Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump’s Syria envoy calls Israeli air strikes on base ‘unnecessary escalation’

    August 18, 2026

    What is behind Russia’s ‘consequences’ threat over UK sending drones to Ukraine? | Russia

    August 18, 2026

    Swedish MP intervenes in ‘damaging’ Brexit row over elderly Britons ordered to leave | Brexit

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump’s Syria envoy calls Israeli air strikes on base ‘unnecessary escalation’
    • What is behind Russia’s ‘consequences’ threat over UK sending drones to Ukraine? | Russia
    • Swedish MP intervenes in ‘damaging’ Brexit row over elderly Britons ordered to leave | Brexit
    • Tesla is finally launching the Cybercab — let’s hope it’s ready
    • OpenAI president urges enterprises to hasten AI security defences
    • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
    • Trump Family Crypto Firm Tied to Chinese AI Models US Government Called a Security Risk
    • NASA Student Aviation Challenge Focuses on Nation’s Infrastructure
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments11 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “I don’t think I ever chose a career in cybersecurity. It chose me.” Well, we’ll see…

    Nico Waisman was born and still lives in Argentina. If what he says is accurate, it suggests he was born in 1982; one year before a seven-year period of military dictatorship in Argentina came to an end.

    Argentine youngsters in the 1980s lived in a time of youthful rebelliousness against the law and the establishment, lingering after the dictatorships. For Waisman, this youthful rebelliousness turned toward emerging technology. He became fascinated by the idea of being able to subvert this tech into doing something he wanted it to do. In short, he became a young hacker – but it was the challenge and enjoyment of doing it rather than any desire to make money or cause harm from it that drove him.

    He received no training in computer technology nor cybersecurity. Neither existed in Argentina at that time. Everything he learned about code, bugs, finding vulnerabilities and exploiting them, he taught himself. 

    “There was no documentation for anything, which was part of the fascination and challenge,” he explains. “So, there was a lot of experimentation and a lot of reverse engineering, to learn how things worked and how to subvert them. This is what I really, really liked and still enjoy: you spend days focusing on one problem, understanding how it works, and then trying to see how you can break it.”

    This was the origin of a career in offensive security. But again, in Argentina at that time, there was no such thing as a career in offensive security. Instead, he considered a career in engineering, but he dropped out of engineering school a couple of times. He then tried ‘communication’ and spent four years studying journalism. Again, he didn’t complete the course and gain a degree; he didn’t do the thesis. All the time he explored other options and developed, for example, new communication skills, his first love was still hacking.

    Advertisement. Scroll to continue reading.

    “Eventually,” he says, “even in Argentina, the future showed up, and I was able to get a job in cybersecurity.” In 2003 he joined Immunity as a senior security researcher. He may not have had formal cybersecurity qualifications, but he had hands-on experience and an ability to demonstrate his knowledge. It was the beginning of his professional career, three-quarters of which has been in offensive security, founded in his early self-taught knowledge of hacking methods.

    He remained at Immunity until 2019, progressively moving up the ladder to become VP of Latin America. “We were building a product [CANVAS, an exploitation framework that largely shaped how early pentesters and red teams evolved] that helped people perform their own penetration testing. I was working both with public and private companies, helping to find vulnerabilities and how they could be exploited, initially with Linux and later with Windows.”

    During this 17-year period, he used his personal expertise from earlier hacking, exercised the communication skills he had acquired (he spoke at conferences including Black Hat, Syscan, PacSec, RuxCon, and Ekoparty), and learned new leadership skills.

    Waisman agrees with Vince Lombardi’s view: “Leaders are made, they are not born.” But the making process can be almost accidental rather than planned. “Originally, I was a bit of an introvert. I was attracted to computers because they’re like a safe space.” While learning to hack as a youngster, he met (online) many other people engaged in the same process of research and hacking.

