At a glance
- Organisation: a UK health-tech company building software that handles regulated health data
- My role: designed and integrated the scanning into existing delivery pipelines, working with DevOps and developers
- Scope: application code moving through the CI server, source control platform, and data-pipeline orchestration
- Result: code-level security checks run as part of normal delivery, not as a separate afterthought
The problem
How I approached it
- Worked inside the existing toolchain. The scanning plugs into the pipelines developers already use, rather than adding a new platform for them to learn.
- Used two complementary SAST approaches. Pattern-based rule scanning catches known insecure constructs quickly, and broader code-quality analysis catches issues that sit between security and maintainability.
- Integrated at the pipeline level, so every change is scanned automatically and the results are visible to the developers who own the code.
- Partnered with DevOps and development teams throughout, so the checks fitted how they work rather than slowing them down.
Why this matters
- Earlier fixes are cheaper fixes: issues are caught while the code is still fresh in the developer's mind.
- Evidence for audits: automated scanning gives a repeatable, demonstrable control for ISO 27001 and customer security reviews.
- Shared ownership: security findings land where the code lives, with the people who can fix them.






