Skip to content
Epic Software Labs
← All services

Cloud & Platform

Security Engineering

Security work calibrated to your stage — not enterprise theatre. The goal is a codebase that’s hard to break, an external assessor that finds nothing, and a certification process that doesn’t stall the next round.

A glowing teal glass core at the centre of nested lattice shells of dark metal, each finer than the last.

What the work involves

Codebase hardening

  • SAST (Semgrep, CodeQL) wired into CI as a blocking gate
  • Dependency scanning, SBOM, and patch policy (Renovate, Dependabot)
  • Secret scanning at commit, pre-receive, and rotation playbooks
  • Hardened defaults: authn/authz, headers, input validation, CSP

Internal pentesting & assurance

  • Internal pentest in preparation for an external CREST/CHECK engagement
  • Threat modelling (STRIDE) on the load-bearing flows
  • Pen-test remediation tracking through to closure

Compliance readiness

  • Cyber Essentials and Cyber Essentials Plus preparation
  • SOC 2 Type I / Type II controls mapping
  • ISO 27001 ISMS scoping and control selection

What you get

  • Internal pentest report + remediation plan
  • Cyber Essentials Plus readiness checklist (signed off)
  • Secure SDLC document + CI security gates

Tools we reach for

  • Semgrep
  • CodeQL
  • Renovate
  • Trivy
  • OWASP ZAP
  • Vanta
  • Drata

Also in Cloud & Platform

Need this on your team?

Tell us the problem and we’ll give you an honest read on whether this is the right discipline for it.