Summary
We build the production software behind modern manufacturing and CAM — mathematically demanding desktop applications refined over decades, plus a growing set of cloud services, running where a bad release stops a production line. R&D Operations makes that possible: DevOps owns the delivery engine, CloudOps the runtime, SecOps the guardrails. For the first time, all three come under a single leader.
You will lead R&D Operations as one department with one strategy, one set of standards and one budget — accountable for its annual delivery, reliability, security and financial targets. This is a leadership role, not a senior engineering role with a bigger title: you will build, coach and hold to account the organisation that writes the pipelines, and make the trade-off calls it cannot make for itself. Managers and Lead engineers report to you; you partner with our Principal engineers, who hold product-line technical authority.
The work is unfinished, and we would rather say so. Practices differ between product lines, some tooling is inherited rather than chosen, and the manager layer is still being built. That is the job: not to maintain a mature platform organisation, but to create one.
Job Responsibilities
- People and organisation. Build the management layer — hire, develop and calibrate Managers and Leads across the three functions. Own workforce planning, succession readiness and credible career paths against our career framework. Harmonise three distinct cultures into one team: the engineer optimising for flow and the engineer optimising for exposure are both
right. - Delivery — one software factory. Set and enforce a single standard for CI/CD, branching, versioning and artefact management across desktop and cloud lines. Drive developer self-service and everything-as-code. Own the department's DORA metrics and make delivery health visible enough for leadership to act on.
Runtime reliability. Own availability, performance and capacity against agreed SLOs, and the architecture behind them. Own Disaster Recovery as a tested capability — contractual RPO/RTO validated by real failover exercises. Act as senior escalation lead for major outages and critical security events, with blameless post-incident reviews whose actions actually close. - Security and compliance by design. Translate enterprise policy into enforced controls: policy-as-code, automated evidence, pipeline gates that fail the build. Own software supply-chain posture (SBOM, signing, provenance, vulnerability SLAs) and continuous audit readiness for [SOC 2 / ISO 27001; FedRAMP or regulated-market programme if applicable]. If a control only works because people are careful, it is not a control.
- Cost and vendors. Own the department's operating budget and bring cloud spend under active management — unit economics, showback to product lines, a working FinOps practice. Lead tooling consolidation and commercial negotiation with cloud and security providers, and put modernisation and security-debt investment cases in terms leadership can weigh against
feature work. - Across the business. Negotiate the velocity-versus-platform split with Product Management; represent our security posture in enterprise customer reviews with Sales; partner with Finance on cloud forecasting; work with Legal and Risk on data sovereignty and export control; align with corporate IT and InfoSec, and argue credibly where R&D must differ
Qualifications
We care what you have done, not the years next to it. Broadly: around a decade across DevOps, SRE, cloud infrastructure or security operations, with several years leading people.
- You have led a multi-team infrastructure, platform or operations organisation with managers or team leads reporting to you — and can point to the organisation you built, not only the systems.
- You have owned production reliability at scale: SLOs, on-call, major incident command, and post-incident practice that changed how the organisation worked.
- You have run a regulated or audited environment end to end (ISO 27001, SOC 2, FedRAMP, NIST 800-53 or equivalent) and know the difference between passing an audit and being continuously compliant.
- You understand hybrid estates architecturally — long-lived desktop products alongside cloud-native services, Kubernetes, infrastructure as code. Not the deepest expert in the room, but able to judge the quality of the argument. • You have held a meaningful cloud or infrastructure budget and improved its efficiency without stalling engineering.
- You can explain infrastructure to executives in terms of revenue, risk and time to market — and a commercial constraint to engineers without patronising them. You lead change through enablement, and you know why mandates rebound.
Valuable, not essential: ITAR, export-controlled or government cloud experience, or eligibility to obtain the clearances such work requires; building an internal developer platform; modernising mature CAD/CAM or other computationally heavy software; formal FinOps or supply-chain security practice (SLSA, SBOM); CISSP, CISM or cloud architect credentials.
Your first year, and how success is measured By 90 days: a clear-eyed assessment of delivery, reliability, security and cost posture — told to us straight, including the parts we will not enjoy. By six months: operating model and organisation design agreed, management layer hired or identified, a prioritised twelve-month plan with named owners and a baseline for every metric you intend to move. By twelve months: measurable movement on delivery and reliability metrics, audit evidence generated from systems, cloud spend under active management, and a department that is visibly one team with a functioning bench. We will agree targets with you in your first quarter across five dimensions: delivery (DORA, cycle time, teams on the standard platform), reliability (SLO attainment, time to restore, recurrence, DR validated), security (audit findings and time to close, remediation within SLA, controls automatically enforced), cost (unit cost per service, forecast accuracy, savings without regression) and people (engagement, voluntary attrition, internal promotion, succession coverage).