LinkedIn officially appointed Lea Kissner as its chief information security officer (CISO) on August 28, 2024. The company said Kissner would lead its cybersecurity organization; Kissner separately confirmed the move and described a remit covering LinkedIn’s members, customers, and employees.
What LinkedIn confirmed
LinkedIn’s August 28, 2024 announcement said Lea Kissner joined the company as CISO and would lead its cybersecurity organization. LinkedIn described Kissner as an information-security and privacy veteran with more than 17 years of experience at major technology companies, including Google, Apple, and Twitter.
Kissner also announced the appointment in a first-person LinkedIn post. They described themselves as an engineer and cryptographer and said their responsibility was to protect LinkedIn’s members, customers, and coworkers. Their comments framed security as a way to make systems more robust, rather than only a compliance or defensive function.
“Former Twitter security chief” refers to Kissner’s previous job. It does not describe a new role connected to Twitter.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Who Lea Kissner is
Kissner’s background spans security, privacy engineering, cryptography, and senior engineering leadership. LinkedIn’s announcement identifies experience at Google, Apple, and Twitter, while SecurityWeek’s account describes earlier privacy, security, and engineering roles across large technology companies.
Their LinkedIn profile also lists published work related to Zanzibar, Google’s consistent global authorization system. That work is relevant to identity and access control, but it would be inaccurate to describe Kissner as the sole creator of Zanzibar.
Kissner uses they/them pronouns. The combination of platform-scale security, privacy engineering, authorization expertise, and executive experience is broader than the Twitter label alone suggests.
What changed in LinkedIn’s security leadership
SecurityWeek reported that Kissner replaced Geoff Belknap as LinkedIn’s CISO and that Belknap moved to a separate leadership role at Microsoft, LinkedIn’s parent company. Those transition details come from secondary reporting; LinkedIn’s appointment announcement does not specify Belknap’s new role, Kissner’s reporting line, the size of the security organization, compensation, or a hiring process.
Rank #2
| Detail | Status |
|---|---|
| Kissner became LinkedIn’s CISO | Confirmed by LinkedIn on August 28, 2024 |
| Kissner leads LinkedIn’s cybersecurity organization | Confirmed in LinkedIn’s announcement |
| Kissner replaced Geoff Belknap | Reported by SecurityWeek |
| Belknap’s Microsoft transition details | Reported by SecurityWeek, not detailed in LinkedIn’s announcement |
| Reporting structure, team size, compensation and first-year targets | Not publicly established in the appointment announcement |
Why LinkedIn’s CISO role is unusually broad
LinkedIn is both a social network and a business infrastructure layer. Its security work touches several high-value systems at once:
- Professional identities, résumés, employment histories, and account credentials.
- Private messages, connection graphs, recruiter outreach, and job-search workflows.
- Company pages, administrator accounts, sales tools, advertising systems, and enterprise integrations.
- Personal and business data subject to privacy, regional compliance, retention, and access-control requirements.
These categories describe the responsibilities and risk environment a platform CISO must manage. They are not proof that LinkedIn has admitted a particular level of account takeover, scraping, recruitment fraud, or other abuse.
Likely priorities, separated from announced strategy
LinkedIn has not published a detailed first-year security roadmap for Kissner. Based on the platform’s functions and Kissner’s public comments, several areas are reasonable priorities to watch.
Phishing-resistant authentication and recovery
Passkeys and other phishing-resistant methods can reduce credential theft. They do not eliminate the need for recovery processes when someone loses a device, changes jobs, or no longer controls an old corporate email address. Recovery must be secure without becoming an easier route for attackers.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Impersonation, fake profiles and malicious outreach
Recruiters, executives, companies, and job candidates are all potential impersonation targets. Detection systems may need to combine account, message, device, and network signals. Stronger checks can improve trust but may create friction for legitimate users, travelers, international members, and small businesses.
Scraping, APIs and third-party access
Professional profiles and relationship data are valuable to automated collectors. A CISO’s remit typically includes rate limits, API authorization, monitoring, data minimization, and controls on third-party integrations, while balancing legitimate recruiting and enterprise use.
Secure development and vulnerability response
Security scanning, dependency management, secret detection, patching, and incident response need to operate at engineering scale. Controls that arrive only as late-stage tickets can slow releases or create alert fatigue; integrated feedback is more sustainable.
Privacy, artificial intelligence and synthetic identities
AI can accelerate vulnerability discovery and attacker operations, while also making convincing fake profiles and messages cheaper to produce. Defenses must be weighed against data minimization, retention, transparency, false positives, and users’ ability to appeal enforcement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
What Kissner has said since joining
Employee passkeys
In a later LinkedIn engineering interview, Kissner said LinkedIn had rolled out passkeys for every employee and described them as strong protection against phishing. That statement applies to employees; it does not establish that passkeys were rolled out to all LinkedIn members.
Patching and security engineering
In the same interview, Kissner emphasized rapid patching as AI increases both vulnerability discovery and attackers’ capabilities. They also discussed security and site-reliability engineering working together.
A separate application-security post described modernizing static application security testing, secret scanning, dependency management, and developer feedback across more than 20,000 repositories. Those repository figures and technical descriptions are statements in LinkedIn material, not independently audited metrics.
Security culture and skills
Kissner has also discussed phishing-resistant authentication, AI, privacy, and cooperation between security and reliability teams in a podcast-related post. They promoted cybersecurity training and LinkedIn Learning’s partnership with Hack The Box in another LinkedIn post. That partnership reflects a talent and training emphasis; it was not announced as a consequence of the CISO appointment.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
What the appointment means for users and businesses
The hire signals senior-level attention to cybersecurity at a platform that handles professional identities, communications, recruiting activity, advertising data, and enterprise connections. Kissner’s technical and privacy background is a logical fit for that combination.
The appointment itself is not evidence that LinkedIn’s security has already improved. It does not announce new login requirements, identity-verification rules, privacy settings, anti-scam tools, or enterprise controls. Executive leadership must be followed by funding, staffing, product changes, measurable controls, and transparent incident communication.
What to watch next
- Member-facing authentication and account-recovery changes, with clear protection against recovery abuse.
- How LinkedIn reports impersonation, fake-account and malicious-message enforcement, including appeal outcomes.
- Security disclosures, vulnerability response and communications after incidents.
- Enterprise documentation covering APIs, integrations, administrator accounts and customer data.
- Evidence that secure-development controls, patching and dependency management are integrated into normal engineering work.
- Privacy and AI governance decisions, especially around behavioral detection, synthetic identities, retention and false positives.
Latest publicly visible role
The latest available LinkedIn profile and later LinkedIn material identify Kissner with LinkedIn and, in related material, as both CISO and VP Engineering. The original 2024 announcement specifically established the CISO appointment; the additional title should be attributed to those later LinkedIn references rather than backdated to the announcement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




