Nico Waisman: From Self-Taught Hacker to AI-Driven Offensive Security
Argentine-born Nico Waisman never formally chose cybersecurity as a career—it chose him. Growing up in Buenos Aires in the 1980s, amid the lingering cultural residue of military dictatorship, Waisman found himself drawn to the rebellious allure of emerging computer technology. With no formal training available in Argentina at the time, he taught himself everything about code, reverse engineering, and vulnerability exploitation through pure experimentation. "There was no documentation for anything, which was part of the fascination and challenge," Waisman recalls, describing how he would spend days dissecting a single problem to understand—and ultimately subvert—how systems worked. This relentless curiosity laid the foundation for what would become a 20-year career in offensive security.
In 2003, Waisman joined Immunity as a senior security researcher, where he would spend the next 17 years rising to VP of Latin America. There, he helped shape CANVAS, the exploitation framework that became foundational training ground for an entire generation of penetration testers and red team operators. His work spanned both public and private sector engagements, initially focused on Linux systems before expanding into Windows environments. Today, Waisman applies that same persistence-driven mindset to his current role at XBOW, where he is helping build an AI-driven offensive security platform designed to autonomously identify and exploit vulnerabilities at machine speed. Practitioners exploring similar offensive techniques can validate their own attack surfaces using a port scanner to identify exposed services, or check their digital exposure with an email breach checker.
At XBOW, Waisman is pioneering the convergence of traditional penetration testing methodologies with artificial intelligence, training models to replicate the intuition and creative problem-solving that defined his self-taught background. The platform represents a significant shift in how organizations approach vulnerability discovery—moving from manual, time-intensive red team engagements toward scalable, AI-augmented continuous testing. Waisman's journey illustrates a broader trend in the industry: the automation of offensive tradecraft. As AI systems become increasingly capable of reasoning about complex software behaviors, the line between human and machine-driven exploitation continues to blur. Security teams adapting to this new reality should also evaluate their defensive posture with an SSL/TLS checker to ensure encrypted communications are properly configured against modern attack vectors.
Waisman's career arc—from Argentine teenager reverse-engineering undocumented software, to architect of one of the industry's most influential exploitation frameworks, to his current work building AI-powered offensive tools—reflects the maturation of cybersecurity as a discipline. His philosophy remains unchanged: "You spend days focusing on one problem, understanding how it works, and then trying to see how you can break it." That ethos, now amplified through AI, is reshaping how the industry thinks about vulnerability discovery, red team operations, and the future of defensive security in an era where attackers and defenders alike are racing to harness artificial intelligence.