enreap-logo-header-desktop

How a leading bank enabled DevSecOps by shifting Security to the Left

Geography
Usa
Industry
Banking
Solution
DevSecOps
Services
DevOps
Employee size
10K +

The client

Discover how a leading bank enabled DevSecOps & improved compliance, reduced risks & accelerated secure software delivery.

Client requirements

  • Automated Security Integration Embed security scans into the development lifecycle to eliminate manual processes and delays.
  • Centralized Visibility & Tracking Provide a unified view of vulnerabilities, scan results, and remediation status across teams.
  • Scalable & Extensible Framework Enable integration of multiple security tools and support evolving DevSecOps requirements.
bny melon case study banner

Our approach & solution

enreap designed an event-driven DevSecOps framework integrated with GitLab CI/CD pipelines to automate application security scans. The approach enabled asynchronous scan execution, centralized result publishing, and seamless integration with existing tools—ensuring security became an integral part of the software development lifecycle without impacting developer productivity.

Automated CI/CD Security Integration

Embedded security scans directly into GitLab pipelines, enabling automated execution during code commits, merges, and release stages.

Event-Driven Orchestration

Leveraged an IFTTT-based framework using tools like Kafka and StackStorm to trigger and manage scans via API/CLI integrations with multiple AppSec tools.

Centralized Visibility & Extensibility

Enabled unified dashboards for scan results and vulnerability tracking, with a scalable architecture to integrate additional security tools over time.

Value delivered

  • Security scans automated and embedded into CI/CD pipelines
  • Reduced manual effort and eliminated process bottlenecks
  • Early vulnerability detection enabling “Shift Left” security
  • Improved developer productivity with minimal disruption
  • Centralized dashboards for visibility and tracking
  • Reduced risk of vulnerabilities reaching production

Technology stack

Jira
GitLab

How a leading bank enabled DevSecOps by shifting Security to the Left

Looking for a Digital Transformation Partner?

bny melon case study banner

Atlassian

How a leading bank enabled DevSecOps by shifting Security to the Left