From Argentina's Early Hacking Scene to AI-Powered Offensive Security: The Nico Waisman Story
How a self-taught hacker with no formal training or career plan built his way to leading security at XBOW, a firm that uses artificial intelligence to find weaknesses before attackers do.

Key points
- Nico Waisman learned hacking entirely through self-study, starting out in Argentina's early underground computing scene.
- He went on to become Chief Information Security Officer (CISO) at XBOW, a company that uses artificial intelligence to run offensive security operations.
- Offensive security means deliberately trying to break into a company's own systems, finding the gaps before criminals do.
- Waisman's path reflects a broader shift in the industry: some of the most effective security leaders came up outside traditional education.
Nico Waisman did not study computer science at university. He did not follow a graduate scheme. He learned to hack by doing it, starting in Argentina during the early days of the public internet, when online communities were small and knowledge spread through curiosity rather than coursework.
That background, detailed in a profile first published by SecurityWeek, brought him eventually to XBOW, where he now serves as Chief Information Security Officer, or CISO. The CISO is the senior executive responsible for keeping an organisation's systems and data safe.
What does XBOW actually do?
XBOW runs offensive security, meaning it attacks its clients' own systems on purpose, with permission, to find weaknesses. The firm uses artificial intelligence, software that can learn patterns and make decisions without being told exactly what to do each time, to automate parts of that process.
Traditionally, this kind of work, called penetration testing or "pen testing", relied entirely on human experts manually probing systems for flaws. It is slow and expensive. XBOW's pitch is that AI can run many of those same checks faster and at greater scale.
Whether AI-driven pen testing finds the same quality of vulnerabilities as a seasoned human researcher is a live debate in the security industry. Critics argue that automated tools miss the creative leaps a skilled human makes. Supporters say AI handles the repetitive groundwork well, freeing humans for the harder problems.
Why does a hacker's backstory matter?
It matters because the security industry has long argued about credentials. Some employers still filter candidates by degree or certification. Waisman is a counter-example: no formal training, genuine expertise.
His route also mirrors how a generation of security professionals actually developed. Forums, shared code, trial and error on home machines. That culture produced people with deep hands-on instincts that classroom courses often do not replicate.
For organisations hiring security staff, the implication is practical. Filtering out candidates without conventional qualifications can mean passing over exactly the people best equipped to think like an attacker.
What should ordinary people take from this?
Most readers will not become CISOs. The relevance here is narrower and more direct.
Organisations that hire security teams willing to attack their own systems, human or AI-assisted, find weaknesses before outsiders do. Customers of those organisations benefit from that rigour, even if they never see it. Asking a business "do you test your own defences regularly?" is a reasonable question, and a good answer should involve more than a shrug.



