Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

CISO Conversations

CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

With no formal training and no career plan, Waisman built a path from Argentina’s early hacking scene to leading security at an AI-powered offensive security firm.

CISO Nico Waisman

“I don’t think I ever chose a career in cybersecurity. It chose me.” Well, we’ll see…

Nico Waisman was born and still lives in Argentina. If what he says is accurate, it suggests he was born in 1982; one year before a seven-year period of military dictatorship in Argentina came to an end.

Argentine youngsters in the 1980s lived in a time of youthful rebelliousness against the law and the establishment, lingering after the dictatorships. For Waisman, this youthful rebelliousness turned toward emerging technology. He became fascinated by the idea of being able to subvert this tech into doing something he wanted it to do. In short, he became a young hacker – but it was the challenge and enjoyment of doing it rather than any desire to make money or cause harm from it that drove him.

He received no training in computer technology nor cybersecurity. Neither existed in Argentina at that time. Everything he learned about code, bugs, finding vulnerabilities and exploiting them, he taught himself. 

“There was no documentation for anything, which was part of the fascination and challenge,” he explains. “So, there was a lot of experimentation and a lot of reverse engineering, to learn how things worked and how to subvert them. This is what I really, really liked and still enjoy: you spend days focusing on one problem, understanding how it works, and then trying to see how you can break it.”

This was the origin of a career in offensive security. But again, in Argentina at that time, there was no such thing as a career in offensive security. Instead, he considered a career in engineering, but he dropped out of engineering school a couple of times. He then tried ‘communication’ and spent four years studying journalism. Again, he didn’t complete the course and gain a degree; he didn’t do the thesis. All the time he explored other options and developed, for example, new communication skills, his first love was still hacking.

Advertisement. Scroll to continue reading.

“Eventually,” he says, “even in Argentina, the future showed up, and I was able to get a job in cybersecurity.” In 2003 he joined Immunity as a senior security researcher. He may not have had formal cybersecurity qualifications, but he had hands-on experience and an ability to demonstrate his knowledge. It was the beginning of his professional career, three-quarters of which has been in offensive security, founded in his early self-taught knowledge of hacking methods.

He remained at Immunity until 2019, progressively moving up the ladder to become VP of Latin America. “We were building a product [CANVAS, an exploitation framework that largely shaped how early pentesters and red teams evolved] that helped people perform their own penetration testing. I was working both with public and private companies, helping to find vulnerabilities and how they could be exploited, initially with Linux and later with Windows.”

During this 17-year period, he used his personal expertise from earlier hacking, exercised the communication skills he had acquired (he spoke at conferences including Black Hat, Syscan, PacSec, RuxCon, and Ekoparty), and learned new leadership skills.

Waisman agrees with Vince Lombardi’s view: “Leaders are made, they are not born.” But the making process can be almost accidental rather than planned. “Originally, I was a bit of an introvert. I was attracted to computers because they’re like a safe space.” While learning to hack as a youngster, he met (online) many other people engaged in the same process of research and hacking.

As his career progressed and he needed to work with other people on different projects, he always preferred working with people he knew, liked and understood. For new projects, he had to hire people to work with him. “So,” he thought at the time, “I’ll hire all these amazing hackers or researchers that I know, that I want to work with, and who I know like to work together.” That’s what he did. But if you build a team, even if you are building a team of friendly equals, it is only natural that the team builder becomes the team leader. For Waisman, becoming a leader was simply the natural evolution of what he was doing – it was neither an innate part of his psychology nor a planned progression of his career.

“Eventually, life and age slowly push you into a management position; and the moment you say, yes, there’s no turning back,” he explains. “As I was growing, I started running teams, initially working on product development, and then doing services. At one point I had 30 or 40 pen testers reporting to me. We were serving Fortune 500 companies, helping them perform application security tests, penetration tests and so on.”

After 17 years at Immunity, he left to join Semmle in June 2019 as director of research for Latin America. Semmle had been founded by Oege de Moor in 2006. Within a few months of Waisman joining Semmle, it was acquired by GitHub; and by the end of 2019, Waisman was the senior director of GitHub Security Lab.

This provided a further evolution in Waisman’s offensive security interests and expertise: open source software. GitHub was already a home for developers and was increasingly keen on securing the software supply chain. This required a new focus on open source software and its danger to the CI/CD pipeline. While at GitHub, Waisman helped his new home adopt and integrate Semmle’s CodeQL. 

“GitHub Security Lab was a group focused on improving open source software. It was already the de facto home of developers, but it wanted to develop a new focus on open source developers. Big companies, including Microsoft, Google and others, were doing their own work to help secure open source, but in an isolated way, each doing their own thing. So, we worked on forming a coalition of companies to work together to secure OSS. Eventually, we passed the result to the Linux Foundation, where it is now formally housed as the Open Source Security Foundation.”

