Kevin Mandia did not set out to spend his working life thinking about people who break into computers. At the Pentagon in 1993, he had a choice of assignments. Computer security was the one he took. The future arrived as a job description, which is considerably less glamorous than arriving as a revelation, but rather more common.
Three decades later, the assignment has acquired a considerable afterlife. Mandia founded Mandiant, led FireEye, co-founded the cybersecurity investment firm Ballistic Ventures and started Armadin. His work has involved discovering intruders, explaining what they did and persuading organizations to take the findings seriously. The inconvenient possibility running through it all is that a network can appear perfectly peaceful while someone else is making themselves at home.
That possibility gives his career its shape. In 2004, he built a company for the aftermath of a breach. In 2026, he is building one that sends AI agents to test defenses before an adversary gets there. Between those two businesses lie public disclosures, corporate transactions and an education in what happens when a technical investigation becomes everybody’s problem.
An assignment, then an appetite
Mandia graduated from Lafayette College in 1992 with a computer science degree. An Air Force ROTC scholarship helped him attend; he took part in the ROTC program at nearby Lehigh. His subsequent military work included computer security at the Pentagon and service as a special agent in the Air Force Office of Special Investigations. He also earned a master’s degree in forensic science at George Washington University.
The combination mattered. Programming teaches you how a system is supposed to behave. Forensics asks what actually happened. A suspicious file, an unexpected connection or a changed account can turn the distance between those two things into a case.
He has described being steered toward computer crime because of those qualifications, rather than pursuing cybersecurity as a childhood calling. His account contains a useful absence of romance: an assignment became a skill, and the skill became work he wanted to do.
“I think I actually got good at it first and recognized I had a passion for it as well.”Kevin Mandia, 2013
After leaving the Air Force, Mandia worked in the private sector, including Sytex and Foundstone, where he built a computer forensics and investigations group. He taught intrusion investigation to law enforcement and government personnel, and co-authored books about incident response. The business he eventually founded grew from work he had already been doing.
Mandiant began in February 2004, initially under the name Red Cliff Consulting. Its premise was direct: breaches happen, and organizations need people who can respond. A company could spend money on defenses and still find itself requiring an investigation. Mandia made that uncomfortable interval a business.
The evidence leaves the room
In February 2013, Mandiant published a report about a group it called APT1. The report described a multiyear espionage operation affecting 141 victims across several industries. It presented evidence linking the group to a unit of China’s People’s Liberation Army, identified as Unit 61398.
The publication turned investigative work into a public argument. Rather than simply telling affected clients what had happened, Mandiant laid out a pattern that other organizations could examine. It also released more than 3,000 indicators, including domains and malware hashes, to help defenders look for traces in their own systems.
A report built to be read - and used.
The decision involved a tradeoff. Mandiant explained that publication might damage its ability to keep gathering intelligence about that particular group. If intruders learn what investigators can see, they can change their behavior. Keeping the information private preserves an advantage; sharing it gives other defenders a chance to act.
The company chose to publish. That choice helps explain why Mandia’s biography belongs partly in the world of public affairs. Technical findings can identify a national security problem. Making them public requires a different kind of judgment from finding them in the first place.

When the investigators became the case
The next revealing disclosure came from closer to home. In December 2020, FireEye, the company Mandia led, announced that it had been breached. Attackers had taken tools used by its security teams to simulate intrusions. A firm hired to investigate other people’s compromises now had its own to explain.
That is a difficult position for any security business. Customers buy expertise and judgment. A breach invites questions about both. Disclosure also gives everyone outside the company a view of an investigation that is still developing, with all the uncertainty that implies.
FireEye went public on December 8. Five days later, it described a wider campaign using the software supply chain. The investigation had identified malicious code delivered through updates to SolarWinds’ Orion software. A trusted piece of business infrastructure had become an entry point.
Ordinary software updates are supposed to make systems better. Here, the mechanism organizations trusted to maintain their networks helped expose them. The campaign complicated the comfortable distinction between the software a company owns and the systems on which its security depends.
Mandiant later attributed the operation to APT29, a Russia-based espionage group assessed to be sponsored by the Russian Foreign Intelligence Service. Its analysis described access to an estimated 18,000 organizations through the compromised software, with further targeting determined by the attackers. Exposure and subsequent exploitation were different stages, an important distinction in a story with so many large numbers.