    As his career progressed and he needed to work with other people on different projects, he always preferred working with people he knew, liked and understood. For new projects, he had to hire people to work with him. “So,” he thought at the time, “I’ll hire all these amazing hackers or researchers that I know, that I want to work with, and who I know like to work together.” That’s what he did. But if you build a team, even if you are building a team of friendly equals, it is only natural that the team builder becomes the team leader. For Waisman, becoming a leader was simply the natural evolution of what he was doing – it was neither an innate part of his psychology nor a planned progression of his career.

    “Eventually, life and age slowly push you into a management position; and the moment you say, yes, there’s no turning back,” he explains. “As I was growing, I started running teams, initially working on product development, and then doing services. At one point I had 30 or 40 pen testers reporting to me. We were serving Fortune 500 companies, helping them perform application security tests, penetration tests and so on.”

    After 17 years at Immunity, he left to join Semmle in June 2019 as director of research for Latin America. Semmle had been founded by Oege de Moor in 2006. Within a few months of Waisman joining Semmle, it was acquired by GitHub; and by the end of 2019, Waisman was the senior director of GitHub Security Lab.

    This provided a further evolution in Waisman’s offensive security interests and expertise: open source software. GitHub was already a home for developers and was increasingly keen on securing the software supply chain. This required a new focus on open source software and its danger to the CI/CD pipeline. While at GitHub, Waisman helped his new home adopt and integrate Semmle’s CodeQL. 

    “GitHub Security Lab was a group focused on improving open source software. It was already the de facto home of developers, but it wanted to develop a new focus on open source developers. Big companies, including Microsoft, Google and others, were doing their own work to help secure open source, but in an isolated way, each doing their own thing. So, we worked on forming a coalition of companies to work together to secure OSS. Eventually, we passed the result to the Linux Foundation, where it is now formally housed as the Open Source Security Foundation.”

    By this point, Waisman’s cybersecurity journey had gone from child hacker through professional offensive security researcher to leader and open source security expert. One major step still missing was the jump into the C-suite. It didn’t take long.

    “A friend offered me the opportunity to help Lyft rebuild its security team. All my life I had been focused on offensive security, and I had done just about everything that can be done in offensive security. Now I wanted to explore what being on the defensive side was like.”

    He left GitHub and became the head of security and privacy at Lyft in 2020, and within two years became its CISO.

    “Lyft was a fantastic introduction to defensive security. It had an infrastructure serving thousands of rides every day, presenting a really fascinating new challenge for me: how do you build a security program that can match the speed of engineers without interrupting that speed?”

    By necessity, almost the first lesson in defensive security he learned was the necessity of combining defense with enablement. It’s like football: you need a solid defense to enable your forwards to advance – you do not want a defense that defends by simply kicking the ball out of the stadium at every opportunity. 

    He did this for three years. Oege de Moor had approached him with an idea for a new firm. The two already had a long relationship: de Moor had founded Semmle and had also been at GitHub. After GitHub was acquired by Microsoft, de Moor led the team that built Microsoft’s Copilot AI.

    “We started discussing the idea of combining AI and offensive security, which was definitely my area of expertise,” explains Waisman. “So, we built this company called XBOW, and we’ve been in business for two years. It was the first AI autonomous product that can perform penetration tests, mimicking human skills, and can do it at scale.”

    Waisman was XBOW’s CISO from the outset, and it is what and where he is today. His professional career had come full circle, starting with offensive security, acquiring new skills in leadership, defensive security, and artificial intelligence, and then combining everything into being CISO at a firm that conducts AI autonomous offensive security.

    Nowhere in this journey is there any sign of a structured career plan beyond a desire and ability to learn, a preference to work with people he knew, and a willingness to accept the challenges presented by happenstance. This appearance confirms his original statement: “I don’t think I ever chose a career in cybersecurity. It chose me.”

