How HackerRank regained 20% of its engineering time with Sprinto

HackerRank is the de facto choice for finding and recruiting technical talent. Companies across the world, including large-scale enterprises like Adobe, Atlassian, and Zynga, rely on HackerRank’s platform to run full-stack skill assessments when hiring developers.

20% decrease In bandwidth spent on compliance tasks
300+ employees Enrolled in security training modules from the platform
30 minutes Bi-weekly call was all the CTO spent on his part
Sprinto white-logo
Before Sprinto
After Sprinto
Security questionnaires from large enterprises and banks were a constant ask, and completing them was long drawn out and time-consuming.
A SOC2 Type 1 report cut down the time HackerRank spent dishing out infrastructure details and, in some cases, made questionnaires redundant. A summary went to the sales team and the report was added to the HackerRank platform for customers to download.
Answering security questions pulled engineers away from building the product and improving features for customers.
HackerRank’s engineering teams now spend as much as 20% less time looking for problems, with the platform alerting them on what needs to be done.
Internal knowledge of SOC2 was limited, and there was no clear way to manage a compliance program.
HackerRank followed Sprinto’s guided implementation plan with a dedicated CSM running the process, which took only a bi-weekly 30-minute call from the CTO.
“Anytime I use engineers for answering security questions, I take the time they could be using to build the actual product or make features better for our customers. I wanted to see how I could manage compliance with the least amount of engineering time taken away from product development.”


– Harishankaran K
Co-founder and CTO, HackerRank

“While the onus is still on the teams and employees to complete their tasks, since using Sprinto, our engineering teams are spending as much as 20% less time looking for problems. The platform automatically alerts us when something needs to be done, where we need to look, and what will take us to the 100% compliance mark.”


– Harishankaran K
Co-founder and CTO, HackerRank

Introduction

HackerRank is the de facto choice for finding and recruiting technical talent. Companies across the world, including large-scale enterprises like Adobe, Atlassian, and Zynga, rely on HackerRank’s platform to run full-stack skill assessments when hiring developers.

Working with large companies and major institutions like banks makes security due diligence a standard event at HackerRank, and the company needed to prove enterprise readiness without draining engineering time. “It became evidently clear that a SOC2 report would cut down the time we spent dishing out details of the health of our infrastructure and provide indivisible proof of readiness,” says Harishankaran K, Co-founder and CTO at HackerRank.

The Problem

With security due diligence a standard event, requests to fill out security questionnaires were a common ask at HackerRank. Completing them was long drawn out, time-consuming, and ate into the engineering teams’ bandwidth, so HackerRank needed a solution that could sufficiently offload the process from engineering.

A SOC2 report, by design, spells out security posture and proves enterprise readiness, which would make questionnaires faster to handle and in some cases redundant. “There were times where a customer would outright say that we could either send them a SOC2 report or fill out an Excel sheet with security questions,” remarks Harishankaran.

HackerRank therefore sought out a partner who could help it get SOC2 compliant and generate a Type 1 report without bearing down on its engineering team. “Anytime I use engineers for answering security questions, I take the time they could be using to build the actual product or make features better for our customers. I wanted to see how I could manage compliance with the least amount of engineering time taken away from product development,” says Harishankaran.

The Solution

HackerRank chose Sprinto to organize and orchestrate a SOC2 compliance program without trading off its teams’ priorities. HackerRank integrated Sprinto’s platform with its systems and infrastructure to run automated checks on key SOC2 controls mapped to three major Trust Service Criteria (TSC).

As part of the same program, HackerRank made security training modules available to 300+ employees directly from the platform, with adherence mapped and measured inside a central dashboard.

Building the program out took very little of the leadership’s calendar. “We didn’t know a lot about SOC2 but it was easy to follow Sprinto’s guided implementation plan,” remarks Harishankaran. “A bi-weekly call of 30 minutes is all I ended up spending on my part. A dedicated CSM guided us through the implementation process and then the platform did the rest.” He adds, “It’s like having a member in your team who project manages the whole process.”

Impact

HackerRank reached compliance readiness in a matter of weeks and received its SOC2 Type 1 report shortly after. A summary of that report was later produced and made available to the sales team. “Our GTM team was very happy,” remembers Harishankaran. HackerRank has also added the SOC2 report to its platform for customers to download and refer to.

Beyond maintaining security compliance, HackerRank uses Sprinto as an observability agent. With continuous monitoring in place, new vulnerabilities in critical infrastructure like GitHub are detected, admins are alerted to the event, and remediation is prompted to sustain compliance. “That kind of push and visibility is incredibly helpful,” he exclaims.

Besides the ensuing agility, Harishankaran has also observed an improvement in his degree of awareness of HackerRank’s security posture since using Sprinto. “As we grow and evolve, keeping up with the maturity becomes important,” he notes. “We are now able to manage security from one place. But over and above this, Sprinto helps us ensure trust in the systems we have in place.”

“While the onus is still on the teams and employees to complete their tasks, since using Sprinto, our engineering teams are spending as much as 20% less time looking for problems. The platform automatically alerts us when something needs to be done, where we need to look, and what will take us to the 100% compliance mark,” says Harishankaran.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
hackerrank logo
Industry Type

Technical talent assessment and recruiting software

Employees

300+

Regions

USA

Modules used
Continuous Monitoring Security Training Guided Implementation Integrations
Frameworks used
SOC 2 Type I