
CHALLENGE
A publicly traded company in the insurance technology sector had an alarming number of un-remediated vulnerabilities across their internal and external application portfolio, including revenue-generating websites/mobile apps. With the program sitting in an immature pipeline state with no secure SDLC policies and almost no tooling/automation (just open-source code scanners, manual secure code review, arbitrary pre-deployment standards, etc.).
SOLUTION
The client needed a security solution to manage the influx of risks and enhance their undeveloped program. The client did not have a DevSecOps program in place nor the resources to help secure their SDLC along with their CI/CD pipeline to allow automation for scanning their applications. They chose to partner with Optomi to find a highly skilled and certified team to establish a vulnerability remediation process against the number of security threats faced every day.
Certifications
Optomi consultants held the following certifications:
- CISSP
- GSSP-Java
- CSSLP
- GWAPT
- GCPN
- AWS Solutions Architect/Security Specialty
THE OPTOMI DIFFERENCE
Optomi is skillset-focused. Our recruiters are five times more certified than the rest of the IT Staffing industry. They are truly integrated within the Cyber Security community across the U.S.
Based on the client’s goals, we deployed highly certified, hybrid security resources to include Senior Engineering Consultants (AppSec & Cloud Sec) and an Architect/Lead Consultant (AppSec & Cloud Sec). With a strong combination of skills and industry-recognized certifications, their new hybrid team secured the cloud and container environment (EC2s, S3 buckets, EKS clusters, etc.) that supported these apps along with firewalls/ WAFs, monitoring/logging, key/secrets management (Hashicorp Vault), CSPM (Wiz.io), encryption, and automated detection.
RESULTS
Having their new DevSecOps team in place, the client saw positive results immediately. With the program starting at an immature pipeline state, Optomi consultants transformed it into a robust DevSecOps program with established remediation SLAs and secure coding standards, commercial SAST/DAST/SCA tools with automated scanning schedules, and security-conscious development teams. This resulted in a 70%+ average reduction in web and mobile application vulnerabilities, with critical findings for all applications near zero.
Today, the client’s DevSecOps team is now established with a combination of security and development skills. With the proper security processes surrounding their application development lifecycle, the client experiences little to no vulnerabilities, preparing them for a brighter future in the cyber security space.
70%
reduction
in web and mobile application vulnerabilities
Want to take the first step towards eliminating vulnerabilities and enhancing your underdeveloped programs?
Contact us at info@optomi.com to get started!








