From Argentina's Early Hacking Scene to AI-Powered Offensive Security: The Nico Waisman Story
How a self-taught hacker with no formal training built his way to leading security at XBOW, a firm that uses artificial intelligence to find weaknesses before attackers do.

Key points
- Nico Waisman learned hacking entirely through self-study, starting in Argentina's early underground computing scene.
- He now serves as Chief Information Security Officer (CISO) at XBOW, a company that uses artificial intelligence to run offensive security operations.
- Offensive security means deliberately attempting to break into a company's own systems, finding gaps before criminals do.
- Some of the most effective security leaders came up outside traditional education, and Waisman's path is a clean example of that.
Nico Waisman didn't study computer science at university and didn't follow any graduate scheme. He learned to hack by doing it, starting in Argentina during the early days of the public internet, when knowledge spread through curiosity rather than coursework.
That background, detailed in a profile first published by SecurityWeek, brought him to XBOW, where he now serves as CISO. The CISO is the senior executive responsible for keeping an organisation's systems and data safe.
What does XBOW actually do?
XBOW runs offensive security: it attacks clients' own systems on purpose, with permission, to find weaknesses. The firm uses artificial intelligence to automate parts of that process. We've covered XBOW twice in the past 90 days, starting with our first report on 9 June 2026.
Traditionally, this kind of work, called penetration testing or pen testing, relied on human experts manually probing systems for flaws. It's slow and expensive. XBOW's pitch is that AI can run many of those checks faster and at greater scale.
The debate isn't settled. Some in the industry say automated tools miss the creative leaps a skilled human makes; others say AI handles repetitive groundwork well, freeing humans for harder problems. Both things can be true.
Why does a hacker's backstory matter?
The security industry has long argued about credentials. Some employers still filter candidates by degree or certification. Waisman is a counter-example: no formal training, genuine expertise.
His route mirrors how a generation of professionals actually developed. Forums, shared code and hours of trial on home machines. That culture produced people with hands-on instincts that classroom courses often don't replicate. As we found in our 4 August piece on Ping Identity's CISO Russ Kirby, the informal path to the C-suite is more common than hiring managers tend to admit.
Filtering out candidates without conventional qualifications can mean passing over exactly the people best equipped to think like an attacker.
Should you worry about who is protecting your data?
Most readers won't become CISOs. The relevance is narrower.
Organisations that hire security teams to attack their own systems find weaknesses before outsiders do. Customers of those organisations benefit from that rigour, even if they never see it. Asking a business whether it tests its own defences regularly is a fair question. A good answer is specific; a shrug isn't.



