Software Engineer

Michael
Mendy

Building secure, scalable CI/CD and cloud infrastructure to enable great teams to ship fast with confidence. Kubernetes, Terraform, gated promos, canaries, and instant rollbacks.

Michael Mendy

Michael Mendy

Software Engineer, CI/CD & Infrastructure

United States Flag

Enterprise Impact

Trusted by leading
organizations

From Ivy League research institutions to Fortune 500 defense contractors, my infrastructure and DevOps work has supported mission-critical systems across industries.

View experience ->

I've worked with

MIT
Harvard University
Lockheed Martin
Northrop Grumman
Nike
American Medical Association
Motorola
Stripe
National Institutes of Health
Ministry of Justice
City of Detroit
Pfizer

About

I build systems that scale, solve complex problems, and make an impact.

With over a decade of experience in software engineering, I specialize in building scalable systems that power some of the pillars of the internet. My work spans from low-level systems programming to high-level architecture design, encompassing distributed systems, developer tools, and infrastructure.

I've spoken at conferences worldwide about performance optimization, distributed systems, and developer experience. When I'm not coding, you'll find me contributing to open source, writing technical articles, or mentoring the next generation of engineers.

ORCID: 0009-0001-9990-4788

Testimonials

What people say

Kyle Wheeler

“Michael is super talented and a great asset to any team. His knowledge of business and the tech behind the business is unique and invaluable.”

Kyle Wheeler

GM @ Lens

Patrick Steadman

“Silicon Valley Boy Genius and Bad Boy!”

Patrick Steadman

Platform Engineer @ Sotheby's

Garrett Loh

“Michael is truly gifted at anything you give him.”

Garrett Loh

Founder of CRS

David Asser

“Michael is a true subject matter expert. He is my first call for all things tech development. This is the cream of the crop of software engineers.”

David Asser

Private Consultant

Lockheed Martin
250+

code commits and merges to Lockheed Martin since 2023

Breaking the impossible

Systems you can trust

Over a decade building production CI/CD pipelines, managing Perforce at enterprise scale for clients like MIT, Harvard, Google, and Lockheed Martin, with infrastructure designed for 99.9% uptime.

VIEW WORK EXPERIENCE

Impact you can prove

7 published research papers, 6+ conference keynotes at events like IBM Z Day, Droidcon, and Arm DevSummit, plus a US Patent for Access Point Hopping technology. Real, measurable contributions to the field.

READ RESEARCH PAPERS

Defense Sector

Enterprise-grade
pipeline velocity

Building CI/CD infrastructure for defense and enterprise clients requires zero-downtime deployments, strict compliance frameworks, and systems that scale under extreme conditions. Track record of reducing incidents while accelerating delivery.

VIEW DEFENSE WORK ->
Defense CI/CD Velocity
Deployment frequency + incident reduction
Historical
Forecast
Pipeline velocity
Incidents
Compliance gap

How I Work

End-to-end pipeline architecture

01

Source & Build

Automated source control integration with Perforce, Git, and hybrid VCS workflows. Builds triggered on commit with parallel compilation, dependency caching, and artifact generation across multi-platform targets.

VIEW CI/CD EXPERIENCE
Build PipelinePassing
Compile
Link
Package
Sign
02

Test & Validate

Comprehensive test orchestration spanning unit, integration, and end-to-end suites. Static analysis, SAST/DAST security scanning, and compliance validation against NIST and DoD frameworks before any artifact is promoted.

READ RESEARCH PAPERS
Test Results
1,247
Unit
342
Integration
89
Security
100% passing
03

Deploy & Monitor

Zero-downtime deployments to air-gapped, hybrid, and cloud environments. Infrastructure as Code with Terraform and Ansible, automated rollback policies, and real-time observability with custom alerting pipelines.

VIEW PROJECTS
Deployment Targets3 environments
Staging
us-east-1
Deployed
Production
multi-region
Deploying
Air-gapped
on-premise
Queued
Control Coverage
Risk Reduction
Policy Status
Continuous Monitoring
1.

Align with NIST & DoD Controls

Map infrastructure, repositories, and deployment pipelines to NIST 800-53 and DoD compliance frameworks. Establish measurable control coverage and risk baselines.

CI/CD Pipeline
GitHub
SBOM Generated
Travis CI
STIG Compliant
Kubernetes
Signed Artifacts
Artifact Registry
Security Scanner
Policy Engine
2.

