Case Study: Centralized Vulnerability Management Across a Multi-Tool Pipeline
The Challenge
SAS develops Customer Intelligence 360, a hybrid multi-tenant SaaS marketing platform, using continuous deployment. Their security pipeline generates findings from seven or more tool categories, each with overlapping coverage. Without centralized management, duplicate findings landed on developers from different tools, there was no triage layer, and migrating between security vendors created parallel finding streams that were impossible to correlate.
The Turning Point
SAS recognized they should have implemented centralized vulnerability management before migrating security tools. Without a layer between scanners and developers, tool transitions caused higher developer impact and inconsistent finding formats. They chose DefectDojo as the single source of truth to sit between their CI/CD pipeline and Jira, normalizing output across all tools.
The DefectDojo Implementation
The SAS Institute implemented DefectDojo as the central hub for all vulnerability findings across their Customer Intelligence 360 product. Their pipeline feeds findings from SAST, SCA, secret scanning, DAST, container image scanning, IAST, and cloud security posture management tools directly into DefectDojo, replacing a fragmented system where each tool opened Jira tickets independently with no triage or visibility in between.
The integration includes automated Jira ticket creation and resolution, normalized finding titles across tool types, embedded remediation instructions, CVE tracking, and SLA-driven goal dates. For high-confidence findings, the entire flow from scan to developer ticket is fully automated with no manual triage required.
The Results
With DefectDojo in place, The SAS Institute achieved faster mean time to resolution by catching and routing verified findings directly to the right developers. Deduplication across overlapping tools eliminated redundant work, and developers now only act on triaged, verified findings rather than raw scanner output.
From a developer perspective, automated ticket lifecycle management means less time in Jira closing tickets and more time writing features. Service owners gained a single-pane view of their security posture with configurable alerting on SLA breaches and risk acceptance expirations. Management gained holistic situational awareness across all services and the ability to run vulnerability impact assessments against service metadata.