A Security Veteran Takes the Helm at GitHub

GitHub has announced a new Chief Security Officer, welcoming a leader with deep experience in building security programs for both fast-moving startups and sprawling enterprises. The new CSO joins the company after five years building and leading the security program at Duo Security, a tenure that shaped a core belief: thoughtful, customer-centric security design means protection and business velocity don’t have to be at odds. Done right, security lets teams move faster and with more confidence.

That philosophy aligns closely with GitHub’s existing developer-first security approach. The platform has already made significant strides in protecting developers and their work, including supporting passwordless authentication via WebAuthn and removing all third-party tracking cookies from GitHub.com—an industry-first move for privacy. On the development side, features like secret scanning and CodeQL serve as practical guardrails that help developers avoid shipping vulnerabilities in the first place. For a leader who has navigated security at both SaaS companies like Duo and larger organizations like Cisco, those capabilities are essential infrastructure for a broad range of users, and they form a strong base for the next phase of growth in GitHub’s Security organization.

The new CSO also brings a personal connection to the platform, noting that much of the security community—and many favorite security projects—call GitHub home.

  • CloudMapper (duo-labs/cloudmapper)
  • stethoscope (Netflix-Skunkworks/stethoscope)
  • GoPhish (gophish/gophish)
  • osquery (osquery/osquery)

Securing the platform that has enabled and amplified these influential open-source projects is central to the role. As the new CSO describes it, this is a pivotal moment for leading GitHub’s Security org, working with both the internal team and the larger community to keep GitHub the most trusted place for developers and teams to build together. Those interested in joining that mission can find open roles on the Security org via GitHub’s careers page.