Applying Next-generation DevSecOps Principles

Pfizer

Industry

Healthcare/Medical

Service

Software Product Design and Development

Summary

  • Takeaway

    CHALLENGE

    In light of COVID-19, Pfizer needed to move faster. That meant the software systems powering its supply chain needed to meet changing requirements with speed.

  • Takeaway

    PARTNERSHIP

    Working across more than 20 disparate teams, we helped Pfizer adopt the research-based practices of DevSecOps that help software teams move faster and with high reliability. The approach highlighted a new version control plan that empowers frequent, immediate feedback and global collaboration.

  • Takeaway

    IMPACT

    By implementing next-gen DevSecOps practices, Pfizer adopted a streamlined software delivery process — enhancing security and compliance — and resulting in a 50% reduction in deployment times.

Pfizer feature medium

It goes without saying that the devastating COVID-19 pandemic changed a great many things for a great many people. But for Pfizer, the unprecedented speed of its response to the need for a vaccine revealed the very real need to move faster, and create systems that would empower change.

Services Provided

  • API Development
  • Application Architecture
  • Cloud Infrastructure & Migration
  • Enterprise Software Development
  • Solution & System Architecture
  • Test Automation
  • Third-party Integrations

OBJECTIVE

Collaboration, iteration, and implementation at the speed of change

Working across more than 20 disparate teams, 8th Light’s teams helped Pfizer establish a DevSecOps foundation that empowers them to collaborate confidently at scale.

It's a partnership and you know that from day one. They really care and want you to succeed.

Vincent Ryan
Senior Manager, Solution Delivery Lead
Pfizer

Results

After assessing the tech stack and systems, a reliable architecture was developed to complement the legacy system and a suite of shared tools established streamlined efficiencies.

To accomplish this, a new version control plan featured frequent, immediate feedback and global collaboration. Configured CI/CD pipelines and automated cloud services tasks streamlined movement of code between environments, reducing the time from solution to production and operational expenses while making processes more predictable.

A uniform secret management plan greatly tightened security for teams who were previously unfamiliar with the tools and techniques; and dedicated servers and role management strategies have streamlined network access, creating additional layers of security across the full corporate network.


 

After identifying opportunities to evolve their security posture, more than 20 teams migrated to a new code hosting solution. Throughout the effort, a suite of automated tools was developed to create a more rigorous, reliable, and secure deployment flow.

The new architecture accommodated the existing legacy system, which enabled a smooth transition. The new tools alongside Pfizer's team are helping to mentor their developers on the languages and tools while empowering them to craft their new environment. And through a facilitated hands-on workshop, teams gained a shared language for seamless collaboration.

Conclusion

Continuing to build on success

This work is just the start of Pfizer’s transformative journey. With 8th Light’s support, Pfizer not only enhanced reliability but aims to launch a robust knowledge management initiative (EQMS) that fosters best practices across teams and researchers. As the collaboration continues, we look forward to finding new opportunities to drive greater impact, ensuring Pfizer stays at the forefront of innovation.


 

Source code was migrated from a manual deployment to an automated and planned CI/CD pipeline. The result: a more asynchronous, observable, and secure deployment pipeline.