<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2489040.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>Security &amp; GRC Decoded</title>

  <lastBuildDate>Tue, 02 Jun 2026 12:05:17 -0400</lastBuildDate>
  <link>https://www.compliancecow.com/podcast/</link>
  <language>en</language>
  <copyright>© 2026 Security &amp; GRC Decoded</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>2a226cce-f413-5b5e-847c-ef30332cda1b</podcast:guid>
  <podcast:txt purpose="verify">eric.smith@compliancecow.com</podcast:txt>
  <itunes:author>Raj Krishnamurthy</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security &amp; GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security &amp; GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:keywords>ComplianceCow,Security,GRC,Compliance,IT,Cyber Security,Security and grc, security and grc decoded,Raj Krishnamurthy</itunes:keywords>
  <itunes:owner>
    <itunes:name>Raj Krishnamurthy</itunes:name>
    <itunes:email>eric.smith@compliancecow.com</itunes:email>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/pbqo043cwmb52q4mqxlufrom444g?.jpg</url>
     <title>Security &amp; GRC Decoded</title>
     <link>https://www.compliancecow.com/podcast/</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/pbqo043cwmb52q4mqxlufrom444g?.jpg" />
  <itunes:category text="Technology" />
  <itunes:category text="Business" />
  <podcast:person role="host" href="https://www.linkedin.com/in/rajkrishnamurthy/" img="https://storage.buzzsprout.com/j7zqdkas8gyjny0nxka5k80t1a85">Raj Krishnamurthy</podcast:person>
  <item>
    <itunes:title>Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath</itunes:title>
    <title>Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal, Head of GRC at UiPath, to explore why the future of GRC looks far more like systems engineering than traditional audit management. Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conve...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with <a href='https://www.linkedin.com/in/sheronpaulc/'>Sheron Chakalakal</a>, Head of GRC at <a href='https://www.uipath.com/'>UiPath</a>, to explore why the future of GRC looks far more like systems engineering than traditional audit management.</p><p>Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together.</p><p>This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year.</p><p><br/></p><p><b>Key Takeaways</b>:</p><ul><li>Modern GRC programs must evolve from audit functions into engineering-driven reliability functions.</li><li>Risk—not compliance—should be the central language for communicating with leadership teams.</li><li>Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.”</li><li>AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks.</li><li>Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership.</li></ul><p><br/></p><p><b>What You’ll Learn</b>:</p><ul><li>Why Sheron believes compliance should be designed into products from day one</li><li>How UiPath approaches continuous risk monitoring and GRC engineering</li><li>Why AIUC-1 introduces a fundamentally different approach to AI assurance</li><li>How GRC teams can become the “translation layer” between business and engineering</li><li>Why future GRC practitioners must develop technical and systems-thinking skills</li></ul><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Sheron Chakalakal | Head of GRC | UiPath<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/sheronpaulc/'>https://www.linkedin.com/in/sheronpaulc/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with <a href='https://www.linkedin.com/in/sheronpaulc/'>Sheron Chakalakal</a>, Head of GRC at <a href='https://www.uipath.com/'>UiPath</a>, to explore why the future of GRC looks far more like systems engineering than traditional audit management.</p><p>Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together.</p><p>This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year.</p><p><br/></p><p><b>Key Takeaways</b>:</p><ul><li>Modern GRC programs must evolve from audit functions into engineering-driven reliability functions.</li><li>Risk—not compliance—should be the central language for communicating with leadership teams.</li><li>Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.”</li><li>AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks.</li><li>Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership.</li></ul><p><br/></p><p><b>What You’ll Learn</b>:</p><ul><li>Why Sheron believes compliance should be designed into products from day one</li><li>How UiPath approaches continuous risk monitoring and GRC engineering</li><li>Why AIUC-1 introduces a fundamentally different approach to AI assurance</li><li>How GRC teams can become the “translation layer” between business and engineering</li><li>Why future GRC practitioners must develop technical and systems-thinking skills</li></ul><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Sheron Chakalakal | Head of GRC | UiPath<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/sheronpaulc/'>https://www.linkedin.com/in/sheronpaulc/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/19260665-beyond-checkbox-compliance-why-grc-must-become-an-engineering-discipline-ft-sheron-chakalakal-head-of-grc-uipath.mp3" length="38659520" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19260665</guid>
    <pubDate>Tue, 02 Jun 2026 11:00:00 -0500</pubDate>
    <itunes:duration>3218</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>36</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security &amp; Assurance Engineering @ CoreWeave</itunes:title>
    <title>From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security &amp; Assurance Engineering @ CoreWeave</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur, Principal of Security &amp; Assurance Engineering at CoreWeave, to explore how AI-native infrastructure is fundamentally reshaping GRC. Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with <a href='https://www.linkedin.com/in/jask31/'>Jasmine Kaur</a>, Principal of Security &amp; Assurance Engineering at <a href='https://www.coreweave.com/'>CoreWeave</a>, to explore how AI-native infrastructure is fundamentally reshaping GRC.</p><p>Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems.</p><p>Key Takeaways:</p><ul><li>Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them.</li><li>Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal.</li><li>GRC must evolve into an infrastructure-level capability that continuously emits assurance signals.</li><li>Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight.</li><li>Future GRC teams must operate more like engineering and reliability functions rather than audit teams.</li></ul><p>What You’ll Learn:</p><ul><li>Why AI infrastructure makes traditional audits ineffective</li><li>What “GRC as infrastructure” actually means in practice</li><li>How to move from point-in-time audits to continuous assurance</li><li>The difference between automation, CCM, and agentic GRC</li><li>How to position GRC as a proactive, business-critical function</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p>Watch more episodes:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p>Connect With Our Guest:<br/>Jasmine Kaur | Principal of Security &amp; Assurance Engineering | CoreWeave<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/jask31/'>https://www.linkedin.com/in/jask31/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/>Apple Podcasts: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with <a href='https://www.linkedin.com/in/jask31/'>Jasmine Kaur</a>, Principal of Security &amp; Assurance Engineering at <a href='https://www.coreweave.com/'>CoreWeave</a>, to explore how AI-native infrastructure is fundamentally reshaping GRC.</p><p>Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems.</p><p>Key Takeaways:</p><ul><li>Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them.</li><li>Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal.</li><li>GRC must evolve into an infrastructure-level capability that continuously emits assurance signals.</li><li>Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight.</li><li>Future GRC teams must operate more like engineering and reliability functions rather than audit teams.</li></ul><p>What You’ll Learn:</p><ul><li>Why AI infrastructure makes traditional audits ineffective</li><li>What “GRC as infrastructure” actually means in practice</li><li>How to move from point-in-time audits to continuous assurance</li><li>The difference between automation, CCM, and agentic GRC</li><li>How to position GRC as a proactive, business-critical function</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p>Watch more episodes:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p>Connect With Our Guest:<br/>Jasmine Kaur | Principal of Security &amp; Assurance Engineering | CoreWeave<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/jask31/'>https://www.linkedin.com/in/jask31/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/>Apple Podcasts: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/19128118-from-compliance-theater-to-grc-infrastructure-why-ai-breaks-traditional-grc-ft-jasmine-kaur-principal-of-security-assurance-engineering-coreweave.mp3" length="39031678" type="audio/mpeg" />
    <link>https://wwww.compliancecow.com/podcast</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19128118</guid>
    <pubDate>Tue, 05 May 2026 11:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/19128118/transcript" type="text/html" />
    <itunes:duration>3249</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>35</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis</itunes:title>
