Cybersecurity requires a level of expertise that is unexpected of a 22 year old.
Even if we imagine that 22 year olds are just as capable as 32 year olds, his young age would be statistically remarkable - considering the number of people over 22 working in cybersecurity, against the number of people under 22.
They might be as capable but 32 year olds have a 10-year head-start of academic and industry experience to from where to draw. Achieving something that others with all that additional academic and professional experience haven't is a huge feat.
I'm not sure if it's because we have a general perception that youth is when you should learn a thing, you then get a bit older and get good at it, then get a bit older and do great things with that ability, then sort of forget it all and be too old to be useful.
Also the older you are the more time you have had to discover something. Even if it's just by random luck you would have just had more time for it to happen.
Reminds me of the TV news, where any time a number is mentioned, they emphasize the hell out of it like I'm supposed to be amazed!!!!! Do they train 'em in journalism school to do that?
Here I see a story of how someone with at least the minimum level of interest and thinking skills goes and RTFM, then thinks about how to exploit this one design feature (a decision essentially made once per chip design, not a beeeellion times), and finally through experimentation and persistence figures out how to do it.