Close
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We couldn't find anything for that query...

Top 1%: How depthfirst Built RevOps on Signals Before Scaling Its Sales Team

Mark Hardy, Head of Revenue Operations at depthfirst, on building the AI security startup’s go-to-market systems as a RevOps team of one.

Author
Author
Clay Team
Date
Sep 9, 2026

Many tech startups hire a team of sales reps first, then build the go-to-market systems later. depthfirst built their systems first.

Mark Hardy is Head of Revenue Operations at depthfirst, an AI security company that finds and fixes vulnerabilities in software. He is a RevOps team of one, building foundational systems now so the team is ready to scale as the sales team grows. Clay is central to their setup; they’re using the platform to turn breach and 10-K signals into Audience segments of security buyers that update automatically. Then, Clay Ads reaches those same buyers on LinkedIn.

Caren Duane, Head of New Bets at Clay, calls Mark a top 1% GTM engineer. 

But not long ago, Mark was doing RevOps the way he always had: managing a stack of tools and fielding requests like an internal help desk. Now he’s connecting Clay, Claude Code, Gong, and Lovable into one system where signals from customer calls become segments and campaigns. Plus, anyone at depthfirst can get answers without going through him. Making this transition came down to curiosity, not becoming ultra-technical. 

Top 1% is our series where we sit down with the best GTM operators in the world. Watch our full conversation with Mark Hardy or catch up on episodes with Osman Sheikhnureldin at Clay or Michael Tai at Brex.

How a one-person RevOps team finds the right buyers

Depthfirst self-describes as the operating system for modern security. The platform maps an entire app, weeds out the security vulnerabilities that traditional scanners miss, confirms which ones are truly exploitable, and opens pull requests to fix them. Its buyers include CISOs and heads of security; the company counts companies like Lovable, Faire, and Tailscale as customers.

Mark’s overarching go-to-market strategy involves going after two kinds of businesses:

  1. Companies still running legacy app security tools like Snyk and Veracode, which depthfirst aims to replace
  2. Companies where engineers are using AI code editors like Cursor (their hypothesis is that these companies produce more code than is feasible for their security teams to review) 

Mark is the entire RevOps team at depthfirst, so his job is to find those companies and the right people inside them. That starts with the basics: Clay enriches accounts and pulls technographic data to see which security tools a company already runs and whether its engineers (and now non-engineers) are coding with AI.

He also uses Clay signals to track things like:

  • 10-K filings, where public companies disclose cyber risk
  • Cybersecurity incidents in the last six to twelve months
  • Breaches and their financial impact
  • Which companies and people in an affected industry could use a product like depthfirst

Ideas for new signals often come from Gong call transcripts, where he hears what customers are worried about. He thinks of Clay as signals infrastructure: find a signal, structure it, push it to the CRM, then build a segment of the people who care about it.

Those segments live in Clay Audiences, which pulls in CRM and other first-party data and keeps the lists updated as records change. Working with depthfirst’s head of demand gen, Mark also builds segments like “CISOs at healthcare companies” or “VPs of application security at finance firms”, then layers on opportunity stage and renewal state to control who sees what at every step of the funnel. 

Warming up security buyers with ads before outbound starts

Once people are sorted into their segments, the bottleneck is writing the right message for that person at that moment. Breach and incident signals create a messaging problem. Emailing a CISO right after their company was attacked to say “this happened to you, so buy our product,” reads as insensitive fear-mongering.

Mark opts for an alternative approach: getting depthfirst’s own research in front of buyers before anyone gets a sales message. depthfirst’s security researchers use the product to find vulnerabilities in widely used open-source libraries, then publish the findings after responsible disclosure. That research runs as LinkedIn ads and posts aimed at the security leaders in his target segments. When a CISO clicks one of those ads or follows the company page, Clay records that engagement as a signal on the account. 

Only then does outbound begin. Instead of implying the buyer’s systems are insecure, the message is crafted to speak to a problem every security team has: legacy scanners generate so many false positives that teams stop trusting the dashboard. On the other hand, depthfirst finds complex authorization vulnerabilities that other tools miss.