By this point, Waisman’s cybersecurity journey had gone from child hacker through professional offensive security researcher to leader and open source security expert. One major step still missing was the jump into the C-suite. It didn’t take long.

“A friend offered me the opportunity to help Lyft rebuild its security team. All my life I had been focused on offensive security, and I had done just about everything that can be done in offensive security. Now I wanted to explore what being on the defensive side was like.”

He left GitHub and became the head of security and privacy at Lyft in 2020, and within two years became its CISO.

“Lyft was a fantastic introduction to defensive security. It had an infrastructure serving thousands of rides every day, presenting a really fascinating new challenge for me: how do you build a security program that can match the speed of engineers without interrupting that speed?”

By necessity, almost the first lesson in defensive security he learned was the necessity of combining defense with enablement. It’s like football: you need a solid defense to enable your forwards to advance – you do not want a defense that defends by simply kicking the ball out of the stadium at every opportunity. 

He did this for three years. Oege de Moor had approached him with an idea for a new firm. The two already had a long relationship: de Moor had founded Semmle and had also been at GitHub. After GitHub was acquired by Microsoft, de Moor led the team that built Microsoft’s Copilot AI.

“We started discussing the idea of combining AI and offensive security, which was definitely my area of expertise,” explains Waisman. “So, we built this company called XBOW, and we’ve been in business for two years. It was the first AI autonomous product that can perform penetration tests, mimicking human skills, and can do it at scale.”

Waisman was XBOW’s CISO from the outset, and it is what and where he is today. His professional career had come full circle, starting with offensive security, acquiring new skills in leadership, defensive security, and artificial intelligence, and then combining everything into being CISO at a firm that conducts AI autonomous offensive security.

Nowhere in this journey is there any sign of a structured career plan beyond a desire and ability to learn, a preference to work with people he knew, and a willingness to accept the challenges presented by happenstance. This appearance confirms his original statement: “I don’t think I ever chose a career in cybersecurity. It chose me.”

That doesn’t mean his journey has always been easy. Being a CISO brought him into close contact with burnout. Burnout is recognized by the WHO as an occupational hazard and is described as a state of severe physical, mental, and emotional exhaustion caused by prolonged, unmanaged stress. CISOs and their security teams are increasingly subject to it.

“I wouldn’t say I was fully burned out during my time at Lyft, but for any CISO there is a huge amount of stress. You are in an impossible position, being responsible for the actions of other people. You have to balance security with enablement, which is really complicated. You’re constantly under-resourced; and although there are ways to manage all this, it all takes its toll – and if anything goes wrong, you are the one who is responsible.”

Similar pressures affect the individual members of the security team; so, an added pressure on the CISO is keeping the team members safe from their own burnout. “One of the roles of leadership is to shield the team from too much pressure,” he says. “CISOs should absorb as much of the pressure of work as they can and be a filter to the amount that gets through to the individual team members.”

He also promotes a healthy work/life balance for his team. “I believe I am very empathic – that’s one of my skills. I think I am able to detect when people are distressed and that’s the time for me to intervene and help them regain the right balance.”

It’s fitting for a person who had no fixed career plan to have little memory of any career advice he received. He does, however, remember learning one thing from Dave Aitel, the founder of Immunity. “In security, there are things that matter and other things that are just theater,” he explains. “Focus on the things that really matter.” It was not so much specific advice as learning through mentorship.

Just as he doesn’t recall receiving career advice, he similarly doesn’t go out of his way to offer his own team specific advice. “I think my role is to provide constant mentoring rather than tell them what to do in the future. I take a Socratic approach to teaching – not by providing answers but by asking questions so that people can find their own answers.” Socrates described this method as maieutics (midwifery) – just as a midwife doesn’t give birth (to new ideas) personally, the midwife assists with the birth (of new ideas).

Despite the aura of calmness that Waisman projects, everyone has one thing that worries them most. For him it is AI (fittingly since his firm operates an AI-based autonomous offensive security platform).

“Just as defenders have a budget, so too do attackers,” he explains. “For now, using AI is too expensive to do what is already possible on a grand scale. But the cost will come down. We’ll get to the point, pretty quickly, where there will be a positive ROI for attackers to target IPs with autonomously adjusting malware on a massive scale – and we’re just not ready for that yet.”

AI is continuously improving, and both attackers and defenders are using it. Almost always, attackers adopt new technology faster than defenders. Eventually, defenders will catch up, and there will be renewed balance. Until that happens, suggests Waisman, “There’s going to be a bit of chaos out there.”

Related: CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct

Related: CISO Conversations: Ross McKerchar, CISO at Sophos

Related: CISO Conversations: Aimee Cardwell

Related: CISO Conversations: Timothy Youngblood; 4x Fortune 500 CISO/CSO

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.