    <title>The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Val Dobrushkin, Director of GRC at Tricentis, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers. This conversation dives into the discon...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/dobrushkin/'>Val Dobrushkin</a>, Director of GRC at <a href='https://www.tricentis.com/'>Tricentis</a>, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers.</p><p>This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&amp;A outcomes, and why solving for today while building for the future is the key to long-term success.</p><p><b>Key Takeaways</b>:</p><ul><li>Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls.</li><li>SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity.</li><li>GRC has a unique advantage over security in directly demonstrating business value and revenue impact.</li><li>“Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition.</li><li>Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why questionnaires and annual vendor reviews fail to capture real third-party risk</li><li>How GRC teams can prove revenue impact through customer trust and assurance</li><li>The hidden role of GRC in M&amp;A, IPO readiness, and contract validation</li><li>Why most GRC metrics fail and what meaningful measurement should look like</li><li>How to implement a “solve now, build for future” strategy in fast-growing companies</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Val Dobrushkin | Director of GRC | Tricentis<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/dobrushkin/'>https://www.linkedin.com/in/dobrushkin/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/dobrushkin/'>Val Dobrushkin</a>, Director of GRC at <a href='https://www.tricentis.com/'>Tricentis</a>, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers.</p><p>This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&amp;A outcomes, and why solving for today while building for the future is the key to long-term success.</p><p><b>Key Takeaways</b>:</p><ul><li>Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls.</li><li>SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity.</li><li>GRC has a unique advantage over security in directly demonstrating business value and revenue impact.</li><li>“Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition.</li><li>Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why questionnaires and annual vendor reviews fail to capture real third-party risk</li><li>How GRC teams can prove revenue impact through customer trust and assurance</li><li>The hidden role of GRC in M&amp;A, IPO readiness, and contract validation</li><li>Why most GRC metrics fail and what meaningful measurement should look like</li><li>How to implement a “solve now, build for future” strategy in fast-growing companies</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Val Dobrushkin | Director of GRC | Tricentis<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/dobrushkin/'>https://www.linkedin.com/in/dobrushkin/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/19050743-the-grc-illusion-why-third-party-risk-is-still-broken-ft-val-dobrushkin-director-of-grc-tricentis.mp3" length="39895453" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19050743</guid>
    <pubDate>Tue, 21 Apr 2026 11:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/19050743/transcript" type="text/html" />
    <itunes:duration>3321</itunes:duration>
    <itunes:keywords>Cybersecurity, Risk Management, Information Security, InfoSec, Governance, Business Enablers, M&amp;A, Mergers and Acquisitions, Technology, Podcast, Director, Val Dobrushkin, Security Programs, Security, GRC, Compliance</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife</itunes:title>
    <title>GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Dylan O’Dell, AVP Information Risk Officer at Manulife, to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions. Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/dylan-odell-72a06412b/'>Dylan O’Dell</a>, AVP Information Risk Officer at <a href='https://www.manulifeim.com/en'>Manulife</a>, to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions.</p><p>Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why GRC needs to evolve beyond audits and control testing into automation, orchestration, and storytelling. This conversation explores how modern GRC teams can reduce operational friction, quantify real risk, and actually influence business outcomes.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC today is overly focused on control testing rather than true risk management and decision-making.</li><li>Automation should eliminate manual audit friction — not just make existing processes faster.</li><li>The future GRC professional must combine technical awareness with storytelling, influence, and business understanding.</li><li>Risk management should be rooted in probability and financial impact — not pass/fail compliance.</li><li>GRC teams can unlock funding and influence by tying their work directly to revenue, cost savings, and business outcomes.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why the “three lines of defense” model often breaks down in practice.</li><li>How to translate technical data into meaningful business risk narratives.</li><li>What modern GRC automation should actually look like (beyond tools).</li><li>How to position GRC as a revenue enabler — not just a cost center.</li><li>Why “start with why” is critical for influencing stakeholders and reducing friction.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </p><p><b>Learn more</b>:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Dylan O’Dell | <b>AVP Information Risk Officer</b> | Manulife<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/dylan-odell-72a06412b/'>https://www.linkedin.com/in/dylan-odell-72a06412b/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/dylan-odell-72a06412b/'>Dylan O’Dell</a>, AVP Information Risk Officer at <a href='https://www.manulifeim.com/en'>Manulife</a>, to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions.</p><p>Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why GRC needs to evolve beyond audits and control testing into automation, orchestration, and storytelling. This conversation explores how modern GRC teams can reduce operational friction, quantify real risk, and actually influence business outcomes.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC today is overly focused on control testing rather than true risk management and decision-making.</li><li>Automation should eliminate manual audit friction — not just make existing processes faster.</li><li>The future GRC professional must combine technical awareness with storytelling, influence, and business understanding.</li><li>Risk management should be rooted in probability and financial impact — not pass/fail compliance.</li><li>GRC teams can unlock funding and influence by tying their work directly to revenue, cost savings, and business outcomes.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why the “three lines of defense” model often breaks down in practice.</li><li>How to translate technical data into meaningful business risk narratives.</li><li>What modern GRC automation should actually look like (beyond tools).</li><li>How to position GRC as a revenue enabler — not just a cost center.</li><li>Why “start with why” is critical for influencing stakeholders and reducing friction.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </p><p><b>Learn more</b>:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Dylan O’Dell | <b>AVP Information Risk Officer</b> | Manulife<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/dylan-odell-72a06412b/'>https://www.linkedin.com/in/dylan-odell-72a06412b/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18971626-grc-is-broken-and-nobody-wants-to-admit-it-ft-dylan-o-dell-avp-information-risk-officer-manulife.mp3" length="48703365" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18971626</guid>
    <pubDate>Tue, 07 Apr 2026 09:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18971626/transcript" type="text/html" />
    <itunes:duration>4055</itunes:duration>
    <itunes:keywords>GRC automation and risk storytelling, GRC, risk management, control testing, automation, audit friction, financial impact, business outcomes, Lean Six Sigma, security, Dylan O’Dell</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security &amp; GRC @ Yahoo</itunes:title>
    <title>Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security &amp; GRC @ Yahoo</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security &amp; GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogie...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security &amp; GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogies to explain vulnerabilities, to reframing GRC as the “Draymond Green” of cybersecurity, Steven shows how the best security leaders translate complexity into clarity, help the business make better decisions, and meet people where they are instead of overwhelming them with jargon.</b></p><p><b>Key Takeaways:</b></p><ul><li><b>Security and GRC succeed when they communicate clearly to humans, not when they simply present more technical detail.</b></li><li><b>The best GRC teams act as guides that help the business make reasonable, compliant, cyber-conscious decisions.</b></li><li><b>Metrics only matter when they drive a clear outcome or decision, not when they exist for their own sake.</b></li><li><b>Strong GRC teams build trust by doing the hard, cross-functional work that others often avoid.</b></li><li><b>Storytelling is a core security skill because people act on messages they understand, remember, and relate to.</b></li></ul><p><b>What You’ll Learn:</b></p><ul><li><b>Why Steven believes security is ultimately a human communication problem.</b></li><li><b>How to tailor security messaging for engineering leaders, CISOs, and business stakeholders.</b></li><li><b>What “guardrails not gates” looks like in a practical GRC program.</b></li><li><b>How to think about data, metrics, and reporting without overwhelming your audience.</b></li><li><b>Why AI may change the consumption layer of GRC, but not eliminate the human need for storytelling.</b></li></ul><p><br/></p><p><b>This podcast is brought to you by </b><a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a><b> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:</b><a href='https://www.compliancecow.com/'><b> https://www.compliancecow.com</b></a></p><p><b>Watch more episodes:</b><a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'><b> https://www.compliancecow.com/podcast</b></a></p><p><b>Connect With Our Guest:<br/>Steven Asifo | Director of Security &amp; GRC | Yahoo<br/>Connect on LinkedIn: </b><a href='https://www.linkedin.com/in/asifosays/'><b>https://www.linkedin.com/in/asifosays/</b></a></p><p><b>Rate, review, and share if you enjoyed the show!