Outbound and ads run at the same time. When a group of CISOs enters a sequence because of a signal, Mark builds an Audiences segment of those same people and pushes it to LinkedIn Campaign Manager, so they see ads while the emails land. Plus, the segment updates each week as new people enter the sequence. Security buyers are conservative, and reaching them across multiple touchpoints is often what gets a meeting on the calendar. Mark has also found that LinkedIn outreach works best when it comes from depthfirst’s founders versus a sales rep.

RevOps as the translation layer for the rest of the company

Beyond finding the right prospects and coordinating outreach, Mark considers it his job to arm the entire company with the same customer intelligence RevOps runs on. He uses Clay to do that, too. This company context brain he’s building consists of all of depthfirst’s systems and signals, connected, so that anyone in product, finance, sales, or marketing can get answers without going through him or booking a meeting. This removes the “collaboration tax” that might otherwise slow down a small company with aggressive goals.

Here are a few of the ways that intelligence is already reaching teams outside sales:

  • Brand voices. Mark crawled Slack and Gong to build voice profiles for the founders and others the company wants posting, and Clay finds the top LinkedIn posts and Twitter articles worth responding to. He also scraped the engineering team’s philosophy from Slack to guide his own code.
  • Rep onboarding. Using Gong and Notion alongside the signals built in Clay, he generates customized onboarding plans for an enterprise rep versus a commercial rep, or for someone focused on healthcare versus financial services.
  • Product questions. Anyone at depthfirst can search Gong call transcripts and Clay signals to see what customers say about a feature, or how prospects react when they consider building the product in-house instead of buying it.
  • Internal apps. Mark builds small apps with Clay and Lovable, like pricing calculators or one-to-one landing pages for target accounts. The ideas come from a standing item in depthfirst’s weekly meetings, where anyone can describe a tool they wish they had.

Mark is still depthfirst’s primary Clay user. Reps work in simpler interfaces he built on top of it, where they can add contacts and enrich accounts without opening a Clay table. He sees this as the direction RevOps and GTM engineering are heading in: the role becomes a translation layer, taking what the systems know and putting it in a form the rest of the company can use.

What Claude Code and Clay do together

Mark uses Claude Code as the analysis layer on top of Clay. Clay holds depthfirst’s data, tables, and the API keys for more than 200 providers, so he never handles credentials himself. Claude Code reads across it all and does the work a one-person team would otherwise skip.

  • Mapping his Clay workspace. He gave Claude Code his Clay session token so it could act as him and map which tables were running in his workspace, which integrations were connected, and what was pushing data to depthfirst’s Salesforce.
  • Auditing the Salesforce sync. Clay enriches depthfirst’s accounts and contacts, then pushes that data into Salesforce fields. Claude Code compared the two systems and actually found one Salesforce field that should have received Clay data but was populated on only 10% of records, meaning the sync for that column was broken. Mark added an update record column in Clay to push the data through, and Claude Code confirmed the field was now filled on 89% of records.
  • Mining Gong transcripts for signals. Claude Code runs a meta-analysis across every call as it comes in and surfaces patterns, like CISOs worried about budget and consolidating tools. Mark then turns those patterns into new Clay signals and segments.

Build on Clay with a coding agent. Clay’s agent plugin lets Claude Code or any other coding agent work inside Clay through the API and CLI, so you can source and enrich accounts, call your existing workflows and Claygents, and build new workflows in natural language without a session token workaround.

What separates the top GTM engineers from the rest

If you’re aiming to bring more automation to your own RevOps org, the systems Mark has built at depthfirst may sound daunting. But he started as a more conventional RevOps operator. Adding Claude Code to his tool stack brought some anxiety: he had fuzzy ideas about what a “GitHub repository” was or what it meant to “commit” or “push.” 

Automating as much of the job as possible, so his time goes to the most impactful work, is what’s driven him to push the limits of whatever tool he’s using—whether that’s Clay or Claude. His advice for others looking to do the same is to stop peering at what people are building on LinkedIn and start experimenting yourself: “The first step is you’ve got to download something or get a license. You’ve got to try it,” says Mark. 

In practice, much of this has meant prompting. AI tools have made it possible to build systems that used to require an engineer, removing the need to learn a coding language. You can describe what you want in plain English, so the only real barrier left is whether you’re willing to try.

More Articles