Skip to main content
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us
Group
Group
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us

Securing the Agentic Workforce: The EDR for AI Agents - Evoke Security

Written by: 
Amy McLean

‍Securing the Agentic Workforce: The EDR for AI Agents - Evoke Security

At Black Hat 2026, Aspiron Search spoke with Jason Rebholz, CEO and co-founder of Evoke Security, about the career path that took him from a college vulnerability-scanning gig to Mandiant, incident response leadership, and a CISO seat, before he decided to found a company securing AI agents. His story is a useful map for anyone weighing a move from practitioner to founder.

‍

From Rubik's Cubes to RIT's Security Program

Jason's route into security started with a knack for puzzles. In high school he was speed-solving Rubik's cubes and learning to program in one of the first computer science classes his school offered. Programming itself didn't stick. "After two years, I realized I'm not really a programmer. I just didn't enjoy it," he said. A teacher pointed him toward networking instead, where he found the security side of it clicked immediately. He went on to RIT, one of the first colleges with a dedicated computer security program, which he credits with teaching him to see systems and networks as a whole rather than a list of configurations.

‍

Learning the Trade at Mandiant

Jason's first taste of the field came running vulnerability scans for RIT's own information security office, sending reports that mostly went unanswered. "I got this perception of, do people even care about security?" That changed when he applied to Mandiant for a pentesting role straight out of college and instead landed in incident response, handed a hard drive on his first day and told to figure out what happened. He became one of Mandiant's earliest college hires.

"It was this extreme concentration of talent and mission-driven people. Everyone was so bought into the mission: find evil," he said. Two colleagues from that era, Marshall (now CEO of DTEX) and Kevin, became lasting mentors. "Your timing is everything in your career, and it's really about making the most of it."

‍

Building Businesses Inside the Ransomware Boom

After Mandiant's acquisition by FireEye, Jason moved to a smaller firm, Crypsis Group, as its fifth employee, building out its incident response practice through the cyber insurance channel. He grew that business from about $1.8 million to just under $10 million in revenue in eighteen months, right as ransomware exploded. He remembers his first case, a group called SamSam demanding a then-eye-watering $50,000, and later negotiating directly with attackers, including one who dismissed the fallout of encrypting a children's hospital with "don't care, happy new year." "That was a real fundamental moment for me: even dealing with humans, there is no compassion."

‍

From CISO to Founder

After co-founding a company focused on restoring systems after a ransomware attack, Jason stepped away from incident response once and for all and took a CISO role at Corvus Insurance, where he also built out threat intelligence and risk services functions, an early-warning program he credits with saving $5 to $7 million annually in cyber claims. When Corvus was acquired by Travelers, he faced a comfortable path forward and turned it down. "I'm all about regret minimization. If I'm eighty years old feeding pigeons on a park bench, I think I'd regret not giving this a shot," he said. "You can't steer a parked car. You just have to get moving."

He co-founded Evoke Security with Jeffrey Chan, a colleague from both Mandiant and Crypsis. Two days after launch, a blog post on GitHub's MCP server convinced him the industry was repeating old infrastructure mistakes with AI agents. Evoke bet against LLM guardrails and MCP gateways alone, on the belief that "the agent is the next operating system for the employee," and built what Jason describes as an EDR-style detection and response layer purpose-built for agents, ignoring model security and instead focusing on what actions an agent actually takes.

‍

FAQ

Who is Jason Rebholz? CEO and co-founder of Evoke Security, formerly a CISO at Corvus Insurance and an incident response leader at Mandiant and Crypsis Group.

What does Evoke Security do? Builds detection and response for AI agents, modeled on how EDR changed endpoint security, tracking agent actions across endpoints, cloud, and frontier lab environments.

Why did Jason leave a CISO career to found a company? He describes it as a regret-minimization decision: after years of incident response and building security programs for others, he wanted to build a product company of his own as a bet on himself and be at the front of where technology and security threats are developing.

Tablet of Contents

TOC Element

Recent Posts

AI in Cybersecurity: The AI vs AI Arms Race Reshaping Security in 2026

August 5, 2026

Building a Cybersecurity GTM Team from Seed to Series B

August 4, 2026

AI Application Security: Why AppSec Isn't Dead in the AI Coding Era

August 3, 2026

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

Company

Why Aspiron?
For Candidates
CyberBytes

Useful Links

Resources
Contact Us
Aspiron Group

Support

Privacy Policy
Cookies Policy
Terms & Conditions

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

© {{year}}  Aspiron Search Limited – All rights reserved