تخطي إلى المحتوى الرئيسي
Cyber News SecurityWeek 3 days ago

CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

Se
SecurityWeek
CISO Nico Waisman

“I don’t think I ever chose a career in cybersecurity. It chose me.” Well, we’ll see…

Nico Waisman was born and still lives in Argentina. If what he says is accurate, it suggests he was born in 1982; one year before a seven-year period of military dictatorship in Argentina came to an end.

Argentine youngsters in the 1980s lived in a time of youthful rebelliousness against the law and the establishment, lingering after the dictatorships. For Waisman, this youthful rebelliousness turned toward emerging technology. He became fascinated by the idea of being able to subvert this tech into doing something he wanted it to do. In short, he became a young hacker – but it was the challenge and enjoyment of doing it rather than any desire to make money or cause harm from it that drove him.

He received no training in computer technology nor cybersecurity. Neither existed in Argentina at that time. Everything he learned about code, bugs, finding vulnerabilities and exploiting them, he taught himself. 

“There was no documentation for anything, which was part of the fascination and challenge,” he explains. “So, there was a lot of experimentation and a lot of reverse engineering, to learn how things worked and how to subvert them. This is what I really, really liked and still enjoy: you spend days focusing on one problem, understanding how it works, and then trying to see how you can break it.”

This was the origin of a career in offensive security. But again, in Argentina at that time, there was no such thing as a career in offensive security. Instead, he considered a career in engineering, but he dropped out of engineering school a couple of times. He then tried ‘communication’ and spent four years studying journalism. Again, he didn’t complete the course and gain a degree; he didn’t do the thesis. All the time he explored other options and developed, for example, new communication skills, his first love was still hacking.

Advertisement. Scroll to continue reading.

“Eventually,” he says, “even in Argentina, the future showed up, and I was able to get a job in cybersecurity.” In 2003 he joined Immunity as a senior security researcher. He may not have had formal cybersecurity qualifications, but he had hands-on experience and an ability to demonstrate his knowledge. It was the beginning of his professional career, three-quarters of which has been in offensive security, founded in his early self-taught knowledge of hacking methods.

He remained at Immunity until 2019, progressively moving up the ladder to become VP of Latin America. “We were building a product [CANVAS, an exploitation framework that largely shaped how early pentesters and red teams evolved] that helped people perform their own penetration testing. I was working both with public and private companies, helping to find vulnerabilities and how they could be exploited, initially with Linux and later with Windows.”

During this 17-year period, he used his personal expertise from earlier hacking, exercised the communication skills he had acquired (he spoke at conferences including Black Hat, Syscan, PacSec, RuxCon, and Ekoparty), and learned new leadership skills.

Waisman agrees with Vince Lombardi’s view: “Leaders are made, they are not born.” But the making process can be almost accidental rather than planned. “Originally, I was a bit of an introvert. I was attracted to computers because they’re like a safe space.” While learning to hack as a youngster, he met (online) many other people engaged in the same process of research and hacking.

As his career progressed and he needed to work with other people on different projects, he always preferred working with people he knew, liked and understood. For new projects, he had to hire people to work with him. “So,” he thought at the time, “I’ll hire all these amazing hackers or researchers that I know, that I want to work with, and who I know like to work together.” That’s what he did. But if you build a team, even if you are building a team of friendly equals, it is only natural that the team builder becomes the team leader. For Waisman, becoming a leader was simply the natural evolution of what he was doing – it was neither an innate part of his psychology nor a planned progression of his career.

“Eventually, life and age slowly push you into a management position; and the moment you say, yes, there’s no turning back,” he explains. “As I was growing, I started running teams, initially working on product development, and then doing services. At one point I had 30 or 40 pen testers reporting to me. We were serving Fortune 500 companies, helping them perform application security tests, penetration tests and so on.”

After 17 years at Immunity, he left to join Semmle in June 2019 as director of research for Latin America. Semmle had been founded by Oege de Moor in 2006. Within a few months of Waisman joining Semmle, it was acquired by GitHub; and by the end of 2019, Waisman was the senior director of GitHub Security Lab.

Written By Kevin Townsend

View Original Report

This intelligence was aggregated from SecurityWeek.

Read on Source