Hacker News new | ask | show | jobs
by TameAntelope 1570 days ago
I spent a few years there, FireEye messed Mandiant up something fierce, but Mandiant was never able to get its product going (with or without FireEye). Maybe Google can figure that part out.

I wonder what will happen to the engineers; there is definitely a lot of expertise at that company, specifically in the IR/security side.

4 comments

I feel like this is an informal announcement that the product has been killed. Where would it live in the GCP portfolio?

As an engineer I would be stoked. The resources that Google can bring in terms of data, compute and depth of analytical skills would be very appealing. It’s probably going to be a disaster for the product folks but i think the engineers will be happy. At least for a little bit.

My experience having gone through an acquisition @ Google (albeit 10 years ago and in a different space) is you might go in with the thoughts like yours expressed here: "wow, cool, think of all the resources Google has to make our product even better."

In reality: your product will be sunsetteded and replaced with a Google-created version of the same thing within two years; your key management (and other) talent will pace around for 3-4 years in frustration waiting for their stocks and acquisition bonuses to fully vest, and eventually most of the talent that can get a competing offer that is close to Google's proverbial buckets of cash will take that and leave.

That said, it might be different in Google Cloud where more of the infrastructure is closer to industry standard infrastructure instead of Google's bespoke creations. And there's a focus on the needs of what people outside of Google do and how they do it.

I did a short stint at Google and I saw this very thing. I think the one thing that’s a little bit different with Mandiant is that it’s largely a services organization. If they pigeonhole it as Google Cloud security then folks will bail very quickly. If they find a way to also extend it into their enterprise customer case as a value added service then I could see it being pretty interesting.
Assuming the engineers aren’t forced to re-interview for their own jobs in the common Google acquisition fashion.
In an acquisition of this size, it’s not typical to interview. HTC engineers did not have to interview AFAIK and having been at Fitbit I can say for sure that no engineers had to interview.

Interviewing happens with startups. When there aren’t interviews the assumption is that Perf will take care of non-performers.

The domain experts are best-in-class.

The engineers probably would need to be re-interviewed. Heh.

Of course they should be interviewed back, what's the alternative?

Hey team, so this is Steve from another department in another company. He's been assigned to our team, so. Of course we're handling text in the Chromium engine and Steve's backgound is in threat analysis, but I guess we'll figure something along the way. Welcome, Steve

The alternative is that they basically keep working on the same things. Maybe now there is some integration project.
Especially since they likely have 2-3 years of services contracts to burn through and don’t really have an org they directly overlay with inside Google. Enterprise security to an extent but also not.
that is already how google works. you get hired as a generic software engineer, and you pick up domain skills on the job every time you join a new team. someone working in threat analysis within google could absolutely put in for a transfer to the chromium engine team, and they would be expected to spend the first month or two getting up to speed on the codebase and specialised algorithms it entailed.
Well, it seems that the Google Chronicle was a semi-failure from all the signals that were coming out. I hope i'm wrong about Chronicle. Maybe this is a future replacement/iteration / improvement.

This could be a way to improve their offering and remove the "security argument" showstopper for cloud migrations.

Having used Chronicle, it felt like an underwhelming paper thin demo product compared to what the industry offers. May as well scrap it and lean on Mandiant's experience for a replacement.
There’s not a huge overlap between Chronicle and Mandiant. Mandiant makes most of its money off intel and incident response. Chronicle sells tools to do those.
Most everyone I know says that Chronicle was a failure.
Mandiant ending up as a glorified GuardDuty and Detective for GCP would be a travesty although I doubt that would be the outcome.
Possible acqui-hire - perhaps it's not the product they're after...
10 million per head is a hell of a sign-in bonus
What is their main source of revenue? They did about $483M in 2021.
Unlikely, google is good at Killing the products they acquire... not much else