Automate Compliance in CI/CD

Embed policy checks, security scans, SBOM generation, and artifact signing directly into pipelines. Enforce controls before deployment — not after.

Secure Cluster
Compliance Shield
AI Engine
Dashboard
Active
REAL-TIME THREAT DETECTION
0 violations
DRIFT MONITORING
Automated
EVIDENCE COLLECTION
0.02
ANOMALY SCORE
3.

Augment with AI Oversight

Use AI to monitor configuration drift, detect anomalous behavior, and auto-generate compliance evidence. Maintain continuous ATO readiness.

Michael Mendy

I just deployed a self built, a Self-Healing, Multi-Region, Service Mesh-Enabled, CI/CD-Driven Platform with Progressive Delivery, Observability, and Zero-Downtime Migrations, entirely containerized through Docker.

Michael Mendy
System Architecture

Mission Architecture

1
Control Architecture
Control Coverage: 82%

NIST 800-53 Control Mapping

Control FamiliesSystem ComponentsRisk Domains
Access Control
Configuration Management
Audit & Accountability
2
Pipeline Enforcement
Policy Gates Passed: 97%

DevSecOps CI/CD Enforcement Layer

GitHub
CI
Security Scan
Policy Engine
Signed Artifact
Deployment
SBOM GeneratedSTIG ValidatedArtifact Signed
3
AI Continuous Oversight

AI-Powered Continuous Monitoring

Drift Detection
Threat Anomaly Detection
Control Evidence Logging
Risk Scoring Engine
Anomaly Index
0.03
Control Drift
Stable
ATO Readiness
Continuous
Policy as CodeContinuous ValidationAutomated Evidence

Philosophy

The AI productivity paradox

I use AI every day. I also know exactly where it breaks.

01

Speed without guardrails is just debt in disguise

I leverage AI to accelerate pipeline authoring, infrastructure-as-code, and configuration management. But velocity without validation is technical debt at scale. My approach pairs AI generation with rigorous review gates, static analysis, and automated compliance checks -- so delivery speed never undermines reliability.

VIEW CI/CD EXPERIENCE
02

Hallucinations don't survive classified networks

AI assistants lose context in complex multi-service architectures. I've built systems for defense and enterprise clients where a single hallucinated config could cascade into outages across classified networks. Understanding these failure modes isn't optional -- it's why I architect every pipeline with deterministic validation layers that no AI can bypass.

READ RESEARCH PAPERS
03

Blind automation inflates budgets and erodes trust

Unpredictable AI outputs create runaway compute costs and new attack surfaces. At organizations like Lockheed Martin and MIT, I've seen firsthand how blindly trusting automation erodes team confidence and balloons budgets. The engineers who thrive with AI are the ones who know exactly where to trust it -- and where not to.

VIEW PROJECTS

Experience

Work Experience

Travis CI logo

Travis CI

2019 - Current

Software Engineer

San Francisco, CA

Leading the development of CI/CD infrastructure that powers thousands of builds daily. Architecting features that enable developers to customize build pipelines with unprecedented flexibility. Managing global server deployments across multiple regions, ensuring 99.9% uptime for enterprise clients.

LASOR logo

LASOR

2018 - 2018

Software Engineer

Los Angeles, CA

Python and Django developer at LASOR, an agile research organization. Contributed to studies on the progression of Non-Alcoholic Fatty Liver Disease (NAFLD), leveraging analytics to advance the mission.

Cheekd logo

Cheekd

2016 - 2018

Lead Software Engineer

New York, NY

Led a team of 3 engineers building innovative mobile networking technology. Architected 'Access Point Hopping,' a groundbreaking feature that earned a US Patent. Built scalable backend systems with React Native and Django.

FC Flamingo logo

FC Flamingo

2015 - 2016

Software Engineer

Santa Monica, CA

Built full-stack web applications for major brand clients using Ruby on Rails. Focused on DevOps practices, implementing automated deployment pipelines and infrastructure as code.

Path logo

Path

2012 - 2015

Software Engineer

San Francisco, CA

Designed and implemented server-side APIs for Path's mobile and web applications, serving millions of users. Built scalable backend services with Python.

Speaking

Keynotes & Conferences

I've had the privilege of sharing knowledge with thousands of developers worldwide. My talks focus on practical insights from building and scaling CI/CD systems, managing enterprise infrastructure, and implementing DevOps best practices.

