Skip to content
CISO Spotlights

Career profile

Robert Wood

Chief Information Security Officer, TiDB (PingCAP)

Status
Current role, per sources checked 1 September 2026
Appointed
1 September 2026
Published

Compiled 27 September 2026 from public records. Each statement below is drawn from the sources listed at the end.

Robert Wood is Chief Information Security Officer of TiDB, the open-source distributed SQL database made by PingCAP, an appointment the company announced alongside the results of an outside source-code security review.

Career path

TiDB's announcement states that Wood previously served as CISO for technology companies and for a U.S. federal agency whose security program protected data covering more than one hundred million people, and that he has built enterprise security organizations, led compliance initiatives from SOC 2 through FedRAMP, and earned recognition as CISO of the Year in the SANS Difference Makers Awards. A CSO Online contributor profile, published before this appointment, identifies that federal-scale role by name, describing him as a chief information security officer of a large healthcare enterprise and giving his title at the time as CISO, Centers for Medicare and Medicaid Services. That same profile adds that he built and managed security programs in the tech sector at several startup organizations, served as a principal consultant at Cigital advising enterprises on software security programs, and founded and led a red-team assessment practice.

Scope of the role and the security review

At TiDB, Wood will oversee product security, cloud infrastructure security, governance, risk management, and compliance, guide the company's assurance roadmap including the cadence of future independent assessments, and work directly with customers evaluating TiDB for mission-critical deployments.

The review that accompanied his appointment gave TiDB's source code to NCC Group for a combined static and dynamic assessment, which found no critical, high, or medium-severity vulnerabilities. Discussing that review, Wood said: "A source-code assessment is a more demanding form of review than a controls audit, and the teams evaluating a database know the difference." He added that his goal is to keep that standard and put independent review on a regular cadence, so customers get clear answers about how TiDB is built, secured and governed.

Sources

  1. 1.
    PingCAP (TiDB)pingcap.com · published 1 September 2026 · checked 27 September 2026 · tier A
  2. 2.
    CSO Onlinecsoonline.com · published 15 June 2023 · checked 27 September 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.