expect that structure to look dated within a year. The convergence Keren describes is coming to firms far smaller than Meta, driven by the same forces of regulation, enterprise scrutiny, and the practical reality that an AI system's safety and its security cannot be separated in production.
The longer view is about talent strategy. As AI moves from pilots to systems that touch customers and regulators, the security leaders who thrive will be the ones fluent in both the model and the compliance regime around it. Meta went to the enterprise and payments world to find that fluency. Smaller organizations should take the hint and start developing or recruiting for it now, before the demand spike makes those leaders even harder to hire. The CISO who can build trust infrastructure for AI at scale is becoming one of the most contested roles in enterprise technology, and Meta just showed the market what it is willing to pay for.