</b></p><p><b>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: </b><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'><b>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</b></a></p><p><b><br/>Apple Podcasts: </b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</b></a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security &amp; GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogies to explain vulnerabilities, to reframing GRC as the “Draymond Green” of cybersecurity, Steven shows how the best security leaders translate complexity into clarity, help the business make better decisions, and meet people where they are instead of overwhelming them with jargon.</b></p><p><b>Key Takeaways:</b></p><ul><li><b>Security and GRC succeed when they communicate clearly to humans, not when they simply present more technical detail.</b></li><li><b>The best GRC teams act as guides that help the business make reasonable, compliant, cyber-conscious decisions.</b></li><li><b>Metrics only matter when they drive a clear outcome or decision, not when they exist for their own sake.</b></li><li><b>Strong GRC teams build trust by doing the hard, cross-functional work that others often avoid.</b></li><li><b>Storytelling is a core security skill because people act on messages they understand, remember, and relate to.</b></li></ul><p><b>What You’ll Learn:</b></p><ul><li><b>Why Steven believes security is ultimately a human communication problem.</b></li><li><b>How to tailor security messaging for engineering leaders, CISOs, and business stakeholders.</b></li><li><b>What “guardrails not gates” looks like in a practical GRC program.</b></li><li><b>How to think about data, metrics, and reporting without overwhelming your audience.</b></li><li><b>Why AI may change the consumption layer of GRC, but not eliminate the human need for storytelling.</b></li></ul><p><br/></p><p><b>This podcast is brought to you by </b><a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a><b> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:</b><a href='https://www.compliancecow.com/'><b> https://www.compliancecow.com</b></a></p><p><b>Watch more episodes:</b><a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'><b> https://www.compliancecow.com/podcast</b></a></p><p><b>Connect With Our Guest:<br/>Steven Asifo | Director of Security &amp; GRC | Yahoo<br/>Connect on LinkedIn: </b><a href='https://www.linkedin.com/in/asifosays/'><b>https://www.linkedin.com/in/asifosays/</b></a></p><p><b>Rate, review, and share if you enjoyed the show!</b></p><p><b>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: </b><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'><b>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</b></a></p><p><b><br/>Apple Podcasts: </b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</b></a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18900553-security-is-a-human-problem-not-a-tool-problem-ft-steven-asifo-director-of-security-grc-yahoo.mp3" length="43231437" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18900553</guid>
    <pubDate>Tue, 24 Mar 2026 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18900553/transcript" type="text/html" />
    <itunes:duration>3599</itunes:duration>
    <itunes:keywords>security communication in GRC, GRC, cybersecurity, Steven Asifo, risk management, compliance, governance, storytelling, security leadership, stand-up comedy, guardrails not gates, AI in GRC, Yahoo</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The 3 Year GRC Reckoning: Customer Trust, Real-Time Assurance, and the Future of Risk ft Bryan Culp, Senior Director of Customer Trust @ Box</itunes:title>
    <title>The 3 Year GRC Reckoning: Customer Trust, Real-Time Assurance, and the Future of Risk ft Bryan Culp, Senior Director of Customer Trust @ Box</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Bryan Culp, Senior Director of Customer Trust at Box, to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust. Bryan shares why the next two to three years will fundamentally change how GRC operates — driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business languag...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Security &amp; GRC Decoded, <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/bryanculp/'><b>Bryan Culp</b></a>, Senior Director of Customer Trust at <a href='https://www.box.com/home'><b>Box</b></a>, to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust.</p><p>Bryan shares why the next two to three years will fundamentally change how GRC operates — driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business language.</p><p>From managing both customer trust and third-party risk at Box, Bryan offers a rare dual perspective: how companies present assurance to customers while simultaneously evaluating vendors themselves. This conversation challenges the idea that certifications alone create security and makes the case for risk being the true language of leadership.</p><p><br/></p><p><b>Key Takeaways</b>:</p><ul><li>Customer Trust is not traditional GRC — it translates security and compliance work into business confidence for customers.</li><li>Certifications enable market access, but they do not eliminate breach risk.</li><li>Risk must be communicated in executive language to influence real business decisions.</li><li>Large financial institutions are beginning to demand real-time internal security metrics instead of snapshot audits.</li><li>AI is transforming GRC workflows — not to cut people, but to enable deeper, higher-value analysis.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why Bryan believes GRC will look materially different in the next 2–3 years.</li><li>How Customer Trust functions differently from compliance and audit teams.</li><li>Why certifications alone cannot prevent major security incidents.</li><li>What “real-time assurance” could look like for large SaaS companies.</li><li>How to think about AI and automation as long-term growth enablers in GRC.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Bryan Culp | Senior Director of Customer Trust | <a href='https://www.box.com/home'>Box</a><br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/bryanculp/'>https://www.linkedin.com/in/bryanculp/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p>Apple Podcasts: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Security &amp; GRC Decoded, <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/bryanculp/'><b>Bryan Culp</b></a>, Senior Director of Customer Trust at <a href='https://www.box.com/home'><b>Box</b></a>, to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust.</p><p>Bryan shares why the next two to three years will fundamentally change how GRC operates — driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business language.</p><p>From managing both customer trust and third-party risk at Box, Bryan offers a rare dual perspective: how companies present assurance to customers while simultaneously evaluating vendors themselves. This conversation challenges the idea that certifications alone create security and makes the case for risk being the true language of leadership.</p><p><br/></p><p><b>Key Takeaways</b>:</p><ul><li>Customer Trust is not traditional GRC — it translates security and compliance work into business confidence for customers.</li><li>Certifications enable market access, but they do not eliminate breach risk.</li><li>Risk must be communicated in executive language to influence real business decisions.</li><li>Large financial institutions are beginning to demand real-time internal security metrics instead of snapshot audits.</li><li>AI is transforming GRC workflows — not to cut people, but to enable deeper, higher-value analysis.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why Bryan believes GRC will look materially different in the next 2–3 years.</li><li>How Customer Trust functions differently from compliance and audit teams.</li><li>Why certifications alone cannot prevent major security incidents.</li><li>What “real-time assurance” could look like for large SaaS companies.</li><li>How to think about AI and automation as long-term growth enablers in GRC.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Bryan Culp | Senior Director of Customer Trust | <a href='https://www.box.com/home'>Box</a><br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/bryanculp/'>https://www.linkedin.com/in/bryanculp/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p>Apple Podcasts: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18819426-the-3-year-grc-reckoning-customer-trust-real-time-assurance-and-the-future-of-risk-ft-bryan-culp-senior-director-of-customer-trust-box.mp3" length="47869612" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18819426</guid>
    <pubDate>Tue, 10 Mar 2026 11:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18819426/transcript" type="text/html" />
    <itunes:duration>3985</itunes:duration>
    <itunes:keywords>GRC, Customer Trust, Real-Time Assurance, Security, Risk Management, Compliance, Box, Bryan Culp, AI, Automation, Third-Party Risk, SOC 2, Security Leadership</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>When GRC Stops Watching and Starts Working ft Ryan Schoeller, Director of Security &amp; GRC @ Treasure Data</itunes:title>
