# The Hacker Who Skipped the Résumé and Ended Up Building AI That Hunts Bugs for a Living


Nico Waisman never enrolled in a cybersecurity program. There wasn't one to enroll in — not in Argentina in the mid-nineties, not for the kind of knowledge he was chasing. He learned the way most of that generation learned: by breaking things until he understood them, trading techniques with a small community of people doing the same thing, and developing an intuition for systems that no classroom has ever reliably taught.


Now he's CISO at XBOW, a startup building AI-driven offensive security tooling. The through-line is less surprising than it sounds.


## Argentina Before the Scene Had a Name


Latin America's early hacking community is underwritten in the history of infosec. Most of the canonical origin stories run through MIT, Bell Labs, and the German Chaos Computer Club. But there were parallel tracks — in Buenos Aires, in São Paulo, in communities that had to work harder to get access to the infrastructure that western hackers took for granted.


Waisman came up in that environment. Limited hardware, limited connectivity, and unlimited curiosity about how systems actually behaved under pressure. That constraint shapes how you think about security in ways that formal education rarely replicates. When you can't buy your way to the answer, you develop pattern recognition. You learn to read code like a native language because you have no other option.


What Waisman accumulated over that period wasn't a credential — it was a methodology. An adversarial orientation toward software that assumes the specification is not the implementation, that trust is a liability, and that the interesting questions are always the ones vendors don't want asked.


## The Career That Looked Like a Career in Hindsight


Self-taught hackers who made names for themselves in the nineties and early 2000s followed a few different paths into the industry. Some ended up at boutique consultancies. Some got absorbed into the research arms of major vendors. A handful went the founding route. What almost none of them did was follow the conventional CISO playbook — compliance framework expertise, enterprise risk management, board-level reporting.


Waisman's path skewed toward the technical, which matters for understanding what he's doing at XBOW. His background is in vulnerability research and offensive tooling, not GRC. The difference is significant. A CISO who came up through compliance thinks about security as a surface area to be governed. A CISO who came up through offensive research thinks about it as an adversarial game — and builds accordingly.


XBOW is an expression of that second orientation. The company's pitch is essentially this: the economics of offensive security are broken because skilled human researchers are expensive, slow, and don't scale. AI changes the calculus.


## What AI-Driven Offensive Security Actually Means


The phrase "AI-powered security" has been diluted to meaninglessness by marketing departments, but what XBOW is attempting is worth taking seriously on its technical merits.


Traditional penetration testing is a manual, time-bounded process. A team of researchers gets scoped access to a target environment, runs a structured engagement over days or weeks, and produces a report. The quality of the output depends almost entirely on who's on the team and how much time they have. It's expensive, it's inconsistent, and it samples a small fraction of the actual attack surface.


What XBOW and a small number of similar firms are building is autonomous vulnerability discovery — systems that can continuously probe targets, correlate findings across large codebases, and identify exploitable conditions without waiting for a human to have the insight. The technical approaches vary: some rely heavily on fuzzing pipelines, some on LLM-assisted code analysis, some on hybrid methods that use AI to prioritize where human researchers should focus.


If it works at scale — and that's a genuine if — it changes the relationship between offense and defense in fundamental ways. The organizations that can afford continuous automated offensive testing will have a substantially clearer picture of their exposure. The organizations that can't will fall further behind.


## HackWire Analysis


Waisman's story is interesting in the profile sense — the self-made expert, the unlikely path — but the more important thread here is structural: the people now leading the AI-offensive-security wave are almost uniformly from the research and exploitation side of the house, not the governance side. That's not an accident, and it has real implications for how this technology gets built and deployed.


AI-driven vuln discovery is asymmetric in ways that should worry defenders more than the marketing copy suggests. XBOW and its competitors are building tools for the defense side — paying clients who want to know where they're exposed before an adversary finds out. That's legitimate and valuable work. But the same underlying capabilities — automated code analysis, exploit chain reasoning, surface area enumeration — are precisely what sophisticated threat actors would want to operationalize.


The self-taught hacker cohort that Waisman represents understands this intuitively. They came up in environments where the offensive and defensive knowledge were inseparable. The current wave of AI-security tooling is being built by people with that same dual fluency, which is probably the best-case scenario for responsible development. The risk is what happens when the techniques commoditize and the people building the next generation of tools don't have that intuition baked in.


There's a second concern other coverage is mostly ignoring: the penetration testing industry itself. If AI genuinely automates the core deliverable of a traditional pentest engagement, a significant portion of the security consultant workforce faces a productivity cliff. The senior researchers who understand exploitation deeply enough to validate and extend AI findings will be fine. The mid-tier testers running scripted engagements are the ones facing displacement — and the industry has not had an honest conversation about that transition.


Waisman's trajectory from Argentina's early hacking scene to a CISO chair at an AI security firm spans roughly the entire history of the modern infosec industry. The next chapter is being written now, and it's going to look a lot less like penetration testing as we've known it.


— HackWire Editorial


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)