You come upon a long running project that has never had a security centric code review before. There are a couple millions lines of code, web applications, microservices, a database; a gold mine of s* to dig through. The opportunities for findings is massive. How the next steps are executed all depend on situational awareness and could result in CSMs (career shortening maneuvers). Topics covered will include what tools to have in the kit for a whitebox code review, what to prioritize, and whom with and how to collaborate with for short and longer term engagements.