    <title>When GRC Stops Watching and Starts Working ft Ryan Schoeller, Director of Security &amp; GRC @ Treasure Data</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Ryan Schoeller, Director of Security &amp; GRC at Treasure Data, to challenge one of the most deeply rooted assumptions in the industry: that GRC should stay passive and “independent.” Drawing from his experience across startups, mid-market tech companies, and large enterprises, Ryan argues that the most effective GRC teams are the ones that actively participate in control monitoring, risk management, and operatio...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/ryanschoeller/'>Ryan Schoeller</a>, Director of Security &amp; GRC at <a href='https://www.treasuredata.com/?utm_medium=social-organic&amp;utm_source=security_grc_decoded'>Treasure Data</a>, to challenge one of the most deeply rooted assumptions in the industry: that GRC should stay passive and “independent.” Drawing from his experience across startups, mid-market tech companies, and large enterprises, Ryan argues that the most effective GRC teams are the ones that actively participate in control monitoring, risk management, and operational decision-making. This conversation goes beyond audits and checklists, exploring how GRC can truly drive business value by protecting revenue, enabling growth, and embedding risk thinking into everyday operations.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC delivers the most value when it actively participates in monitoring controls, not just validating them after the fact.</li><li>Risk is the most critical — and most neglected — pillar of GRC, often confused with gaps or vulnerabilities.</li><li>Strong relationships with engineering and business teams are essential for GRC to gain meaningful access to data.</li><li>GRC engineering is not just about writing code; it’s about applying an engineering mindset to workflows, tooling, and processes.</li><li>Automation alone is not a business case — value comes from how freed-up time is reinvested.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why the “three lines of defense” model often breaks down in real organizations</li><li>How GRC teams can reduce compliance theater by becoming more operational</li><li>The difference between a vulnerability, a gap, and an actual risk</li><li>How to build a business case for GRC automation that leadership will support</li><li>Why front-ending GRC work (sales assurance, customer trust) often matters more than backend audit prep</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Ryan Schoeller | Director of Security &amp; GRC | Treasure Data<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/ryanschoeller/'>https://www.linkedin.com/in/ryanschoeller/</a></p><p><b>Rate, review, and share if you enjoyed the show!</b></p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/ryanschoeller/'>Ryan Schoeller</a>, Director of Security &amp; GRC at <a href='https://www.treasuredata.com/?utm_medium=social-organic&amp;utm_source=security_grc_decoded'>Treasure Data</a>, to challenge one of the most deeply rooted assumptions in the industry: that GRC should stay passive and “independent.” Drawing from his experience across startups, mid-market tech companies, and large enterprises, Ryan argues that the most effective GRC teams are the ones that actively participate in control monitoring, risk management, and operational decision-making. This conversation goes beyond audits and checklists, exploring how GRC can truly drive business value by protecting revenue, enabling growth, and embedding risk thinking into everyday operations.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC delivers the most value when it actively participates in monitoring controls, not just validating them after the fact.</li><li>Risk is the most critical — and most neglected — pillar of GRC, often confused with gaps or vulnerabilities.</li><li>Strong relationships with engineering and business teams are essential for GRC to gain meaningful access to data.</li><li>GRC engineering is not just about writing code; it’s about applying an engineering mindset to workflows, tooling, and processes.</li><li>Automation alone is not a business case — value comes from how freed-up time is reinvested.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why the “three lines of defense” model often breaks down in real organizations</li><li>How GRC teams can reduce compliance theater by becoming more operational</li><li>The difference between a vulnerability, a gap, and an actual risk</li><li>How to build a business case for GRC automation that leadership will support</li><li>Why front-ending GRC work (sales assurance, customer trust) often matters more than backend audit prep</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Ryan Schoeller | Director of Security &amp; GRC | Treasure Data<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/ryanschoeller/'>https://www.linkedin.com/in/ryanschoeller/</a></p><p><b>Rate, review, and share if you enjoyed the show!</b></p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18720212-when-grc-stops-watching-and-starts-working-ft-ryan-schoeller-director-of-security-grc-treasure-data.mp3" length="41232139" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18720212</guid>
    <pubDate>Tue, 24 Feb 2026 11:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18720212/transcript" type="text/html" />
    <itunes:duration>3432</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Does GRC Belongs Outside Security? The Case for an Independent Second Line ft Charles Nwatu - GRC Engineering Leader</itunes:title>
    <title>Does GRC Belongs Outside Security? The Case for an Independent Second Line ft Charles Nwatu - GRC Engineering Leader</title>
    <itunes:summary><![CDATA[What if GRC shouldn’t sit inside Security at all—and what if the bigger problem isn’t automation, but what you do after you automate? In this episode, Raj Krishnamurthy sits down with Charles Nwatu (former Security GRC Engineering &amp; Assurance leader at Netflix) for a candid, systems-level conversation about why “annual audit rituals” fail modern engineering, how GRC can produce high-fidelity signals that strengthen security decision-making, and why the next wave of GRC engineering is abou...]]></itunes:summary>
    <description><![CDATA[<p>What if <b>GRC shouldn’t sit inside Security at all</b>—and what if the bigger problem isn’t automation, but what you do <em>after</em> you automate? In this episode, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/cnwatu/'>Charles Nwatu</a> (former Security GRC Engineering &amp; Assurance leader at Netflix) for a candid, systems-level conversation about why “annual audit rituals” fail modern engineering, how <b>GRC can produce high-fidelity signals that strengthen security decision-making</b>, and why the next wave of GRC engineering is about <b>analytics, specifications, and business impact</b>—not just speeding up evidence collection.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC is a continuous discipline—point-in-time compliance can help, but it can’t be the end state.</li><li>Automation is necessary but not sufficient: the real value is in turning collected evidence into actionable insights.</li><li>Specifications enable measurement—without clear expected behaviors, security metrics become inconsistent and hard to compare.</li><li>GRC can feed security with high-fidelity signals (like identity/access review metadata) that improve posture beyond audit readiness.</li><li>Third-party risk doesn’t “finish”—the goal is visibility, data lineage awareness, and making the mess less messy. <br/><br/></li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Where Charles believes GRC should sit org-wise—and why Security should be a “customer” of GRC</li><li>What “shift-left GRC” looks like in practice (beyond annual audits)</li><li>Why “efficiency savings” don’t automatically equal “security value”</li><li>How to think about metrics, specifications, and risk in a shared language</li><li>Why third-party risk management is “unsolvable,” and how to build guardrails anyway</li></ul><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. <br/><br/><b>Learn more</b>:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Charles Nwatu | GRC Engineering Leader<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/cnwatu/'>https://www.linkedin.com/in/cnwatu/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>What if <b>GRC shouldn’t sit inside Security at all</b>—and what if the bigger problem isn’t automation, but what you do <em>after</em> you automate? In this episode, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'>Raj Krishnamurthy</a> sits down with <a href='https://www.linkedin.com/in/cnwatu/'>Charles Nwatu</a> (former Security GRC Engineering &amp; Assurance leader at Netflix) for a candid, systems-level conversation about why “annual audit rituals” fail modern engineering, how <b>GRC can produce high-fidelity signals that strengthen security decision-making</b>, and why the next wave of GRC engineering is about <b>analytics, specifications, and business impact</b>—not just speeding up evidence collection.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC is a continuous discipline—point-in-time compliance can help, but it can’t be the end state.</li><li>Automation is necessary but not sufficient: the real value is in turning collected evidence into actionable insights.</li><li>Specifications enable measurement—without clear expected behaviors, security metrics become inconsistent and hard to compare.</li><li>GRC can feed security with high-fidelity signals (like identity/access review metadata) that improve posture beyond audit readiness.</li><li>Third-party risk doesn’t “finish”—the goal is visibility, data lineage awareness, and making the mess less messy. <br/><br/></li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Where Charles believes GRC should sit org-wise—and why Security should be a “customer” of GRC</li><li>What “shift-left GRC” looks like in practice (beyond annual audits)</li><li>Why “efficiency savings” don’t automatically equal “security value”</li><li>How to think about metrics, specifications, and risk in a shared language</li><li>Why third-party risk management is “unsolvable,” and how to build guardrails anyway</li></ul><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. <br/><br/><b>Learn more</b>:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Charles Nwatu | GRC Engineering Leader<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/cnwatu/'>https://www.linkedin.com/in/cnwatu/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18645514-does-grc-belongs-outside-security-the-case-for-an-independent-second-line-ft-charles-nwatu-grc-engineering-leader.mp3" length="43955901" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast?utm_source=podcast</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18645514</guid>
    <pubDate>Tue, 10 Feb 2026 11:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18645514/transcript" type="text/html" />
    <itunes:duration>3659</itunes:duration>
