
CHALLENGE
A publicly traded insurance technology company experienced an alarming number of unremediated vulnerabilities across its internal and external application portfolio, including revenue-generating websites and mobile apps. The program had an immature pipeline state with no secure SDLC policies and no tooling or automation—just open-source code scanners, manual secure code review, arbitrary pre-deployment standards, etc. With no DevSecOps program in place, the client needed a security solution to manage the influx of risks and enhance the undeveloped program. Optomi was engaged to source a highly skilled, certified team to establish a vulnerability remediation process against security threats.
SOLUTION
Optomi’s skillset-focused recruiters in the cybersecurity sector deployed highly certified, hybrid security resources including:
- Senior Engineering Consultants (AppSec & Cloud Sec)
- Architect/Lead Consultant (AppSec & Cloud Sec)
With a strong combination of skills and industry-recognized certifications, the client’s new hybrid team secured the cloud and container environment (EC2s, S3 buckets, EKS clusters, etc.) that supported these apps, along with firewalls/ WAFs, monitoring/logging, key/secrets management (HashiCorp Vault), CSPM (Wiz.io), encryption, and automated detection.
Optomi consultants held the following certifications:
- CISSP
- GSSP-Java
- CSSLP
- GWAPT
- GCPN
- AWS Solutions Architect/Security Specialty

IMPACT
The client immediately saw positive results with the new DevSecOps team in place. Optomi consultants transformed the immature pipeline state into a robust DevSecOps program with established remediation SLAs and secure coding standards, commercial SAST/DAST/SCA tools with automated scanning schedules, and security-conscious development teams. Web and mobile application vulnerabilities decreased, and critical findings for all applications were near zero. Today, the client’s DevSecOps team has implemented effective security processes throughout the application development lifecycle, resulting in minimal vulnerabilities and positioning them for future cybersecurity success.
Get in touch
Connect with Optomi to eliminate vulnerabilities and enhance underdeveloped programs.
Contact Us




