Nico Waisman's Unconventional Journey in Cybersecurity
Nico Waisman, a native of Argentina, never planned a career in cybersecurity. Instead, it chose him. Growing up in a time of youthful rebelliousness against the law and the establishment in the 1980s, Waisman turned his fascination with emerging technology into a passion for hacking. Without formal training in computer technology or cybersecurity, he taught himself everything he knows about code, bugs, finding vulnerabilities, and exploiting them through experimentation and reverse engineering.
Early Days and the Origin of a Career in Offensive Security
Waisman's journey into offensive security began with his early self-taught knowledge of hacking methods. He joined Immunity as a senior security researcher in 2003, where he worked on building a product called CANVAS, an exploitation framework that significantly shaped how early pentesters and red teams evolved. Over 17 years, Waisman progressed up the ladder, becoming VP of Latin America, and exercised his communication skills by speaking at conferences like Black Hat, Syscan, PacSec, RuxCon, and Ekoparty.
Leadership and the Evolution of Offensive Security
Waisman agrees that leaders are made, not born. His leadership skills developed almost accidentally as he progressed in his career. He preferred working with people he knew and liked, and as he needed to hire more people for new projects, he realized that building a team naturally made him the team leader. Waisman's career took a significant turn when he left Immunity to join Semmle in 2019 as the director of research for Latin America, which was later acquired by GitHub.
Open Source Software and the GitHub Security Lab
At GitHub, Waisman helped adopt and integrate Semmle's CodeQL, focusing on improving open source software security. He worked on forming a coalition of companies to secure open source software, which eventually led to the creation of the Open Source Security Foundation, now housed at the Linux Foundation. This marked a significant evolution in Waisman's offensive security interests and expertise, shifting towards open source software and its impact on the CI/CD pipeline.
The Jump to the C-Suite and Defensive Security
Waisman's next major step was joining Lyft as the head of security and privacy in 2020, where he explored defensive security. He learned the necessity of combining defense with enablement, ensuring that security measures did not interrupt the speed of engineers. Within two years, he became Lyft's CISO. This experience introduced him to the challenges of defensive security, including the constant need to balance security with enablement and manage the stress that comes with being responsible for the actions of others.
Combining AI and Offensive Security at XBOW
Waisman's current role as CISO at XBOW combines his expertise in offensive security with artificial intelligence. XBOW is the first AI autonomous product that can perform penetration tests, mimicking human skills at scale. Waisman's professional career has come full circle, from offensive security to leadership, defensive security, and now AI-driven security, all stemming from his early days as a self-taught hacker.
Challenges and Concerns in the Evolving Landscape of Cybersecurity
Despite his calm demeanor, Waisman is concerned about the future of cybersecurity, particularly with the increasing use of AI by both attackers and defenders. He believes that as AI technology becomes more affordable, attackers will be able to target IPs with autonomously adjusting malware on a massive scale, leading to a period of chaos before defenders can catch up. Waisman emphasizes the importance of focusing on what really matters in security, a lesson he learned from Dave Aitel, the founder of Immunity.
Mentorship and Leadership Approach
Waisman takes a Socratic approach to teaching, preferring to ask questions that help his team find their own answers rather than providing them with specific advice. He believes in providing constant mentoring and prioritizes maintaining a healthy work-life balance for his team, recognizing the risks of burnout that CISOs and their security teams face.
Source: SecurityWeek