Thread regarding Optum layoffs

ESRO is such a clown show

They give all these teams a deadline of 12/15 to get their MBO score in order. Many teams in our org had releases scheduled to address various vulnerabilities prior to this deadline. Now that date has magically shifted to 12/10 and the "MBO Score" which determines our year end review and RRP eligibility is frozen.

Who the he-l decided that giving these id--ts this much influence in the company was a good idea? Half the time their scanners aren't even working and they don't know why, so your MBO score will fluctuate between two wildly different numbers weekly, making planning not an option.


by
| 1041 views | | 2 replies (last December 11) | Reply
Post ID: @OP+1kc4jw7p8

2 replies (most recent on top)

@bh The tools they are enforcing for scanning are garbage. Constant false positives, and a 'guilty until proven innocent' mentality. It seems like I'm always stuck in 'maintenance' mode, because my pipelines randomly fail due to some new false positive scan alert which blocks the build from completing and pushing.

The ESRO team is also great at deflecting. You join their calls to address a false positive, and they may direct you to another team that has nothing to do with it, or ask you to send an email to them to take it offline. Problem is, they never respond to that email in several cases I've tried. It seems like their primary focus is to get off the office hours call as quickly as possible with as few as possible action items on their side.

Security is great, but to use products which are obviously not ready for this level of enterprise usage is frustrating. Probably just went with the cheapest option available.

by
| | Reply
Post ID: @c0+1kc4jw7p8

@OP how about just code securely. It's been around for ohhhhh more than 20 years now. Why are you working on vulnerabilities when code should be secure-by-design.

ESRO is not influenceing the company for secure coding, the CTO, shareholders, board and all the customers want and need secure code which is professional grade code.

by
| | Reply
Post ID: @bh+1kc4jw7p8

Post a reply

: