Meta Names Assaf Keren as Its New Chief Information Security Officer
The social media company has appointed a PayPal and Qualtrics veteran to lead its security operations, replacing the man who built the function from scratch.

Key points
- Assaf Keren was appointed Chief Information Security Officer (CISO) of Meta on Wednesday, July 2025.
- Keren replaces Guy Rosen, Meta's first-ever CISO, who announced his departure in June 2025 after 13 years at the company.
- Before Meta, Keren served as Chief Security Officer at Qualtrics and spent nine years in security leadership roles at PayPal, including as its CISO.
- Rosen has indicated he will work as an advisor rather than join another company directly.
Meta, the company that owns Facebook, Instagram, and WhatsApp, has a new person in charge of keeping its systems and nearly four billion users' data safe. Assaf Keren confirmed the appointment on Wednesday, stepping into the role of Chief Information Security Officer, the executive responsible for an organisation's entire security strategy.
Who is Assaf Keren?
Keren is a career security executive with direct experience running security at large financial and technology companies. He spent nine years at PayPal, the payments platform used by hundreds of millions of people, working across several leadership positions including CISO. He then joined enterprise software company Qualtrics in March 2024 as its Chief Security Officer, a role he held for just over a year before Meta came calling.
In a statement announcing his appointment, Keren described the scale of the challenge plainly: "Building AI at the frontier means building the trust infrastructure for it at the same frontier, with the same seriousness, at a scale that touches billions of people."
Who did Keren replace, and why does it matter?
Guy Rosen held the job before him. Rosen was no ordinary predecessor: he was Meta's first CISO, appointed in 2022 after years leading the company's product security and integrity work. He announced in June 2025 that he would leave after 13 years at Meta. Rosen has not said he is joining another company; he indicated he plans to advise other leaders and organisations instead.
Rosen's departure matters because he built Meta's security function from the ground up. Whoever follows him inherits a large, established team, but also owns all the decisions that team will make going forward.
| Details | |
|---|---|
| New CISO | Assaf Keren |
| Announcement date | July 2025 |
| Previous role | CSO, Qualtrics (from March 2024) |
| Role before that | CISO and other leadership, PayPal (nine years) |
| Predecessor | Guy Rosen (Meta's first CISO, 2022 to 2025) |
Should ordinary Meta users care about this?
A new CISO does not change the apps you use day to day. What it does signal is where Meta places security in its priorities, particularly as the company pushes deeper into artificial intelligence. Keren's background in payments security at PayPal means he has experience protecting systems where a breach carries immediate, tangible financial harm to real people. That experience should translate reasonably well to a platform that stores personal messages, photos, and, in some markets, payment information for billions of accounts.
If you use Facebook, Instagram, or WhatsApp, the standard advice still applies: use a strong, unique password for your Meta account, turn on two-factor authentication (a second check, like a code texted to your phone, that stops criminals even if they steal your password), and be cautious about unexpected login alerts. Leadership changes do not require users to act, but good account hygiene is never wasted.
(This story was first reported by SecurityWeek.)



