Kevin Mandia doesn't do small.
The cybersecurity entrepreneur who built Mandiant from a basement operation into a $5.4 billion Google acquisition announced Monday that his latest venture, Armadin, has emerged from stealth with $189.9 million in the bank—the result of a combined Seed and Series A raise that the company is billing as the largest early-stage cybersecurity funding on record. Whether that claim survives scrutiny depends on how you're counting, but either way, it's a striking debut for a startup that didn't officially exist six months ago.
Accel led the Series A, joined by GV (Google Ventures), Kleiner Perkins, Menlo Ventures, and In-Q-Tel, the CIA's venture arm. Follow-on money came from 8VC and Ballistic Ventures, the latter being the firm where Mandia himself sits as a general partner—a detail that underscores just how deeply embedded he remains in the cybersecurity funding ecosystem. The company reportedly raised a quieter $24 million seed round late last year, according to SecurityWeek, though Armadin has been characteristically tight-lipped about valuation. Pre-launch chatter in January floated a figure north of $600 million, though no one's confirming that now.
As for the "record" designation: it's complicated. TechCrunch points out that companies like 1Password and OneTrust each pulled in $200 million Series A rounds back in 2019, but those weren't announced as bundled Seed-plus-A figures fresh out of stealth. So perhaps Armadin has earned its bragging rights on a technicality. The cybersecurity industry, not known for its understatement, is unlikely to mind.
Mandia's track record lends weight to the hype. He founded Mandiant in 2004, sold it to FireEye for roughly $1 billion in 2013, then stayed on as the combined entity's CEO. When Google snapped up the business in 2022 for $5.4 billion, Mandia became something of a folk hero in security circles—a rare founder who built, sold, and somehow made the acquirer look smart twice over.
The Armadin team reads like a Mandiant reunion with a Google Cloud overlay. Travis Lanham, formerly of Google Cloud Security, is CTO. Evan Peña, who led offensive security operations at Mandiant for years, now holds the title Chief Offensive Security Officer—a role that sounds like it was invented specifically for him. David Slater, ex-Google SecOps, rounds out the leadership as Chief Architect. The company registered in California in October 2024 and operates out of the San Francisco Bay Area, though like many post-pandemic startups, its footprint seems more conceptual than geographic.
So what exactly is Armadin building? The pitch hinges on what the company calls an "agentic attacker swarm"—autonomous AI agents designed to think, adapt, and strike like advanced persistent threats, only on behalf of the organizations they're meant to protect. The idea is to continuously identify, validate, and document exploitable vulnerabilities at speeds no human red team could match.

"In a world of machine-speed attacks, defense must become autonomous," Mandia said in the announcement, leaning into the kind of high-stakes framing that has defined his public persona for two decades. "We are building the most formidable offense to give organizations the greatest defense."
Ping Li, a partner at Accel, described the platform as weaponizing "the attacker's perspective" to create an autonomous security validation system. It's a concept that has been kicking around cybersecurity circles for years—simulation-based testing, continuous red-teaming, adversary emulation—but the AI wrapper gives it a fresh urgency. Whether Armadin's execution lives up to the rhetoric remains to be seen, though investors seem willing to bet heavily on Mandia's instincts.
The company plans to plow the capital into engineering and research headcount, further refinement of the AI-driven attack simulation engine, and scaling up enterprise deployments. Armadin's website includes a careers page, though no specific roles were visible at launch—a sign, perhaps, that they're still figuring out exactly what kind of talent they need, or that the hiring spree is happening through quieter channels.

The raise lands in the middle of what has been, by most measures, a robust stretch for cybersecurity investment. Firms in the sector pulled in roughly $14 billion across nearly 400 funding rounds last year, according to an analysis by Pinpoint Search Group cited by SecurityWeek. Armadin now finds itself in a crowded field that includes Horizon3.ai, which raised $100 million last May, and Pentera, both of which are also chasing autonomous security testing and validation.
The difference, if Mandia has his way, will be execution. And perhaps that's the real story here: not the size of the round, but the implicit wager that in an industry drowning in hype, a proven operator with a track record of building valuable companies still commands premium treatment from investors who've seen too many flash-in-the-pan security startups. Whether Armadin becomes the next Mandiant or just another well-funded experiment will depend on whether the technology delivers—and whether enterprises are ready to hand over their security testing to an AI swarm that thinks like an attacker.
For now, though, the money's in the bank, and Kevin Mandia is back in the game.
