In many organizations security testing is done outside of development testing loops, following a
“scanthenfix”
approach. The security team runs a scanning tool or conducts a pen test, triages
the results, and then presents the development team a list of vulnerabilities to be fixed. This is
often referred to as "the hamster wheel of pain". There is a better way.