Philip Martin Takes the CISO Chair at Uber

The former Coinbase security chief steps into one of tech's more scrutinised security roles, bringing a résumé that spans crypto, defence contracting, and cloud infrastructure.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
Philip Martin Takes the CISO Chair at Uber
Share

Key points

  • Philip Martin, formerly CISO at Coinbase, has joined Uber to lead its cybersecurity and enterprise security organisation.
  • His background includes Palantir, Amazon, and U.S. Army service.
  • Uber's security record includes a 2016 breach concealed from regulators and a 2022 intrusion attributed to a Lapsus$-affiliated actor.
  • The scope of Martin's mandate has not been made public.
  • The appointment comes as Uber expands freight, delivery, and autonomous-vehicle data operations.

Why does this hire matter?

Uber has bad security history. A 2016 breach was concealed from regulators for more than a year; former CSO Joe Sullivan was convicted in 2022 on obstruction and concealment charges related to that cover-up. A 2022 intrusion, attributed to a Lapsus$-affiliated actor known as 'teapotuberhacker', exposed internal Slack channels, HackerOne bug reports, and cloud dashboards after an attacker used social engineering to compromise a contractor's credentials. No perimeter controls fully compensate for weak identity hygiene, and Uber learned that at cost.

Martin steps into that context with an unusually varied record. Military discipline, data-analytics exposure at Palantir, cloud-scale operations at Amazon, and the adversarial pressure of a major crypto exchange is the profile boards reach for after bad headlines. Coinbase operates under financial-sector regulatory scrutiny and has been a persistent target for SIM-swapping crews and nation-state phishing campaigns. Running security there is not a quiet job.

The CISO role at Uber has become a referendum on how seriously the company takes security governance. Our 22 June 2026 piece "CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready." captured exactly the institutional pressure Martin will face: security chiefs are now expected to own risks that finance and operations once called their own.

Should you worry?

Uber handles driver and rider personal data at scale, payment rails, and real-time location feeds, making it a perennial target. A CISO with financial-sector and government-adjacent experience is a plausible answer to that exposure. What his mandate actually covers, whether it extends to physical security or third-party risk, remains unspecified. The company has issued no formal statement on scope or priorities.

A chair change is not a security programme. Martin's record is strong, but the real signal will be what Uber publishes, discloses, and funds in the next twelve months. Watch the regulatory filings.

© 2026 Threat Vectr