VIEW ALL TALKS

Featured Conferences

IBM Z Day logoIBM Z Day
Droidcon logoDroidcon
Arm DevSummit logoArm DevSummit
Replicated logoReplicated
LeadDev logoLeadDev
DockerCon 18' logoDockerCon 18'
michaelmendy@gentoo:~/certificates

Talks

Talks I've Done

[8 records]

Speaking engagements and technical presentations on CI/CD, DevOps, and software engineering.

CLASSIFIED // OPEN SOURCE
Travis CI Demo
01.

Running Travis CI on Arm

Demo showcasing Travis CI running on Arm architecture and comparing performance metrics across different platforms.

2022
Travis CI Demo
RepliCon Q302

The Value of Replicated

2022
RepliCon Q3
IBM Z Day03

IBM Z Day

2021
IBM Z Day
Droidcon SF04

Running Android Emulators in Travis CI

2023
Droidcon SF
Droidcon
05.

Travis CI + Building on Android

How to wire up an Android app to Travis CI, creating a basic .travis.yml so your project builds and tests automatically.

2024
Droidcon
DevOps Summit06

Building Smart with Travis CI and Docker

2023
DevOps Summit
DevOps Summit 202407

The Less Complicated Way of Using Docker and Travis CI

2023
DevOps Summit 2024
Travis CI Workshop
08.

Running Travis CI on Specific VMs

A comprehensive guide to configuring and running Travis CI builds on specific virtual machines.

2022
Travis CI Workshop

Expertise

Perforce Expertise

Deep expertise in enterprise version control, managing large-scale codebases and binary assets at the frontier of development workflows.

Command Prompt

Terracotta

I've created custom software called Terracotta that makes Git repositories Perforce compatible, bridging the gap between modern distributed version control and enterprise-scale centralized systems.

Version Control Architecture

Expert in designing and implementing scalable Perforce depot structures for large-scale enterprise projects.

Branching Strategies

Advanced knowledge of stream-based workflows, mainline development, and complex merge operations.

Performance Optimization

Specialized in optimizing Perforce server performance, replication, and handling massive binary assets.

Security & Access Control

Implementation of robust security policies, protections, and fine-grained permission systems.

RBAC Implementation

Role-Based Access Control design and deployment, managing user permissions, group hierarchies, and access policies at scale.

CI/CD Integration

Seamless integration of Perforce with modern CI/CD pipelines, automated builds, and deployment workflows.

Team Collaboration

Facilitating efficient team workflows, code reviews, and collaboration across distributed development teams.

Technical Expertise

Building CI/CD pipelines that deploy 10,000+ builds daily across enterprise infrastructure at organizations like MIT, Harvard, and Lockheed Martin.

CI/CDPerforceKubernetesAI/MLAWSDockerTerraformDefensePythonReactJenkinsGit

Projects

Featured Projects

Transformative projects that have impacted millions of users and shaped the way teams build software.

Cheekd

2016-2018

Access Point Hopping

Pioneered an innovative networking technology that revolutionized how mobile devices connect in crowded environments. This patent-pending system intelligently manages wireless access points to maintain optimal connectivity. Granted a US Patent.

React NativeDjangoUS PatentMobile Innovation

Travis CI

2019-Current

Travis CI On-Prem

Architected and built critical features for one of the world's leading continuous integration platforms, serving thousands of organizations globally. Implemented advanced caching strategies, parallel execution systems, and intelligent resource allocation.

CI/CDDevOpsInfrastructureYAMLGlobal Scale

Multiple Clients

2012-Current

Version Control Systems

Implemented and managed Perforce version control systems for institutions including Stanford, MIT, Harvard, Google, Lockheed Martin, and Nike. Designed scalable architectures handling massive codebases with thousands of developers.

PerforceVersion ControlArchitectureGlobal Scale

Security Research

2025-Current

Rigmaiden

A secure system management tool for handling USB devices, network interfaces, and system resources. Can detect IMSI-catching activity and respond accordingly. Built for educational and law enforcement purposes.

SecurityIMSI DetectionSystem ManagementCross-Platform

Contact

GitHub

I basically don't respond to outreach, I'm in a full-time role. The best thing to do is check out my GitHub. If you still choose to reach out, include a concise brief message with context.

github.com/montana ->
contact.js
1const developer = {
2name: "Michael Mendy",
3role: "Senior DevOps Engineer",
4experience: 12, // years
5location: "Los Angeles, CA",
6github: "github.com/montana",
7skills: ["Python", "JavaScript", "Ruby", "Docker", "K8s"],
8clients: ["MIT", "Google", "Lockheed Martin", "Nike"]
9}

Michael Mendy © 2026