Nico Waisman: From Hacker to CISO at AI Penetration Firm

Self-taught Argentine hacker Nico Waisman built roles at Immunity, GitHub and Lyft and now co-founded XBOW, where he serves as CISO for an AI-driven autonomous penetration testing platform.

Nico Waisman began as a self-taught programmer and hacker in Argentina and later held roles at offensive security firm Immunity, at GitHub and as Lyft’s head of security and CISO. He is now CISO and co-founder of XBOW, a startup that develops AI-driven autonomous penetration testing tools.

Waisman learned programming and vulnerability research through experimentation and reverse engineering. He recalled that early work lacked formal documentation and required trial-and-error to understand how systems behaved. “There was no documentation for anything,” he said, describing those years as hands-on learning focused on finding and exploiting vulnerabilities rather than profit.

He joined Immunity in 2003 as a senior security researcher and spent 17 years there, advancing to vice president for Latin America. At Immunity he contributed to the CANVAS exploitation framework and led penetration-testing teams that worked with corporate clients, including large enterprises. At times he managed 30 to 40 penetration testers and led both product work and client services.

In June 2019 Waisman left Immunity to join Semmle as director of research for Latin America. Semmle was acquired by GitHub within months, and by the end of 2019 he was senior director at GitHub Security Lab. He worked on integrating Semmle’s CodeQL into GitHub tooling and helped form a multi-company effort to improve open-source software security that was later placed under the Linux Foundation as the Open Source Security Foundation.

Waisman moved to Lyft in 2020 to lead security and privacy and became CISO within two years. He described the main challenge at Lyft as creating a security program that matched engineering speed without blocking development. He stressed the need to enable product teams while maintaining protective controls and described leadership as an incremental shift that followed his work building and managing teams.

After Lyft, Waisman joined Oege de Moor to found XBOW. The company offers software that automates penetration testing with AI models designed to mimic human testers and run tests at scale. Waisman highlighted both potential uses and risks of AI in offensive security and warned that current costs limit wide attacker use. “For now, using AI is too expensive to do what is already possible on a grand scale. But the cost will come down,” he observed.

Waisman has presented at major security conferences and prefers to hire people he knows and has worked with. He addressed stress and burnout in security teams and emphasized a leader’s role in reducing pressure on staff. “One of the roles of leadership is to shield the team from too much pressure,” he said, and described using empathy and questioning to mentor team members rather than prescribing a single career path.

At XBOW, Waisman combines experience in offensive research, defensive security and software tooling to develop automated offensive testing while noting the operational and ethical questions that follow wider deployment of AI-driven tools.

Articles by this author