Decrease Security Risks with a Highly Certified DevSecOps Team
February 1, 2024

CHALLENGE

A publicly traded company in the insurance technology sector had an alarming number of un-remediated vulnerabilities across their internal and external application portfolio, including revenue-generating websites/mobile apps. With the program sitting in an immature pipeline state with no secure SDLC policies and almost no tooling/automation (just open-source code scanners, manual secure code review, arbitrary pre-deployment standards, etc.).


SOLUTION

The client needed a security solution to manage the influx of risks and enhance their undeveloped program. The client did not have a DevSecOps program in place nor the resources to help secure their SDLC along with their CI/CD pipeline to allow automation for scanning their applications. They chose to partner with Optomi to find a highly skilled and certified team to establish a vulnerability remediation process against the number of security threats faced every day.

Certifications

Optomi consultants held the following certifications:

  • CISSP
  • GSSP-Java
  • CSSLP
  • GWAPT
  • GCPN
  • AWS Solutions Architect/Security Specialty

THE OPTOMI DIFFERENCE

Optomi is skillset-focused. Our recruiters are five times more certified than the rest of the IT Staffing industry. They are truly integrated within the Cyber Security community across the U.S.


Based on the client’s goals, we deployed highly certified, hybrid security resources to include Senior Engineering Consultants (AppSec & Cloud Sec) and an Architect/Lead Consultant (AppSec & Cloud Sec). With a strong combination of skills and industry-recognized certifications, their new hybrid team secured the cloud and container environment (EC2s, S3 buckets, EKS clusters, etc.) that supported these apps along with firewalls/ WAFs, monitoring/logging, key/secrets management (Hashicorp Vault), CSPM (Wiz.io), encryption, and automated detection.

RESULTS 

Having their new DevSecOps team in place, the client saw positive results immediately. With the program starting at an immature pipeline state, Optomi consultants transformed it into a robust DevSecOps program with established remediation SLAs and secure coding standards, commercial SAST/DAST/SCA tools with automated scanning schedules, and security-conscious development teams. This resulted in a 70%+ average reduction in web and mobile application vulnerabilities, with critical findings for all applications near zero.


Today, the client’s DevSecOps team is now established with a combination of security and development skills. With the proper security processes surrounding their application development lifecycle, the client experiences little to no vulnerabilities, preparing them for a brighter future in the cyber security space. 

70%

reduction

in web and mobile application vulnerabilities

Download the PDF version of this case study

Want to take the first step towards eliminating vulnerabilities and enhancing your underdeveloped programs?

Contact us at info@optomi.com to get started!

February 10, 2025
Optomi Professional Services (OPS) is pleased to announce the appointment of Carey Luhn as the organization's Vice President of Strategic Accounts. In this role, Luhn will be responsible for creating development strategies aligned to enterprise partners with a focus on growing adoption of the unified suite of OPS service offerings.
Blake Guyton, Chief Revenue Officer (CRO) of Optomi Professional Services
October 4, 2024
Optomi Professional Services (OPS) is pleased to announce the addition of Blake Guyton as the company's Chief Revenue Officer (CRO). In this role, Guyton will provide strategic and tactical leadership across key revenue-focused initiatives as OPS continues to unify and elevate their service offerings.
Optomi + Staffing Industry Analysts (SIA) Fastest Growing Staffing Firms list 2024
September 17, 2024
Optomi is proud to announce its recognition from Staffing Industry Analysts (SIA) as one of the fastest-growing staffing firms in the U.S. Appearing on the list for the fifth time, Optomi ranked 2024 and 9th among IT-focused firms. The company's continued success showcases its dedication to delivering top-tier IT solutions.
Optomi has once again been named one of America’s Fastest Growing Private Companies by Inc. Magazine
August 13, 2024
Optomi has once again been named one of America’s Fastest Growing Private Companies by Inc. Magazine with the release of its annual Inc. 5000 list. This marks the eighth consecutive year that Optomi has earned this recognition, showcasing an unwavering commitment to excellence and growth. “This achievement highlights our team's ability to navigate challenges and seize opportunities. We're proud to be part of the Inc. 5000 and excited for the future as we continue to grow and evolve,” said Chuck Ruggiero, CEO of Optomi Professional Services. “Our inclusion in this list for the eighth consecutive year serves as a powerful reminder of what we can accomplish together. We are more motivated than ever to push boundaries, embrace change, and drive forward with the same determination that has brought us this far." Compiled annually by Inc. magazine, the Inc. 5000 list recognizes the fastest-growing private companies in America. This award is based on sustained revenue growth over a three-year period and showcases organizations that have demonstrated consistent growth and the ability to thrive in competitive markets. Over this period, Optomi achieved an impressive 145% growth, highlighting our commitment to excellence and innovation within a dynamic marketplace. Optomi President Radka Winwood said, “We are thrilled to be recognized among the fastest-growing companies in America, a testament to the extraordinary grit, tenacity, and drive of our team. This achievement underscores our unwavering perseverance, innovation, and ability to stay ahead of industry trends. As we move forward, our focus remains on driving growth and exceeding expectations for our partners and consultants alike.”  View the full release here .
Once again, Optomi is pleased to announce its recognition by Staffing Industry Analysts (SIA) as one
July 15, 2024
Once again, Optomi is pleased to announce its recognition by Staffing Industry Analysts (SIA) as one of the Largest IT Staffing Firms in the US in 2024.
July 3, 2024
A mobility, Big Data, and Cloud Intelligence company struggled with finding local, on-site resources to deliver cutting-edge connected products. The client required skilled software engineers and product delivery resources with experience in mature agile/Scrum methodology within a production environment to transform the automotive industry.
May 15, 2024
A global leader in security-related services embarked on a project to integrate three critical Identity and Access Management (IAM) solutions: SailPoint IdentityNow, CyberArk, and Okta. With a team of only one primary engineer and a backup, the project faced significant resource constraints. The integration required robust technical skills, especially in managing APIs, debugging, and setting up backend connections. Additionally, the client struggled to manage compliance with HIPAA and SOX regulations, which require meticulous attention to detail and thorough documentation.
March 30, 2024
A Fortune 500 software and technology company was struggling with executing an organizational shift to user and product-focused initiatives. The client had a surplus of UX designers and not enough product-focused designers to handle requests flooding in from shared services. The company was evolving and needed all inquiries to funnel through one, robust team comprised of individuals capable of carrying multiple skillsets.
December 21, 2023
A Fortune 500 utilities company faced several challenges with running its Cyber Security Operations Center (CSOC). After evaluating the situation with their prior managed security service provider (MSSP), the client realized the MSSP did not have the appropriate access or authorization to investigate alerts off-site. This was extremely important for the client as they had multiple security protocols in place, meaning that investigations of alerts and escalations required on-site authorization or full-time employee (FTE) access. The client also struggled with retention and did not have effective methods to find quality candidates that fit the culture of their organization.
November 2, 2023
For 20 years, a multinational healthcare services company relied on the outsourcing support of a managed services provider to fulfill their hiring needs. Upon evaluating the deal later on, the client learned that not only were they overspending on resources, but that they lacked all contract proprietary rights. They did not own any of the documentation or standard operating procedures in place in their own company, handcuffing them to their old vendor.
More Posts
Share by: