Nico Waisman has a simple way of describing his career: “I don’t think I ever chose a career in cybersecurity. It chose me.” His story starts far from structured security education and ends in the C-suite—where he now tackles the next shift in offensive work powered by artificial intelligence. Along the way, he moved from hands-on vulnerability research to leadership, from offensive expertise to defense, and from traditional testing to AI autonomous penetration attempts.
What makes the journey especially interesting is how little it followed a straight line. Instead, it reflects curiosity, a preference for learning by doing, and an ability to adapt as the industry changed around him.
From self-taught hacker to professional offensive research
Waisman grew up in Argentina and remained there. In his telling, the environment of his youth brought rebellious energy toward emerging technologies rather than away from them. Instead of aiming for money or causing harm, he was drawn to the intellectual challenge: taking technology apart, understanding how it works, and finding a way to break it.
He did not receive formal computer or cybersecurity training. Back then, he says, relevant documentation was scarce, and that lack became part of the appeal. He learned coding, bug discovery, exploitation, and reverse engineering through experimentation—spending days focused on a single problem until he could see what made it fail.
This mindset eventually pushed him toward offensive security as a career direction, even if the concept didn’t exist as a clear path in his region at the time. He considered other avenues—engineering and even journalism—but he repeatedly found himself returning to hacking and the practical investigation that came with it.
Immunity years: scaling offensive security knowledge
By 2003, even though he lacked formal cybersecurity qualifications, Waisman began working in the field. He joined Immunity as a senior security researcher and remained there until 2019. During that period, he progressed to VP of Latin America.
A key part of his work centered on helping others perform penetration testing. His team built a product called CANVAS, an exploitation framework that influenced early pentesting and red team practices. Waisman’s role combined vulnerability research with practical guidance—working with both public and private organizations.
Initially, he supported environments centered on Linux, later shifting toward Windows. He also credited communication and presentation as a major driver of his growth: he spoke at conferences including Black Hat and multiple regional security events. In parallel, he gained leadership experience that came not just from managing tasks, but from coordinating people who were doing real security work under real constraints.
Leadership without a master plan
Waisman’s leadership approach didn’t come from a lifelong plan. He described himself as somewhat introverted early on, attracted to computers as a “safe space.” Over time, however, he realized that career progression required collaboration across projects and teams.
When new initiatives arrived, he preferred hiring people he already knew and understood—then building teams of researchers who could work together effectively. Inevitably, that team-building expanded into team leadership. He explained that leadership can be the natural evolution of what you’re already doing, especially when you’re responsible for how work happens.
He also shared a view aligned with Vince Lombardi’s idea that leaders are made, not born. In Waisman’s case, that “making” process happened through experience: running teams, handling product development, and later supporting services for major enterprises. At one point, he managed dozens of pentesters serving Fortune 500 companies with application security testing and penetration testing.
GitHub Security Lab and the shift toward open source risk
After leaving Immunity in June 2019, Waisman joined Semmle as director of research for Latin America. Semmle had been founded by Oege de Moor, and within a short time, Semmle was acquired by GitHub. By the end of 2019, Waisman became senior director of GitHub Security Lab.
This phase added a new dimension to his offensive security foundation: open source software. Waisman said that securing the software supply chain required focusing on how OSS can introduce risks, especially along CI/CD pipelines.
At GitHub, he helped integrate Semmle’s CodeQL and supported a broader effort to improve open source security. GitHub Security Lab’s mission included forming a coalition across companies that were already working to secure OSS—but often in isolation. The end result was handed to the Linux Foundation, where the initiative is now housed as the Open Source Security Foundation.
For Waisman, the experience represented another “evolution step” in his cybersecurity journey: from hands-on offensive research, to leadership, to open source security expertise.
Lyft: learning defensive security at C-suite level
Even with offensive strength and research leadership behind him, Waisman saw one major gap: moving fully into defensive responsibilities. The opportunity came through a friend who offered him a chance to help rebuild a security organization at Lyft.
He joined in 2020 as head of security and privacy and became CISO within two years. The work introduced an everyday defensive challenge he highlighted: how to build a security program that can keep up with engineering speed without slowing teams down or disrupting momentum.
His first lessons in defense involved the balance between protection and enablement. He compared it to football: strong defense matters, but the goal is not to “kick the ball out of the stadium” every time an issue appears. Defense has to support the team’s ability to advance.
In his view, building a defensive program that engineers can still move through requires careful trade-offs, strong operational clarity, and constant communication about what security does and why.
Building XBOW and bringing AI to offensive security
While at Lyft, Waisman discussed a new idea with Oege de Moor—someone he had worked with across multiple stages of his career. Their collaboration centered on combining AI with offensive security, leveraging Waisman’s expertise while creating something new.
They formed XBOW. Waisman described it as the first AI autonomous product designed to perform penetration tests by mimicking human skills and scaling that capability. XBOW’s work reflects a return to offensive security—now paired with a different automation model.
As the CISO from the outset, Waisman positioned his experience across the stack: offensive expertise, defensive leadership, and AI-focused innovation. In effect, his career had “come full circle,” but with a modern objective—AI autonomous offensive security.
Burnout risk and the CISO’s responsibility to the team
Leadership in security does not come without cost. Waisman described burnout as a constant pressure that CISOs can face, especially given responsibility for the actions of other people and the need to balance security with enablement. He noted that teams can be under-resourced and that fixes take time—meaning the toll accumulates over the long run.
He also emphasized that leadership includes protecting the team from excessive pressure. One responsibility of a leader, he said, is acting as a buffer—absorbing some of the stress so it does not fully reach individual team members.
Another practical element is empathy. He believes he can detect when people become distressed and that intervention is sometimes necessary to restore a healthier work-life balance.
Mentorship over directives
When it comes to advising others, Waisman does not treat leadership as the act of giving constant answers. He remembered learning a lesson from Dave Aitel, founder of Immunity: focus on what truly matters, rather than “theater.” For Waisman, mentorship mattered more than formal career instructions.
He applies a Socratic teaching style—asking questions instead of dictating outcomes. The approach helps people find their own solutions, and it supports growth without creating dependency on the leader for every decision.
This style fits his background: he was never handed a handbook for cybersecurity. He learned by investigating, experimenting, and figuring things out step by step.
Why AI-Driven Offensive Security raises concerns for defenders
Despite projecting calm, Waisman said there is one topic that worries him most: AI’s trajectory. Because attackers and defenders both operate under budget realities, he believes AI capabilities will become easier for attackers to use at scale once costs fall.
In his expectation, defenders may face increasing pressure as AI-driven malware can adjust autonomously and target IPs across a much wider set of targets. He argues that the industry is not fully prepared for that level of ROI-driven offensive automation yet.
He also cautioned that attackers usually adopt new technology faster than defenders. Over time, defensive communities catch up, but until that balancing phase arrives, he expects “a bit of chaos.”
Conclusion: an adaptive career built on learning, leadership, and AI
Nico Waisman’s career highlights how cybersecurity leadership can grow out of curiosity rather than a rigid plan. Starting as a self-taught hacker, he built credibility through hands-on offensive research, expanded into leadership at Immunity, contributed to open source security efforts via GitHub Security Lab, and learned defensive program design at Lyft.
Today, his focus on AI-Driven Offensive Security through XBOW reflects both continuity and change: the same drive to understand how systems can be broken, now extended with autonomous AI capabilities. And with AI improving on all sides, his message is clear—security teams must keep evolving, manage pressure wisely, and prepare for a future where offensive automation becomes harder to contain.
