Signed, Sealed, Secured: Newly Appointed CISOs to Watch

Related

Share

Five organisations named new security chiefs in July and August 2026: a hotel group, a physical security company, an AI data centre operator, a remittance firm, and a crypto exchange. The businesses have little in common. The CISOs they hired have more than it first appears. Between them, they have run incident response at cloud scale, built security organisations from a single role, and carried national security experience long before they carried enterprise budgets. The mandates are new. The experience behind them is not.

Daniel Dubowski — SVP and CISO, Marriott International

Daniel Dubowski returns to the industry where he learned security at scale. Marriott International appointed him SVP and CISO in August 2026, eight years after he directed global IT security at InterContinental Hotels Group, a remit covering 5,300 hotels, 30,000 employees, and 420,000 identities. The years in between took him through Equifax, where he spent nearly six years rising from VP of identity and access security to CISO of the USIS business, and Hertz, where he served as SVP and CISO from March 2024. Earlier roles in healthcare and homebuilding gave him an operational grounding well outside the security echo chamber. His new brief, protecting one of the world’s largest hospitality companies, pairs naturally with the identity, access, and compliance depth that has shaped his career.

Jordan Avnaim — Global CISO, Allied Universal

Jordan Avnaim‘s path to the CISO seat ran through audit rooms before security operations centres. He spent nearly six years at Deloitte & Touche advising clients on Sarbanes-Oxley, HIPAA, and PCI compliance, established the internal audit function at Advantage Sales & Marketing, and lectured at the University of Southern California. Capital Group then kept him for 13 years, promoting him from technology risk manager to Vice President of Information Security and Technology Risk Management. That governance-first grounding now underpins a rapid run of CISO seats: Entrust from August 2023, Hyundai AutoEver America from October 2025, and Allied Universal since August 2026, where he serves as Global CISO. He brings more than 20 years of technology and cyber risk experience to the role, drawing on enterprise risk management, regulatory compliance, and critical infrastructure protection.

Eric Hammersley — CISO, IREN

Eric Hammersley built Nutanix’s product security organisation from a single architecture role into a team of roughly 20 engineers, then established the company’s US Live Site Operations and Global Security Operations functions. IREN appointed him CISO in July 2026, giving the AI data centre infrastructure company a security chief shaped by construction rather than inheritance. His second Nutanix chapter carried him from Senior Director of Engineering to Chief Product Security Officer and then VP of Engineering and CPSO, advising executive leadership and the board on product security, technology risk, and customer trust. Between the two chapters he led software security architecture at NVIDIA. The foundation came earlier still: nearly a decade of enterprise architecture and technology modernisation across the US Department of Defense, a chief engineer role supporting the Joint Chiefs of Staff, and a federal engineering post at VMware. Hammersley started in the US Navy as a fire controlman aboard guided missile frigates, planning Harpoon missile engagements and leading a shipboard network installation normally entrusted to commissioned officers.

Jeff Lyon — VP and CISO, Remitly

When Robinhood disclosed a data breach in November 2021, Jeff Lyon led the incident response, weeks into his role as Senior Director of Security Engineering. He stayed two years, steering the company’s Log4j remediation, embedding security teams inside engineering through a DevSecOps transformation, and launching passkey authentication on the first day of iOS support. He joins Remitly as VP and CISO, appointed in July 2026, from Coinbase, where he led infrastructure security spanning cloud, corporate, and development security, vulnerability management, and runtime teams. The formation came earlier, at Amazon Web Services: seven years building a global perimeter security organisation across Seattle, Vancouver, and Cape Town, launching AWS Shield Advanced and AWS Managed Rules, and serving as a Bar Raiser across 350 interview loops. Before that came nine years as a US Navy Petty Officer First Class. Lyon is an Afghanistan Campaign Medal recipient and a disabled veteran.

Michael Sikorski — CISO, Coinbase

Michael Sikorski wrote the book on malware analysis, literally. Practical Malware Analysis grew out of a career that began at the NSA, where he graduated from the System and Network Interdisciplinary Program and briefed the agency’s director on his team’s work. It matured at Mandiant, where he co-founded M-Labs, contributed analysis to the landmark APT1 report, and founded the FLARE reverse engineering team. When attackers breached FireEye, Sikorski’s expanded FLARE organisation, by then more than 100 people, worked alongside incident responders on the discovery of the SolarWinds backdoor code, findings he briefed to CISA and the Department of Defense. He most recently spent four years as CTO and VP of Engineering for Palo Alto Networks’ Unit 42, directing nation-state and crimeware tracking and briefing more than 100 CISOs a year. Coinbase appointed him CISO in July 2026. Sikorski has testified before Congress on AI security, sits on the Cyber Threat Alliance board, and has taught malware analysis at Columbia University for more than a decade.

Five Seats, No Shared Blueprint

These appointments show how many routes now lead into the CISO seat. Identity and access management, audit and risk, organisation building, cloud-scale incident response, and malware research all feature here. What unites the group is the nature of the businesses they now protect. A hotel chain’s guests, a security company’s officers and clients, the data centres behind AI, the remittances families depend on, and a crypto exchange’s custody of customer assets are all trust businesses. Security failure in any of them would strike at the core of the enterprise. That is what makes these five appointments worth watching.

More CISOs to Watch:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.