    <itunes:keywords>GRC engineering, GRC engineering leader, security decisions, risk management, security metrics, compliance automation, evidence collection, annual audit, continuous assurance, Netflix GRC, shift-left GRC, security value, specifications, data lineage, Char</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>GRC Is an Engineering Discipline. Not a Checklist. ft Akhila Chitiprolu, Head of Security &amp; GRC @ Sierra</itunes:title>
    <title>GRC Is an Engineering Discipline. Not a Checklist. ft Akhila Chitiprolu, Head of Security &amp; GRC @ Sierra</title>
    <itunes:summary><![CDATA[GRC has long been seen as abstract, manual, and disconnected from how modern engineering teams actually work, but that narrative is breaking down. In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Akhila Chitiprolu, Head of Security &amp; GRC at Sierra, to explore why GRC must be treated as an engineering discipline, not a compliance afterthought. Drawing from her experience across T-Mobile, Expedia, Stripe, and AI-native companies, Akhila explains how systems th...]]></itunes:summary>
    <description><![CDATA[<p>GRC has long been seen as abstract, manual, and disconnected from how modern engineering teams actually work, but that narrative is breaking down. In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/akhilachitiprolu/'><b>Akhila Chitiprolu</b></a>, Head of Security &amp; GRC at Sierra, to explore why GRC must be treated as an engineering discipline, not a compliance afterthought. Drawing from her experience across T-Mobile, Expedia, Stripe, and AI-native companies, Akhila explains how systems thinking, automation, and shared ownership can radically reduce compliance toil while increasing trust. This conversation goes deep into GRC engineering, audit realities, automation tradeoffs, and what the future of compliance looks like in an AI-driven world.<br/><br/><b>Key Takeaways</b>:</p><ul><li>GRC works best when treated as a system with inputs, processes, outputs, and feedback loops </li><li>Automation should focus on intent and outcomes, not blindly speeding up broken manual processes</li><li>GRC professionals act as a middleware layer between engineers, auditors, and customers</li><li>Not all controls should be automated — but 70% can be, with humans in the loop where it matters</li><li>The future of GRC depends on engineering mindset, context, and trust, not checklists </li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why GRC is fundamentally a systems engineering problem</li><li>How to reduce engineering toil without weakening audit posture</li><li>When automation helps — and when it creates false efficiency</li><li>How GRC teams should approach AI, agents, and non-deterministic systems</li><li>Practical ways to build a GRC engineering function over time</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><a href='https://www.linkedin.com/in/akhilachitiprolu/'>Akhila Chitiprolu</a> | Head of Security &amp; GRC | <a href='https://sierra.ai/'>Sierra</a><br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/akhilachitiprolu/'>https://www.linkedin.com/in/akhilachitiprolu/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>GRC has long been seen as abstract, manual, and disconnected from how modern engineering teams actually work, but that narrative is breaking down. In this episode of <b>Security &amp; GRC Decoded</b>, <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/akhilachitiprolu/'><b>Akhila Chitiprolu</b></a>, Head of Security &amp; GRC at Sierra, to explore why GRC must be treated as an engineering discipline, not a compliance afterthought. Drawing from her experience across T-Mobile, Expedia, Stripe, and AI-native companies, Akhila explains how systems thinking, automation, and shared ownership can radically reduce compliance toil while increasing trust. This conversation goes deep into GRC engineering, audit realities, automation tradeoffs, and what the future of compliance looks like in an AI-driven world.<br/><br/><b>Key Takeaways</b>:</p><ul><li>GRC works best when treated as a system with inputs, processes, outputs, and feedback loops </li><li>Automation should focus on intent and outcomes, not blindly speeding up broken manual processes</li><li>GRC professionals act as a middleware layer between engineers, auditors, and customers</li><li>Not all controls should be automated — but 70% can be, with humans in the loop where it matters</li><li>The future of GRC depends on engineering mindset, context, and trust, not checklists </li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why GRC is fundamentally a systems engineering problem</li><li>How to reduce engineering toil without weakening audit posture</li><li>When automation helps — and when it creates false efficiency</li><li>How GRC teams should approach AI, agents, and non-deterministic systems</li><li>Practical ways to build a GRC engineering function over time</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><a href='https://www.linkedin.com/in/akhilachitiprolu/'>Akhila Chitiprolu</a> | Head of Security &amp; GRC | <a href='https://sierra.ai/'>Sierra</a><br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/akhilachitiprolu/'>https://www.linkedin.com/in/akhilachitiprolu/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18573836-grc-is-an-engineering-discipline-not-a-checklist-ft-akhila-chitiprolu-head-of-security-grc-sierra.mp3" length="39389882" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18573836</guid>
    <pubDate>Tue, 27 Jan 2026 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18573836/transcript" type="text/html" />
    <itunes:duration>3279</itunes:duration>
    <itunes:keywords>GRC, GRC engineering, Compliance automation, Security, Risk management, Audit, Systems thinking, Akhila Chitiprolu, Sierra, Compliance toil, AI in GRC, Security GRC Decoded, Podcast</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>GRC as a Growth Engine: From Checklists to Continuous Assurance ft Vivek Madan - Director of Security, Risk, and Compliance @ Fortinet</itunes:title>
    <title>GRC as a Growth Engine: From Checklists to Continuous Assurance ft Vivek Madan - Director of Security, Risk, and Compliance @ Fortinet</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Vivek Madan to unpack what it really means to run a modern GRC program inside a global cybersecurity company. Drawing from his journey across networking, security engineering, risk, and compliance, Vivek shares how GRC can function as a true business enabler—opening markets, accelerating revenue, and strengthening trust. This conversation stands out for its practical frameworks, real-world stories, and honest disc...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, <b>Raj Krishnamurthy</b> sits down with <b>Vivek Madan</b> to unpack what it really means to run a modern GRC program inside a global cybersecurity company. Drawing from his journey across networking, security engineering, risk, and compliance, Vivek shares how GRC can function as a true business enabler—opening markets, accelerating revenue, and strengthening trust. This conversation stands out for its practical frameworks, real-world stories, and honest discussion about friction between engineering, security, auditors, and compliance teams, giving listeners a grounded view of how GRC works when it’s done right.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC works best when it is positioned as a growth enabler that unlocks new markets, not just a compliance checkbox.</li><li>Strong governance establishes foundational rules that allow security and risk decisions to scale consistently across the business.</li><li>Storytelling is a critical GRC skill—people align with compliance when they understand the “why,” not just the requirement.</li><li>Common controls frameworks reduce complexity when designed intentionally across global, application-specific, and product-specific needs.</li><li>Automation matters, but process automation is just as important as technical automation to reduce compliance friction.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>How GRC enables business expansion into regulated and global markets</li><li>Why compliance resistance exists—and how to overcome it</li><li>A practical 50–35–15 model for common controls frameworks</li><li>How to balance continuous assurance with annual audits</li><li>What modern GRC leaders look for when hiring talent</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><b>Vivek Madan</b> | Director of Security, Risk, and Compliance | <b>Fortinet</b><br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/vivek-madan-cissp-ccsp/'>https://www.linkedin.com/in/vivek-madan-cissp-ccsp/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>:<a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, <b>Raj Krishnamurthy</b> sits down with <b>Vivek Madan</b> to unpack what it really means to run a modern GRC program inside a global cybersecurity company. Drawing from his journey across networking, security engineering, risk, and compliance, Vivek shares how GRC can function as a true business enabler—opening markets, accelerating revenue, and strengthening trust. This conversation stands out for its practical frameworks, real-world stories, and honest discussion about friction between engineering, security, auditors, and compliance teams, giving listeners a grounded view of how GRC works when it’s done right.</p><p><b>Key Takeaways</b>:</p><ul><li>GRC works best when it is positioned as a growth enabler that unlocks new markets, not just a compliance checkbox.</li><li>Strong governance establishes foundational rules that allow security and risk decisions to scale consistently across the business.</li><li>Storytelling is a critical GRC skill—people align with compliance when they understand the “why,” not just the requirement.</li><li>Common controls frameworks reduce complexity when designed intentionally across global, application-specific, and product-specific needs.</li><li>Automation matters, but process automation is just as important as technical automation to reduce compliance friction.</li></ul><p><b>What You’ll Learn</b>:</p><ul><li>How GRC enables business expansion into regulated and global markets</li><li>Why compliance resistance exists—and how to overcome it</li><li>A practical 50–35–15 model for common controls frameworks</li><li>How to balance continuous assurance with annual audits</li><li>What modern GRC leaders look for when hiring talent</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><b>Vivek Madan</b> | Director of Security, Risk, and Compliance | <b>Fortinet</b><br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/vivek-madan-cissp-ccsp/'>https://www.linkedin.com/in/vivek-madan-cissp-ccsp/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>:<a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18497407-grc-as-a-growth-engine-from-checklists-to-continuous-assurance-ft-vivek-madan-director-of-security-risk-and-compliance-fortinet.mp3" length="39966099" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18497407</guid>
