Finding exploitable risk is only part of the security challenge. In large, decentralized organizations, findings also need to reach the right owners and move into remediation without creating another disconnected process.
Virginia Tech needed a scalable way to validate external exposure across an environment spanning hundreds of independent departments, multiple locations, cloud providers, and locally managed infrastructure.
This customer story explores how Virginia Tech used the NodeZero® GraphQL API to automate external pentesting through GitLab and route findings into ServiceNow, creating a repeatable workflow from attack validation to remediation.
Key Insight
Security testing creates more value when findings flow directly into the systems teams already use to manage engineering work and remediation.
Rather than treating pentesting as a standalone security activity, Virginia Tech integrated NodeZero into its existing engineering processes.
The result:
- Automated external pentesting through GitLab
- Attack validation integrated into an existing engineering workflow
- Direct routing of findings into ServiceNow
- Clear assignment and follow-up for subnet owners
- A repeatable process connecting testing, ownership, and remediation
- Greater accountability across a highly decentralized environment
What You’ll Learn
- How to operationalize pentesting across a large, federated organization
- How the NodeZero GraphQL API enables security workflow automation
- How Virginia Tech integrated autonomous pentesting with GitLab
- Why routing findings directly into ServiceNow improves remediation workflows
- How automation helps lean security teams scale external attack validation
- How to connect security findings with the teams responsible for remediation
- Why pentesting shouldn’t end when a report is produced
Why It Matters
Large organizations often distribute technology ownership across many teams. That makes security validation as much an operational challenge as a technical one.
At Virginia Tech, the security organization supports an environment serving more than 38,000 students, with hundreds of independent departments and infrastructure spanning Virginia, the Washington, D.C., area, major cloud providers, and public-facing assets around the world.
Generating another security report wouldn’t solve the coordination problem.
By using NodeZero as the attack validation layer between GitLab and ServiceNow, Virginia Tech created a workflow in which testing can run automatically, findings reach responsible owners, and remediation is tracked through established processes.
Testing no longer ends when the pentest does. Each run becomes part of a repeatable security operation connecting validation → ownership → remediation.
Download the customer story to see how Virginia Tech integrated NodeZero with GitLab and ServiceNow to automate external pentesting and create a repeatable path from attack validation to remediation.

