Pentester Spotlight — Edu Garcia

The Cobalt Pentester Spotlight highlights the fascinating journey of our Core members. Through an interview style, we share their experiences, background, and insights into the world of an accomplished pentester.

What's your handle? Do you use more than one? What's the origin story?

My handle is wagiro. "Wagiros" is what my family is called in my hometown.

What got you into cybersecurity? How did you get into pentesting specifically?

My interest in cybersecurity began around 1998 when I was 16. Things were very different back then, but from the very beginning, I wanted to focus on offensive security, attacking systems, websites, and so on, to find vulnerabilities and fix them.

What exploit or clever attack are you most proud of and why?

Blind SQL injection is an attack I’ve always really liked; I used to view it as magical. Even without directly revealing the database contents, you could extract the data by asking Boolean questions; I love it. They aren't as common these days, though.

What is your go-to brag when talking about your pentesting skills?

I don’t like to brag, but if I were to highlight my strengths, it would be my understanding of technology—not just the vulnerability aspect, but how things work under the hood. This allows me to think outside the box and execute less common attacks. At the same time, I’m good at automating processes.

Share a time something went wrong during a pentest. What happened and what did you do?

After so many years in this field, things have gone wrong on many occasions. One of the biggest concerns in our line of work is the fear of overlooking a vulnerability in the target. Over time, I have learned to develop a robust methodology to cover everything, yet sometimes an unforeseen issue still arises; in those instances, you simply have to accept it and move on. For those of us who care deeply about our work, we have to learn to live with that reality.

What are your favorite tools or TTPs when conducting pentests? Why?

Right now, the projects I work on most are penetration testing for websites and APIs, as well as AI-driven automation. For this, I use Burp Suite (I’ve used it since the early versions, and it has been incredibly useful) and Burp Bounty Pro, and I rely heavily on AI to guide the penetration testing process.

On the technique side, I'd emphasize understanding application workflows and testing authorization across users and roles. For AI systems, that extends to examining which data an agent can access and which actions its tools can perform. Those questions help connect a technical weakness to its practical impact.

What are your favorite asset types to pentest and why?

Right now, it’s all about AI-powered automations. Over the last two years, I’ve been learning a lot about AI because I find it fascinating. I built numerous AI automations to understand them, and then I set about breaking them. Currently, this is the type of asset I enjoy working with most, whether it’s chatbots, RAG systems, or any automation that incorporates LLMs into the process.

What certifications do you have? Why did you choose them?

Right now, I have:

  • Certified AI Security Professional (CAISP)
  • Certified AI/ML Pentester (C-AI/MLPen)
  • Certified API Security Analyst (APIsec)
  • Securing LLM and NLP APIs (APIsec)
  • API Penetration Testing (APIsec)
  • EC-Council Instructor (CEI)
  • Certified Ethical Hacker (CEH)

As you can see, I’m currently focusing on pentesting certifications involving AI automation.

What advice do you wish someone had given you when you first started pentesting?

Spend time learning how applications work before trying to memorize attacks. Understanding HTTP, authentication, and authorization gives you a foundation that transfers across tools and technologies.

I'd also encourage new pentesters to write down how they tested an idea and why they believe the result is valid. That habit makes it easier to learn from an engagement and explain a finding.

How do you explain findings to customers and ensure they have a quality experience?

For me, a good explanation starts with the impact in the customer's context, followed by the conditions needed to exploit the issue and the evidence supporting it. A developer should be able to reproduce the behavior and understand what needs to change.

A good customer experience also depends on communication throughout the engagement: relevant updates, clear answers to questions, and remediation advice that makes sense for that application.

What is your favorite part of working with a pentesting team? What about working on your own?

The most interesting part of working with a team is seeing how another pentester approaches the same application. A different interpretation of a workflow can open up a new line of investigation.

Working independently gives me room to stay with a difficult problem and follow an idea through. Both ways of working have something valuable to offer.

Why do you like pentesting with Cobalt?

I've worked with Cobalt since 2020 and have also written for Cobalt. I like the opportunity to contribute through hands-on testing and share knowledge through writing. I'd like to build on that involvement, especially around AI security, research, and practical content for other pentesters.

I think Cobalt also offers an extra degree of freedom; I really like how they organize pentests, the reporting platform, and project management with clients.

Would you recommend Cobalt to someone looking for a pentest? Why or why not?

Yes. Having worked with Cobalt since 2020, I would recommend it to organizations looking for an assessment involving experienced pentesters.

I would also encourage customers to discuss their goals and scope upfront, so the engagement focuses on the systems and risks that matter to them. Relevant expertise and clear communication are especially important when choosing a pentesting team.

What do customers or the media often misunderstand about pentesters?

People often imagine that the job is mostly about running a powerful tool or producing a dramatic exploit. Much of the work is careful investigation: understanding normal behavior, checking assumptions, and ruling out misleading results.

Writing and collaboration also matter a great deal. A finding becomes useful when someone can understand its impact and take action on it.

How do you see pentesting changing in 2026 and over the next few years?

I expect pentesting to expand further into AI automations and LLM applications. That will require assessing the workflow around a model, including how it receives information, which data it can access, and what actions it can trigger through connected tools.

Traditional web and API security knowledge will remain valuable because those systems still depend on identities, permissions, and integrations. I also expect AI to assist with more of the testing workflow, which will make it especially important to verify results and explain exactly what the evidence demonstrates. This is the direction I've been specializing in.

What's one non-technical skill that is becoming critically important for a successful pentester, and how do you cultivate it?

Writing. A pentester needs to make a complex issue understandable to someone who wasn't there during the investigation.

I've already written for Cobalt, and I'd like to do more technical writing and research, particularly around AI security. Writing for others gives me a reason to organize technical ideas, explain the assumptions, and make the practical takeaway clear.

What's your p(Doom)?

In my opinion, if things continue to be done the same way, the probability is 80%, but I’m optimistic; I hope we learn and that probability trends toward 0%.

AI and Pentesting Pulse Report 2026 CTA

Back to Blog
About Noelle Hori
Noelle Hori is the Community Operations Manager at Cobalt. She graduated with a Bachelor’s degree in Hospitality Management from San Francisco State University. With over six years of community leadership experience, Noelle plays a key role in advancing the Cobalt mission to revolutionize how organizations protect themselves from cyber threats—by uniting the best of people and technology. Noelle partners closely with product and delivery teams to maximize the pentester experience while also helping guide community initiatives for the Cobalt Offensive Security Platform. More By Noelle Hori