Management & Strategy

Eric Goldstein Leaving CISA for Private Sector Role

CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.

CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.

Eric Goldstein, the executive assistant director for cybersecurity at the DHS’s Cybersecurity and Infrastructure Security Agency (CISA), is leaving the organization for a private sector role. 

The news of Goldstein’s departure was first reported last week by CyberScoop and CNN cybersecurity reporter Sean Lyngaas

It was soon confirmed by CISA director Jen Easterly, who applauded Goldstein’s work at the agency. 

Goldstein told CyberScoop that he is set to take on a cybersecurity leadership role in the private sector, but he has not named the company he is joining. 

Goldstein took the role of executive assistant director for cybersecurity at CISA in February 2021, helping build partnerships and what Easterly described as a “rockstar team”.

Prior to his role at CISA, Goldstein served as global head of cybersecurity policy, strategy, and regulation at Goldman Sachs. He also held various roles at CISA’s precursor, the National Protection and Programs Directorate.

Information on hiring announcements, promotions, and career achievements within the cybersecurity community is available in SecurityWeek’s continuously updated People on the Move section.

Advertisement. Scroll to continue reading.

Related: Healthcare Cybersecurity Firm Blackwell Raises $13 Million

Related: US Cyber Command Appoints Morgan Adamski as Executive Director

Related: Microsoft Hires Influential AI Figure Mustafa Suleyman to Head up Consumer AI Business

Related: Rockwell Automation Hires Stephen Ford as Chief Information Security Officer

Related Content

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Government

Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.

ICS/OT

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

Risk Management

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

Vulnerabilities

Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies...

Government

The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version