    <pubDate>Tue, 13 Jan 2026 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18497407/transcript" type="text/html" />
    <itunes:duration>3327</itunes:duration>
    <itunes:keywords>GRC, Vivek Madan, Raj Krishnamurthy, Fortinet, Governance Risk and Compliance, Business Enablement, Cybersecurity, Common Controls Framework, Risk Management, ComplianceCow, Continuous Assurance, Security GRC, GRC, Compliance</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Audit ≠ Security: Building Auditable Controls in a High-Velocity World ft Varun Prasad, Cloud Security &amp; Privacy Assurance @ BDO</itunes:title>
    <title>Audit ≠ Security: Building Auditable Controls in a High-Velocity World ft Varun Prasad, Cloud Security &amp; Privacy Assurance @ BDO</title>
    <itunes:summary><![CDATA[Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil — but what if that mindset is holding security teams back? In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing lin...]]></itunes:summary>
    <description><![CDATA[<p>Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil — but what if that mindset is holding security teams back? In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing link between fast-moving engineering teams and slow, annual audit cycles — and how organizations can stop treating audits as an afterthought and start using them as a trust-building mechanism.</p><p><b>Key Takeaways</b>:</p><ul><li>Audits are designed to provide reasonable assurance, not eliminate all risk </li><li>The biggest failure in modern GRC is building controls that are automated but not auditable</li><li>Continuous controls monitoring only works if auditors can validate completeness and accuracy</li><li>Screenshots persist because they remain the clearest way to demonstrate system state over time</li><li>Security controls should be built to improve posture first — and explained clearly second<br/><br/></li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why audit skepticism is a feature, not a flaw</li><li>How internal and external audits serve fundamentally different purposes</li><li>Where continuous monitoring breaks down from an auditor’s perspective</li><li>What “auditable controls” actually mean in CI/CD environments</li><li>How AI can assist auditors without replacing human judgment</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Varun Prasad | Cloud Security &amp; Privacy Assurance | BDO<br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/varunprasad/'>https://www.linkedin.com/in/varunprasad/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p><b>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts</b>:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>:</p><p><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil — but what if that mindset is holding security teams back? In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing link between fast-moving engineering teams and slow, annual audit cycles — and how organizations can stop treating audits as an afterthought and start using them as a trust-building mechanism.</p><p><b>Key Takeaways</b>:</p><ul><li>Audits are designed to provide reasonable assurance, not eliminate all risk </li><li>The biggest failure in modern GRC is building controls that are automated but not auditable</li><li>Continuous controls monitoring only works if auditors can validate completeness and accuracy</li><li>Screenshots persist because they remain the clearest way to demonstrate system state over time</li><li>Security controls should be built to improve posture first — and explained clearly second<br/><br/></li></ul><p><b>What You’ll Learn</b>:</p><ul><li>Why audit skepticism is a feature, not a flaw</li><li>How internal and external audits serve fundamentally different purposes</li><li>Where continuous monitoring breaks down from an auditor’s perspective</li><li>What “auditable controls” actually mean in CI/CD environments</li><li>How AI can assist auditors without replacing human judgment</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Varun Prasad | Cloud Security &amp; Privacy Assurance | BDO<br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/varunprasad/'>https://www.linkedin.com/in/varunprasad/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p><b>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts</b>:<br/><br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><b>Apple Podcasts</b>:</p><p><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18432256-audit-security-building-auditable-controls-in-a-high-velocity-world-ft-varun-prasad-cloud-security-privacy-assurance-bdo.mp3" length="42726185" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18432256</guid>
    <pubDate>Tue, 30 Dec 2025 12:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18432256/transcript" type="text/html" />
    <itunes:duration>3557</itunes:duration>
    <itunes:keywords>Security and GRC Decoded, Raj Krishnamurthy, Varun Prasad, BDO, GRC, Audit Assurance, Auditable Controls, Cloud Security, Cybersecurity, DevOps, Compliance, Governance Risk and Compliance, Security GRC Podcast, Compliance Cow</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Scaling GRC Without the Chaos: How to Build Programs That Don’t Break ft Tom Scuderi, Senior Manager of Security &amp; GRC @ LTK</itunes:title>
    <title>Scaling GRC Without the Chaos: How to Build Programs That Don’t Break ft Tom Scuderi, Senior Manager of Security &amp; GRC @ LTK</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy sits down with Tom Scuderi, Senior Manager of Security &amp; GRC at LTK and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why cur...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/tom-scuderi/'><b>Tom Scuderi</b></a>, <b>Senior Manager</b> of <b>Security &amp; GRC</b> at <a href='https://company.shopltk.com/en/company'><b>LTK</b></a> and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen—not dilute—your security program, and how to anchor leadership decisions with meaningful risk data.</p><p><b>Key Takeaways</b></p><ul><li>GRC only scales when its processes mirror how engineering teams already work.</li><li>SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise.</li><li>Curated visibility reduces friction and improves cross-functional trust.</li><li>Clarity in ownership is the backbone of a scalable GRC function.</li><li>Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How Tom built and matured GRC programs across four different companies.</li><li>Why engineering alignment is essential for sustainable compliance.</li><li>How curated visibility replaces access sprawl and accelerates audits.</li><li>The difference between risk-driven and compliance-driven GRC.</li><li>Why automation only works when underlying processes are mature.</li><li>How to structure ownership to reduce bottlenecks during SOC 2 and similar frameworks.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. <b>Automate evidence collection</b>, <b>eliminate screenshots</b>, and <b>scale your program with confidence</b>. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><b>Tom Scuderi</b> | Senior Manager of Security &amp; GRC | LTK<br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/tom-scuderi/'>https://www.linkedin.com/in/tom-scuderi/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: </p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>:</p><p><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p><p>#SecurityAndGRCDecoded #RajKrishnamurthy #TomScuderi #LTK #GRC #ScalingGRC #SOC2 #EngineeringAlignment #RiskManagement #SecurityLeadership #Compliance #GovernanceRiskCompliance #SecurityGRCPodcast #ComplianceCow</p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/tom-scuderi/'><b>Tom Scuderi</b></a>, <b>Senior Manager</b> of <b>Security &amp; GRC</b> at <a href='https://company.shopltk.com/en/company'><b>LTK</b></a> and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen—not dilute—your security program, and how to anchor leadership decisions with meaningful risk data.</p><p><b>Key Takeaways</b></p><ul><li>GRC only scales when its processes mirror how engineering teams already work.</li><li>SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise.</li><li>Curated visibility reduces friction and improves cross-functional trust.</li><li>Clarity in ownership is the backbone of a scalable GRC function.</li><li>Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How Tom built and matured GRC programs across four different companies.</li><li>Why engineering alignment is essential for sustainable compliance.</li><li>How curated visibility replaces access sprawl and accelerates audits.</li><li>The difference between risk-driven and compliance-driven GRC.</li><li>Why automation only works when underlying processes are mature.</li><li>How to structure ownership to reduce bottlenecks during SOC 2 and similar frameworks.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a> — the smarter way to manage compliance. <b>Automate evidence collection</b>, <b>eliminate screenshots</b>, and <b>scale your program with confidence</b>. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/><b>Tom Scuderi</b> | Senior Manager of Security &amp; GRC | LTK<br/><b>Connect on LinkedIn</b>: <a href='https://www.linkedin.com/in/tom-scuderi/'>https://www.linkedin.com/in/tom-scuderi/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to <b>Security &amp; GRC Decoded</b> wherever you get your podcasts:<br/><br/><b>Spotify</b>: </p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683</a></p><p><br/><b>Apple Podcasts</b>:</p><p><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p><p>#SecurityAndGRCDecoded #RajKrishnamurthy #TomScuderi #LTK #GRC #ScalingGRC #SOC2 #EngineeringAlignment #RiskManagement #SecurityLeadership #Compliance #GovernanceRiskCompliance #SecurityGRCPodcast #ComplianceCow</p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18346461-scaling-grc-without-the-chaos-how-to-build-programs-that-don-t-break-ft-tom-scuderi-senior-manager-of-security-grc-ltk.mp3" length="40661981" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18346461</guid>
