Oxford, England
ProjectsJuly 2, 2024

Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines
  • Organisation: a UK health-tech company building software that handles regulated health data
  • My role: designed and integrated the scanning into existing delivery pipelines, working with DevOps and developers
  • Scope: application code moving through the CI server, source control platform, and data-pipeline orchestration
  • Result: code-level security checks run as part of normal delivery, not as a separate afterthought
In an organisation handling health data, a vulnerability that reaches production is expensive: in remediation effort, in audit findings, and potentially in data protection terms. The aim was to move those checks as early as possible in the lifecycle, into the pipeline developers already use every day. Security then becomes part of how code ships, rather than a gate at the end.
  1. Worked inside the existing toolchain. The scanning plugs into the pipelines developers already use, rather than adding a new platform for them to learn.
  2. Used two complementary SAST approaches. Pattern-based rule scanning catches known insecure constructs quickly, and broader code-quality analysis catches issues that sit between security and maintainability.
  3. Integrated at the pipeline level, so every change is scanned automatically and the results are visible to the developers who own the code.
  4. Partnered with DevOps and development teams throughout, so the checks fitted how they work rather than slowing them down.
  • Earlier fixes are cheaper fixes: issues are caught while the code is still fresh in the developer's mind.
  • Evidence for audits: automated scanning gives a repeatable, demonstrable control for ISO 27001 and customer security reviews.
  • Shared ownership: security findings land where the code lives, with the people who can fix them.
Static application security testing, CI/CD integration, secure SDLC, developer enablement.

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Xcevia: a security consultancy in the making
In development

Xcevia: a security consultancy in the making

A practitioner-led security consultancy for UK SMEs that I'm building on the side. It's not trading yet. The groundwork is being laid for Cyber Essentials Plus readiness, cloud security, and DevSecOps support.
Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage

A vendor review at a UK health-tech company. I consolidated onto one platform that covers every operating system and the cloud, then closed the one remaining gap with a dedicated patch management tool.
Incident response and endpoint security in health tech

Incident response and endpoint security in health tech

Owning day-to-day alert handling across a multi-OS estate at a UK health-tech company, correlating cloud activity with endpoint telemetry, and leading the response to a live, high-severity security incident.
Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance

Preparing the organisation for Cyber Essentials Plus certification, running the annual penetration testing programme, and keeping security policy, BCP/DR and awareness training aligned with ISO 27001 and GDPR.
EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care

An Innovate UK funded feasibility study and proof of concept with PBL Care Limited and Birmingham City University. The system replaces paper-based complaint handling with CQC-standard digital forms, NLP classification, and a live dashboard.