A publicly traded company in the insurance technology sector had an alarming number of un-remediated vulnerabilities across their internal and external application portfolio, including revenue-generating websites/mobile apps. With the program sitting in an immature pipeline state with no secure SDLC policies and almost no tooling/automation (just open-source code scanners, manual secure code review, arbitrary pre-deployment standards, etc.).
The client needed a security solution to manage the influx of risks and enhance their undeveloped program. The client did not have a DevSecOps program in place nor the resources to help secure their SDLC along with their CI/CD pipeline to allow automation for scanning their applications. They chose to partner with Optomi to find a highly skilled and certified team to establish a vulnerability remediation process against the number of security threats faced every day.
Optomi is skillset-focused. Our recruiters are five times more certified than the rest of the IT Staffing industry. They are truly integrated within the Cyber Security community across the U.S.
Based on the client’s goals, we deployed highly certified, hybrid security resources to include Senior Engineering Consultants (AppSec & Cloud Sec) and an Architect/Lead Consultant (AppSec & Cloud Sec). With a strong combination of skills and industry-recognized certifications, their new hybrid team secured the cloud and container environment (EC2s, S3 buckets, EKS clusters, etc.) that supported these apps along with firewalls/ WAFs, monitoring/logging, key/secrets management (Hashicorp Vault), CSPM (Wiz.io), encryption, and automated detection.
RESULTS
Having their new DevSecOps team in place, the client saw positive results immediately. With the program starting at an immature pipeline state, Optomi consultants transformed it into a robust DevSecOps program with established remediation SLAs and secure coding standards, commercial SAST/DAST/SCA tools with automated scanning schedules, and security-conscious development teams. This resulted in a 70%+ average reduction in web and mobile application vulnerabilities, with critical findings for all applications near zero.
Today, the client’s DevSecOps team is now established with a combination of security and development skills. With the proper security processes surrounding their application development lifecycle, the client experiences little to no vulnerabilities, preparing them for a brighter future in the cyber security space.
70%
reduction
in web and mobile application vulnerabilities
Want to take the first step towards eliminating vulnerabilities and enhancing your underdeveloped programs?
Contact us at info@optomi.com to get started!
Established in 2012, Optomi is committed to providing superior IT Talent Services via contract, contract-to-hire, and team augmentation models. Our delivery teams are aligned by competencies focused on 7 key areas in technology. Our skillset-focused approach allows our recruiting teams to become experts within their space and streamline the hiring process. We save you time and money by accelerating your hiring process as our delivery team truly understands your needs and only brings you the right talent for your team.