Uber hires Joe Sullivan to be its first chief security officer, luring him away from Facebook
Context & Ripple Effects
In 2015 this hire read as a coup: Uber had no chief security officer at all, and it pulled one straight out of Facebook's security organization as the ride-hailing company scaled. Seven years of subsequent coverage turned the same appointment into a cautionary arc.
Sullivan was fired in November 2017 after the disclosure of Uber's 2016 data breach, joined Cloudflare as CSO within months, and in 2020 faced federal obstruction charges over concealing that breach from FTC officials. His trial opened in September 2022, with CEO Dara Khosrowshahi testifying he fired Sullivan because he could no longer trust his judgment.
First-order effects
- Uber gains a dedicated security executive for the first time and strips a senior security leader from Facebook; the CSO seat becomes a permanent fixture on Uber's leadership chart.
- Sullivan leaves Facebook's security operation mid-career for a higher-profile, less proven platform — a direct talent transfer between the two companies.
Second-order effects
- After Sullivan's firing, Uber splits and rebuilds the function: Ruby Zefo arrives from Intel as its first-ever chief privacy officer reporting to the general counsel, while ex-NSA general counsel Matt Olsen takes the CSO role Sullivan originally defined.
- Cloudflare converts Uber's loss into its own gain, hiring Sullivan as CSO almost immediately after his dismissal — a reminder that reputation damage in security leadership is not always disqualifying in adjacent markets.
Third-order effects
- The obstruction charges and 2022 trial establish personal criminal exposure for security executives who oversee breach concealment, not just corporate fines — reshaping how CSOs document and escalate incident decisions.
- The Uber arc points toward structural separation of privacy and security governance inside large platforms: distinct officers, distinct reporting lines to legal, rather than one consolidated security chief.
The trend: Data-breach handling is shifting from an internal corporate-misconduct matter to personal criminal liability for named executives, with companies responding by splitting privacy and security into separately accountable roles.