    That doesn’t mean his journey has always been easy. Being a CISO brought him into close contact with burnout. Burnout is recognized by the WHO as an occupational hazard and is described as a state of severe physical, mental, and emotional exhaustion caused by prolonged, unmanaged stress. CISOs and their security teams are increasingly subject to it.

    “I wouldn’t say I was fully burned out during my time at Lyft, but for any CISO there is a huge amount of stress. You are in an impossible position, being responsible for the actions of other people. You have to balance security with enablement, which is really complicated. You’re constantly under-resourced; and although there are ways to manage all this, it all takes its toll – and if anything goes wrong, you are the one who is responsible.”

    Similar pressures affect the individual members of the security team; so, an added pressure on the CISO is keeping the team members safe from their own burnout. “One of the roles of leadership is to shield the team from too much pressure,” he says. “CISOs should absorb as much of the pressure of work as they can and be a filter to the amount that gets through to the individual team members.”

    He also promotes a healthy work/life balance for his team. “I believe I am very empathic – that’s one of my skills. I think I am able to detect when people are distressed and that’s the time for me to intervene and help them regain the right balance.”

    It’s fitting for a person who had no fixed career plan to have little memory of any career advice he received. He does, however, remember learning one thing from Dave Aitel, the founder of Immunity. “In security, there are things that matter and other things that are just theater,” he explains. “Focus on the things that really matter.” It was not so much specific advice as learning through mentorship.

    Just as he doesn’t recall receiving career advice, he similarly doesn’t go out of his way to offer his own team specific advice. “I think my role is to provide constant mentoring rather than tell them what to do in the future. I take a Socratic approach to teaching – not by providing answers but by asking questions so that people can find their own answers.” Socrates described this method as maieutics (midwifery) – just as a midwife doesn’t give birth (to new ideas) personally, the midwife assists with the birth (of new ideas).

    Despite the aura of calmness that Waisman projects, everyone has one thing that worries them most. For him it is AI (fittingly since his firm operates an AI-based autonomous offensive security platform).

    “Just as defenders have a budget, so too do attackers,” he explains. “For now, using AI is too expensive to do what is already possible on a grand scale. But the cost will come down. We’ll get to the point, pretty quickly, where there will be a positive ROI for attackers to target IPs with autonomously adjusting malware on a massive scale – and we’re just not ready for that yet.”

    AI is continuously improving, and both attackers and defenders are using it. Almost always, attackers adopt new technology faster than defenders. Eventually, defenders will catch up, and there will be renewed balance. Until that happens, suggests Waisman, “There’s going to be a bit of chaos out there.”

    Related: CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct

    Related: CISO Conversations: Ross McKerchar, CISO at Sophos

    Related: CISO Conversations: Aimee Cardwell

    Related: CISO Conversations: Timothy Youngblood; 4x Fortune 500 CISO/CSO

    AIDriven CISO Conversations Hacker Nico offensive Security SelfTaught Waisman XBOW
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI president urges enterprises to hasten AI security defences

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    Trump Family Crypto Firm Tied to Chinese AI Models US Government Called a Security Risk

    AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

    Gehen der Ukraine die Schutzschilde aus? Mit Nico Lange – POLITICO

    TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump’s Syria envoy calls Israeli air strikes on base ‘unnecessary escalation’

    August 18, 2026

    What is behind Russia’s ‘consequences’ threat over UK sending drones to Ukraine? | Russia

    August 18, 2026

    Swedish MP intervenes in ‘damaging’ Brexit row over elderly Britons ordered to leave | Brexit

    August 18, 2026

    Tesla is finally launching the Cybercab — let’s hope it’s ready

    August 18, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump’s Syria envoy calls Israeli air strikes on base ‘unnecessary escalation’

    August 18, 2026

    What is behind Russia’s ‘consequences’ threat over UK sending drones to Ukraine? | Russia

    August 18, 2026

    Swedish MP intervenes in ‘damaging’ Brexit row over elderly Britons ordered to leave | Brexit

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.