Hi everyone. I'm new to the security side of our data pipeline but have been tasked with researching a SAST + DAST solution. We're a mid-sized e-commerce company with a dev team of about 40, mostly using Python and JavaScript with some legacy PHP.
Our main apps are customer-facing: the storefront, cart, and payment integrations. We're moving to a microservices model, so we need something that can integrate into our CI/CD (Jenkins) and work with cloud deployments (AWS). I'm trying to understand if Veracode is a good fit.
My main questions are:
1. How steep is the learning curve for developers who aren't security experts?
2. How well does it handle the combo of modern frameworks and older monolithic code?
3. Is the pricing model manageable for a team of our size, or does it get complex quickly?
I'm looking for concrete examples on integration and how actionable the findings are. We don't have a dedicated AppSec team, so the tool needs to guide us clearly.
PipelinePadawan