    <pubDate>Tue, 16 Dec 2025 11:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18346461/transcript" type="text/html" />
    <itunes:duration>3385</itunes:duration>
    <itunes:keywords>Security And GRC Decoded, Raj Krishnamurthy, Tom Scuderi, LTK, GRC, Scaling GRC, SOC 2, Engineering Alignment, Risk Management, Security Leadership, Compliance, Governance Risk Compliance, ComplianceCow, Audit Readiness, Access Reviews, Process Maturity, </itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>25</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Controls Are Promises: Rethinking GRC for Modern Security ft Sergio Alonso @ Rapid7</itunes:title>
    <title>Controls Are Promises: Rethinking GRC for Modern Security ft Sergio Alonso @ Rapid7</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy sits down with Sergio Alonso, a seasoned GRC and information security leader at Rapid7, whose 17–year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/salonsor/'><b>Sergio Alonso</b></a>, a seasoned GRC and information security leader at <a href='https://www.rapid7.com/'><b>Rapid7</b></a>, whose 17–year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls should be treated as “promises” that teams must honor every day. This conversation explores scaling GRC in high-velocity environments, reducing compliance fatigue, applying zero-knowledge principles to trust, and building the next generation of context-driven risk programs.<br/><br/><br/></p><p>Key Takeaways</p><ul><li>Automation is the only sustainable path to scaling GRC without increasing friction.</li><li>Controls should be viewed as “promises,” and audits as the consequence of keeping or breaking them.</li><li>Context — technical, business, and risk — is the primary driver of effective triage and prioritization.</li><li>GRC must evolve from a legacy function into a trust-driven, engineering-aligned discipline.</li><li>Zero-knowledge-style thinking may define the future of transparency and customer trust.</li></ul><p>What You’ll Learn</p><ul><li>How to adapt legacy compliance experience for cloud, SaaS, and fast-moving tech companies.</li><li>Why automation, evidence APIs, and GRC engineering are becoming non-negotiable.</li><li>How to reduce compliance fatigue using “meet once, meet many” principles.</li><li>Why context is the key to reducing noise from security tools.</li><li>How to partner with engineers using empathy, clarity, and strong framing.</li><li>Why trust and transparency are reshaping GRC inside cybersecurity companies.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p>Watch more episodes:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p>Connect With Our Guest:<br/>Sergio Alonso | GRC &amp; Information Security Leader | Rapid7<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/salonsor/'>https://www.linkedin.com/in/salonsor/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify:<a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'> https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL<br/><br/></a>Apple Podcasts:<a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634'> https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/salonsor/'><b>Sergio Alonso</b></a>, a seasoned GRC and information security leader at <a href='https://www.rapid7.com/'><b>Rapid7</b></a>, whose 17–year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls should be treated as “promises” that teams must honor every day. This conversation explores scaling GRC in high-velocity environments, reducing compliance fatigue, applying zero-knowledge principles to trust, and building the next generation of context-driven risk programs.<br/><br/><br/></p><p>Key Takeaways</p><ul><li>Automation is the only sustainable path to scaling GRC without increasing friction.</li><li>Controls should be viewed as “promises,” and audits as the consequence of keeping or breaking them.</li><li>Context — technical, business, and risk — is the primary driver of effective triage and prioritization.</li><li>GRC must evolve from a legacy function into a trust-driven, engineering-aligned discipline.</li><li>Zero-knowledge-style thinking may define the future of transparency and customer trust.</li></ul><p>What You’ll Learn</p><ul><li>How to adapt legacy compliance experience for cloud, SaaS, and fast-moving tech companies.</li><li>Why automation, evidence APIs, and GRC engineering are becoming non-negotiable.</li><li>How to reduce compliance fatigue using “meet once, meet many” principles.</li><li>Why context is the key to reducing noise from security tools.</li><li>How to partner with engineers using empathy, clarity, and strong framing.</li><li>Why trust and transparency are reshaping GRC inside cybersecurity companies.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'>ComplianceCow</a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more:<a href='https://www.compliancecow.com/'> https://www.compliancecow.com</a></p><p>Watch more episodes:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p>Connect With Our Guest:<br/>Sergio Alonso | GRC &amp; Information Security Leader | Rapid7<br/>Connect on LinkedIn: <a href='https://www.linkedin.com/in/salonsor/'>https://www.linkedin.com/in/salonsor/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><br/>Spotify:<a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'> https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL<br/><br/></a>Apple Podcasts:<a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634'> https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18259384-controls-are-promises-rethinking-grc-for-modern-security-ft-sergio-alonso-rapid7.mp3" length="40493879" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18259384</guid>
    <pubDate>Tue, 02 Dec 2025 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18259384/transcript" type="text/html" />
    <itunes:duration>3371</itunes:duration>
    <itunes:keywords>SecurityAndGRCDecoded, Raj Krishnamurthy, Sergio Alonso, Rapid7, Rapid7 Automation, Zero Knowledge, Zero-Knowledge Security, Automation, Zero Knowledge Automation, Risk Management, Risk Management Automation, Risk Monitoring, Cybersecurity, Cybersecurity </itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>24</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime</itunes:title>
    <title>How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy sits down with Mukund Sarma, Deputy CISO and Head of Product Security at Chime, to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/sarmamukund/'><b>Mukund Sarma</b></a>, Deputy CISO and Head of Product Security at <a href='https://www.chime.com/'><b>Chime</b></a>, to explore what happens when governance, risk, and compliance teams work <em>with</em> engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity.</p><p><b><br/>5 Key Takeaways</b></p><ul><li>GRC isn’t a blocker—it’s a mirror that keeps security honest and accountable.</li><li>Strong security engineering automatically strengthens compliance outcomes.</li><li>Friction between security and engineering fades when empathy drives collaboration.</li><li>“Shift left” works best when paved paths and automation support developers.</li><li>Practical controls and continuous validation create sustainable, scalable governance.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How to bridge silos between security, GRC, and engineering teams.</li><li>Why automation and continuous control monitoring are the future of compliance.</li><li>What “practical controls” really mean in modern DevSecOps environments.</li><li>How empathy and communication transform security culture.</li><li>Why compliance should <em>follow</em> great security engineering, not lead it.</li><li>Real-world examples from Chime’s approach to product security.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a> — the smarter way to manage compliance. <b>Automate evidence collection</b>, <b>eliminate screenshots</b>, and <b>scale your program with confidence</b>. Learn more:<a href='https://www.compliancecow.com'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Mukund Sarma | Deputy CISO and Head of Product Security | <a href='https://www.chime.com/'>Chime</a><br/> Connect on LinkedIn: <a href='https://www.linkedin.com/in/tristaningold/'>https://www.linkedin.com/in/sarmamukund/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr<br/></a><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569</a></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <b><em>Security &amp; GRC Decoded</em></b>, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> sits down with <a href='https://www.linkedin.com/in/sarmamukund/'><b>Mukund Sarma</b></a>, Deputy CISO and Head of Product Security at <a href='https://www.chime.com/'><b>Chime</b></a>, to explore what happens when governance, risk, and compliance teams work <em>with</em> engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity.</p><p><b><br/>5 Key Takeaways</b></p><ul><li>GRC isn’t a blocker—it’s a mirror that keeps security honest and accountable.</li><li>Strong security engineering automatically strengthens compliance outcomes.</li><li>Friction between security and engineering fades when empathy drives collaboration.</li><li>“Shift left” works best when paved paths and automation support developers.</li><li>Practical controls and continuous validation create sustainable, scalable governance.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How to bridge silos between security, GRC, and engineering teams.</li><li>Why automation and continuous control monitoring are the future of compliance.</li><li>What “practical controls” really mean in modern DevSecOps environments.</li><li>How empathy and communication transform security culture.</li><li>Why compliance should <em>follow</em> great security engineering, not lead it.</li><li>Real-world examples from Chime’s approach to product security.</li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a> — the smarter way to manage compliance. <b>Automate evidence collection</b>, <b>eliminate screenshots</b>, and <b>scale your program with confidence</b>. Learn more:<a href='https://www.compliancecow.com'> https://www.compliancecow.com</a></p><p><b>Watch more episodes</b>:<a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'> https://www.compliancecow.com/podcast</a></p><p><b>Connect With Our Guest</b>:<br/>Mukund Sarma | Deputy CISO and Head of Product Security | <a href='https://www.chime.com/'>Chime</a><br/> Connect on LinkedIn: <a href='https://www.linkedin.com/in/tristaningold/'>https://www.linkedin.com/in/sarmamukund/</a></p><p>Rate, review, and share if you enjoyed the show!</p><p>Subscribe to Security &amp; GRC Decoded wherever you get your podcasts:<br/><b>Spotify</b>: <a href='https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL'>https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr<br/></a><b>Apple Podcasts</b>: <a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634'>https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569</a></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18174016-how-pragmatic-controls-build-trust-between-grc-security-and-engineering-ft-mukund-sarma-deputy-ciso-chime.mp3" length="40902070" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18174016</guid>