For Mandia, the episode gave practical force to Mandiant’s founding premise. An organization could have security expertise and still be compromised. What followed depended on investigation, communication and the ability to turn findings into actions other people could take.
A different side of the table
By then, Mandia had already experienced several versions of company leadership. FireEye acquired Mandiant in December 2013. He joined as chief operating officer, became president in 2015 and took over as CEO in June 2016. The investigator was now responsible for a public company.
In 2021, FireEye sold its product business, and the remaining business adopted the Mandiant name. Google completed its acquisition of Mandiant in September 2022 in a transaction valued at approximately $5.4 billion. Google’s announcement emphasized threat intelligence and incident response as parts of its broader security offering.
- 2004Build Mandiant
- 2016Lead FireEye
- 2022Join Google
- 2024Invest as a GP
- 2026Launch Armadin
Mandia had also co-founded Ballistic Ventures in 2021 with Barmak Meftah, Ted Schlein, Jake Seid and Roger Thornton. Initially a strategic partner, he became a general partner in June 2024. The firm backs early-stage cybersecurity companies. His experience could now be useful before a founder had built an organization large enough to have its own crisis room.
His work there included leading the investment in SpecterOps, whose tools help organizations identify attack paths. He initially served as a board observer; SpecterOps now lists him as chairman. The subject is familiar territory: understand the routes an adversary could use, then help close them.
Some connections reach much further back. Expel appointed him to its board in October 2024. Its CEO, Dave Merkel, had known him for roughly 30 years, since their Air Force days. Security companies may sell software, but careers in the field also accumulate people who have seen each other do the work.

Lafayette remains part of that network. In 2013, Mandia described staying in touch with dozens of fellow graduates and helping each other’s ventures. The following year, the college awarded him an honorary Doctor of Public Service degree. He has since become a trustee. The institutional relationship has lasted considerably longer than the undergraduate programming assignments.
The investigation moves forward
Armadin represents another turn toward building. Mandia is its founder and CEO, alongside co-founders with backgrounds in engineering and offensive security, including Travis Lanham and Evan Peña. The company publicly launched in March 2026 with $189.9 million in combined seed and Series A financing.
Its proposition reflects Mandia’s concern that AI will accelerate attacks. Software agents can search for weaknesses and pursue objectives at a speed and scale that human teams cannot easily match. Armadin applies that approach to authorized security testing, probing an organization’s defenses to find routes an attacker might exploit.
For a reader outside cybersecurity, the distinction is useful. An incident response team investigates an intrusion that has happened. An offensive security test attempts to discover what an intruder could do. Both depend on evidence about real systems. They sit at different points in the sequence.
On October 1, Armadin announced a further $255.5 million in Series B funding, taking its reported total to $445 million. The company said the money would support its platform, research and commercial expansion. The financing establishes the resources available for that effort; the work ahead is to make the tests useful to the organizations running them.
The questions that survive the software
Mandia’s executive advice is often simpler than the systems it addresses. He urges leaders to ask about weak spots, worst cases, response plans and how someone would break in. Those questions connect a security program to consequences that a board can discuss.
They also make room for judgment. A list of products can describe what an organization bought. Questions about an attack ask how those purchases, the people operating them and the rest of the business behave together. The answer may be reassuring. It needs to be earned.
In September 2026, Amazon elected Mandia to its board. He serves on its audit and security committees. The appointment puts an investigator and company builder inside the oversight conversation, where security decisions have to coexist with the rest of an organization’s responsibilities.
His career began with a Pentagon assignment. It has kept returning to a fairly stubborn question about computers and the people who depend on them: what is actually happening here? A quiet network is pleasant. Mandia has built his working life around asking whether it deserves to be.
Follow the investigation
- Mandia at Ballistic Ventures ↗
- Mandia at Armadin ↗
- Kevin Mandia on LinkedIn ↗
- The APT1 report and defensive indicators ↗
- Amazon’s board appointment announcement ↗
- Armadin’s October 2026 funding update ↗
- Ahead of the Threat: interview and transcript ↗
- Watch: Fortune conversation with Nina Easton ↗
- Watch: Resilience Universe with Sanjay Poonen ↗