**From Child Hacker to CISO: How Nico Waisman’s Career Was Chosen for Him**
Nico Waisman’s career in cybersecurity is a testament to the unpredictable paths many professionals take in this dynamic field. Born in Argentina in the early 1980s, Waisman’s journey began not with a formal plan, but with a deep-seated curiosity for technology and a rebellious spirit that turned him into a young hacker. With no formal training or cybersecurity programs available at the time, he taught himself coding, reverse engineering, and vulnerability exploitation out of sheer fascination and a love for the challenge.
His career in offensive security started organically. After drifting through studies in engineering and journalism without completing them, he found his true calling in hacking. In 2003, he joined Immunity as a senior security researcher, where his hands-on experience and self-taught expertise quickly propelled his career forward. Over 17 years, he evolved from a technical researcher to a leader, eventually becoming VP of Latin America. His work on Immunity’s CANVAS exploitation framework shaped the way pentesters and red teams operated, and he became a prominent voice at major security conferences.
Waisman’s leadership journey was as accidental as it was natural. Preferring to work with people he knew and trusted, he found himself leading teams almost by necessity as projects grew and responsibilities expanded. What began as a preference for working with friends became a leadership role managing hundreds of pen testers serving Fortune 500 companies.
A major turning point came when he joined GitHub as Senior Director of Security Lab, where he helped integrate CodeQL and championed open source software security. This role expanded his focus from traditional offensive security to securing the software supply chain, collaborating with industry giants to form a coalition for open source security under the Linux Foundation.
The leap into the C-suite followed when he was asked to help rebuild Lyft’s security team. As head of security and privacy, and later as CISO, he applied his offensive security background to defense, emphasizing the importance of balancing security with enablement. He likened a strong security program to a football defense—necessary not to block progress, but to enable it.
Today, Waisman serves as CISO at XBOW, a company he co-founded that leverages AI to conduct autonomous penetration testing. His career has come full circle—from self-taught hacker to offensive security expert, leader, open source advocate, and now AI-driven security leader.
**Frequently Asked Questions (FAQ)**
**Q: Did Nico Waisman have formal training in cybersecurity?**
A: No. Waisman had no formal cybersecurity education or training. He taught himself everything—coding, reverse engineering, and exploitation—due to a lack of available resources in Argentina at the time.
**Q: What was the catalyst for Waisman’s shift from hacking to a professional security career?**
A: The catalyst was the evolution of the cybersecurity field in Argentina and the growing recognition of offensive security as a legitimate career. In 2003, he joined Immunity as a senior security researcher, which allowed him to transition from hobbyist hacking to a professional role.
**Q: How did Waisman move into leadership roles?**
A: Leadership came naturally as he worked with trusted colleagues on increasingly complex projects. As teams expanded, he found himself leading—not by design, but by circumstance and his ability to attract and work with talented people.
**Q: What role did open source security play in his career?**
A: At GitHub, Waisman helped pioneer open source security efforts, forming coalitions across major tech companies to secure the software supply chain. This work led to the creation of the Open Source Security Foundation under the Linux Foundation.
**Q: How does Waisman balance security with business enablement?**
A: He emphasizes a “defense with enablement” approach, ensuring security supports rather than stifles innovation. He believes security teams must remove obstacles for engineers, not block them.
**Q: What advice does Waisman offer to his team?**
A: Instead of giving direct advice, Waisman mentors through questioning—a Socratic approach. He encourages team members to find their own solutions, acting as a midwife to new ideas rather than dictating them.
**Q: What worries Waisman most in his current role?**
A: His primary concern is AI. As both defenders and attackers adopt AI, he fears that attackers will eventually use it at scale to create autonomously adjusting malware, making defense significantly more challenging and potentially chaotic.
—
**Conclusion**
Nico Waisman’s career defies the traditional narrative of planned professional progression. His path—from self-taught hacker in Argentina to CISO of an AI security firm—was shaped by curiosity, adaptability, and a willingness to embrace whatever came his way. He never chose cybersecurity; cybersecurity chose him.
His story highlights the value of hands-on experience, continuous learning, and leading through influence rather than authority. It also underscores the evolving nature of security—from offensive hacking to open source defense and now AI-driven security—where flexibility and a thirst for knowledge are just as important as technical skills.
For professionals navigating their own paths, Waisman’s journey is a reminder that sometimes the most impactful careers are the ones we don’t plan—but the ones that plan us.



