August 19, 2026•5 min read

Nico Waisman on His Journey in Offensive Security and AI

Nico Waisman's career journey from a young hacker in Argentina to CISO at XBOW highlights his expertise in offensive security and the role of AI in cybersecurity.

Nico Waisman speaking at a cybersecurity conference

A Journey from Hacking to CISO

Nico Waisman’s entrance into the cybersecurity realm is a narrative of serendipity and self-discovery. Born in Argentina around 1982, Waisman's early years were marked by the residual rebellious spirit against the authoritarian regime that fell just before his birth. With limited access to formal training in technology, Waisman found himself drawn to the emerging world of computers and hacking, fascinated by the idea of manipulating technology to serve his purposes.

The Self-Taught Hacker

Without traditional documentation or resources available at the time, Waisman embarked on a unique learning journey. "There was no documentation for anything, which was part of the fascination and challenge," he recalls. His exploration involved a great deal of experimentation and reverse engineering, leading him to develop a strong foundational knowledge of coding, bugs, and vulnerabilities—skills that would prove invaluable in his later career.

Early Career Begins at Immunity

In 2003, Waisman began his formal career in cybersecurity as a senior security researcher at Immunity, driven not by formal qualifications but by self-acquired knowledge and hands-on experience. This opportunity marked the start of a trajectory that would largely influence the field of offensive security. For the next 17 years, he climbed the ranks from inputting code to leading security teams. His work primarily focused on penetration testing and vulnerability assessments, fostering a collaborative environment where both public and private organizations could strengthen their defenses.

Versatility in Leadership and Technical Skills

During his tenure at Immunity, Waisman spearheaded the development of CANVAS, an exploitation framework pivotal for early penetration testers and red teams. His journey was bolstered by communication skills acquired during a stint studying journalism, which he now often applies in sharing knowledge at security conferences like Black Hat and Ekoparty. Waisman recognizes that leaders are cultivated through experience, often in unexpected ways. "Eventually, life and age slowly push you into a management position," he noted, reflecting on how he transitioned from an introverted tech enthusiast to a leader managing a team of up to 40 pentesters.

Transition to GitHub Security Lab

In 2019, Waisman transitioned to Semmle, where he continued to deepen his engagement with security research. The acquisition of Semmle by GitHub soon followed, positioning Waisman as the Senior Director of GitHub Security Lab, focusing on the intersection of cybersecurity and open-source software. His efforts culminated in the formation of the Open Source Security Foundation (OpenSSF), formalizing collaborative initiatives to enhance security within the open-source community—a crucial undertaking as more companies incorporate open-source components into their software development cycles.

Embracing Defensive Security at Lyft

Seeking new challenges, Waisman joined Lyft in 2020 as the head of security and privacy, ultimately ascending to CISO within two years. This role introduced him to the intricacies of defensive security—shifting focus from offensive tactics to ensuring operational security without hampering development speed. His experience at Lyft underscored the critical balance between security and engineering, emphasizing that effective security should enable progress rather than impede it.

Nico Waisman overseeing operations at Lyft headquarters.

The Origins of XBOW

As Waisman sought to integrate his offensive expertise with defensive practices, he met Oege de Moor, a long-time collaborator. They co-founded XBOW, which now stands at the forefront of combining artificial intelligence with offensive security methodologies. The firm developed an autonomous penetration testing product that mimics human skills while allowing security assessments to scale efficiently—a significant innovation in the industry. Through this role as CISO, Waisman has merged his vast knowledge of offensive security, leadership experience, and burgeoning interest in AI.

Addressing Burnout in Cybersecurity

Alongside his professional journey, Waisman openly discusses the issue of burnout affecting CISOs and their teams—an unavoidable challenge attributed to the immense stress associated with cybersecurity leadership. Cited by the World Health Organization as an occupational hazard, burnout manifests as emotional and physical exhaustion stemming from relentless demands. To combat this, Waisman promotes a healthy work/life balance, prioritizing empathy and emotional awareness to help his team navigate the pressures they face. He advocates for shielding his team from excessive stress and intervening when necessary to help them regain balance in their professional lives.

Advice for Future Cybersecurity Leaders

Despite his own unconventional path, Waisman does not provide direct career advice to his team, preferring a mentoring approach. He emphasizes the importance of focusing on what truly matters in security, a principle he learned from his mentor, Dave Aitel. Waisman employs a Socratic method, encouraging his team to ask questions and seek their own insights rather than simply offering prescriptive solutions. This nurturing style aligns with his beliefs about learning and development in the dynamic field of cybersecurity.

The Future of AI in Cybersecurity

Waisman’s focus on AI also reflects broader concerns within the cybersecurity domain. As attackers increasingly utilize AI tools for sophisticated strategies, a growing worry lies in the future accessibility of these tools. He warns, "For now, using AI is too expensive to do what is already possible on a grand scale. But the cost will come down," suggesting that organizations may soon need to contend with attacking adversaries armed with advanced autonomous malware. He believes that the security community must be vigilant and adaptive, preparing for a future where AI-driven attacks become commonplace.

Key Takeaways

  • Nico Waisman is a self-taught hacker turned CISO, emphasizing the importance of experiential learning.
  • His roles have evolved from an offensive security researcher to a leader focused on defensive strategies and AI integration.
  • The creation of XBOW represents a significant innovation in autonomous penetration testing.
  • Waisman promotes empathy and work/life balance to combat burnout in cybersecurity teams.
  • He advises future leaders to focus on what genuinely matters in security, fostering a questioning approach to learning.

Nico Waisman’s career trajectory illustrates a compelling evolution from a self-taught hacker in Argentina to a pioneering cybersecurity executive. His induction into the world of offensive security and his embrace of defensive strategies highlight an adaptive mindset crucial for addressing the challenges posed by modern cyber threats, particularly as technology like AI continues to shape the landscape. As the cybersecurity domain becomes increasingly complex, Waisman's experiences offer a practical guide for the next generation of leaders seeking to navigate this intricate field.

Frequently Asked Questions

Nico Waisman started his career in cybersecurity in 2003 as a senior security researcher at Immunity, where he developed a strong foundation in offensive security.
#Cybersecurity#Offensive Security#CISO#AI#Leadership