    <pubDate>Thu, 13 Nov 2025 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18174016/transcript" type="text/html" />
    <itunes:duration>3405</itunes:duration>
    <itunes:keywords>Security &amp; GRC Decoded, Raj Krishnamurthy, Mukund Sarma, Mukund Sharma, Chime, Deputy CISO, Product Security, GRC, Governance Risk Compliance, Security Engineering, DevSecOps, Shift Left, Compliance Automation, Continuous Controls Monitoring, Continuous C</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta</itunes:title>
    <title>How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta</title>
    <itunes:summary><![CDATA[How do you build real trust between GRC and engineering? In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...]]></itunes:summary>
    <description><![CDATA[<p><b>How do you build real trust between GRC and engineering?</b> In this episode of Security &amp; GRC Decoded, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> welcomes <a href='https://www.linkedin.com/in/tristaningold/'><b>Tristan Ingold</b></a>, Security GRC Program Manager at <a href='https://www.meta.com/'>Meta</a>. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.</p><p>He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.</p><p><b><br/>5 Key Takeaways</b></p><ul><li><b>Partnership Over Policing: </b>GRC earns influence by modeling partnership behaviors and meeting teams where they are.</li><li><b>Translate Controls to Engineering: </b>Use product language and existing telemetry; design evidence around the way the system actually works.</li><li><b>Make It Observable: </b>Treat GRC like an observability layer -- surface risk signals the business already emits.</li><li><b>Tell the Story, Not the Score: </b>Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.</li><li><b>Define the Right Role: </b>The best GRC teams act as a <em>sparring partner --</em>challenging, supportive, and focused on outcomes.</li></ul><p><b>What You’ll Learn</b></p><ul><li><b>How to rebuild trust with engineering after “audit fatigue”</b></li><li><b>Practical ways to convert control requirements into product language</b></li><li><b>How to design evidence from logs, pipelines, and tickets you already have</b></li><li><b>When to push, when to partner, and how to escalate with credibility</b></li><li><b>Communicating risk trade-offs without killing roadmap velocity</b></li></ul><p><b>Connect With Our Guest</b>:<br/><a href='https://www.linkedin.com/in/tristaningold/'>Tristan Ingold</a> | Security GRC Program Manager | Meta</p><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a> - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.</p><p><a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'><b>Watch more episodes</b></a></p><p><b>Rate, review, and share if you enjoyed the show</b>!</p><p><br/> <b>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b><br/></a><br/></li></ul>]]></description>
    <content:encoded><![CDATA[<p><b>How do you build real trust between GRC and engineering?</b> In this episode of Security &amp; GRC Decoded, host <a href='https://www.linkedin.com/in/rajkrishnamurthy/'><b>Raj Krishnamurthy</b></a> welcomes <a href='https://www.linkedin.com/in/tristaningold/'><b>Tristan Ingold</b></a>, Security GRC Program Manager at <a href='https://www.meta.com/'>Meta</a>. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.</p><p>He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.</p><p><b><br/>5 Key Takeaways</b></p><ul><li><b>Partnership Over Policing: </b>GRC earns influence by modeling partnership behaviors and meeting teams where they are.</li><li><b>Translate Controls to Engineering: </b>Use product language and existing telemetry; design evidence around the way the system actually works.</li><li><b>Make It Observable: </b>Treat GRC like an observability layer -- surface risk signals the business already emits.</li><li><b>Tell the Story, Not the Score: </b>Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.</li><li><b>Define the Right Role: </b>The best GRC teams act as a <em>sparring partner --</em>challenging, supportive, and focused on outcomes.</li></ul><p><b>What You’ll Learn</b></p><ul><li><b>How to rebuild trust with engineering after “audit fatigue”</b></li><li><b>Practical ways to convert control requirements into product language</b></li><li><b>How to design evidence from logs, pipelines, and tickets you already have</b></li><li><b>When to push, when to partner, and how to escalate with credibility</b></li><li><b>Communicating risk trade-offs without killing roadmap velocity</b></li></ul><p><b>Connect With Our Guest</b>:<br/><a href='https://www.linkedin.com/in/tristaningold/'>Tristan Ingold</a> | Security GRC Program Manager | Meta</p><p><br/></p><p>This podcast is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a> - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.</p><p><a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'><b>Watch more episodes</b></a></p><p><b>Rate, review, and share if you enjoyed the show</b>!</p><p><br/> <b>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b><br/></a><br/></li></ul>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18102282-how-to-build-trust-between-grc-and-engineering-ft-tristan-ingold-security-grc-program-manager-at-meta.mp3" length="41309878" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18102282</guid>
    <pubDate>Thu, 30 Oct 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18102282/transcript" type="text/html" />
    <itunes:duration>3439</itunes:duration>
    <itunes:keywords>GRC, engineering collaboration, security culture, compliance automation, trust in security, audit relationships, Meta, Tristan Ingold, Raj Krishnamurthy, Security and GRC Decoded, ComplianceCow, GRC partnership, risk management, security governance, audit</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue</itunes:title>
    <title>Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue</title>
    <itunes:summary><![CDATA[In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions. He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode,<b> Raj Krishnamurthy</b> speaks with <b>Tony Martin-Vegue</b>, seasoned risk practitioner, speaker, and co-chair of the <b>FAIR Institute</b> San Francisco chapter. Tony shares decades of lessons learned from leading <b>cyber risk management</b> at <b>Netflix</b>,<b> Gap</b>, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions.</p><p>He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned.</p><p><b><br/>Key Takeaways<br/></b><br/></p><ol><li><b>CRQ doesn’t require perfection—start with what you have and refine over time.</b></li><li><b>The most effective risk programs focus on directionally correct data, not precision.</b></li><li><b>Good risk scenarios clearly define asset, threat, and effect to avoid misalignment.</b></li><li><b>Generative AI accelerates scenario development, data research, and model creation.</b></li><li><b>CISOs should demand more from risk teams—move beyond “pick a color” heat maps.</b></li></ol><p><b><br/>Topics Covered<br/></b><br/></p><ul><li><b>Cyber risk quantification (CRQ)</b></li><li><b>Monte Carlo simulations and modeling</b></li><li><b>Risk scenario design and measurement</b></li><li><b>GRC and compliance integration</b></li><li><b>Generative AI in risk management</b></li><li><b>Moving from qualitative to quantitative risk</b></li><li><b>Improving risk hygiene and maturity</b></li><li><b>CISO leadership and risk culture<br/></b><br/></li></ul><p><b>What You’ll Learn<br/></b><br/></p><ul><li><b>The difference between qualitative and quantitative risk methods</b></li><li><b>How to conduct your first risk quantification in Excel</b></li><li><b>Why Monte Carlo simulations are simpler than most think</b></li><li><b>How GRC, compliance, and security teams can collaborate effectively</b></li><li><b>The six levers that influence risk magnitude and frequency</b></li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a>:</p><p><b>ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business. </b></p><p><b>Learn more at </b><a href='https://www.compliancecow.com/'><b>ComplianceCow.com</b></a></p><p><br/></p><p>Connect with our guest: <b>Tony Martin-Vegue on </b><a href='https://www.linkedin.com/in/tonymartinvegue'><b>LinkedIn</b></a></p><ul><li><b>Co-Chair, FAIR Institute San Francisco Chapter</b></li><li><b>Former Risk Leader at Netflix and Gap Inc.</b></li><li><b>Author, </b><b><em>From Heat Maps to Histograms</em></b><b> (coming 2026)</b></li></ul><p>Subscribe to<b> </b><b><em>Security &amp; GRC Decoded</em></b><b> </b>on your favorite platform:</p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=0f831f42f49d44aa&amp;nd=1&amp;dlsi=d667d878b7954d7a'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b></a></li><li><b>Explore all episodes: </b><a href='https://www.compliancecow.com/podcast/'><b>ComplianceCow.com/podcast</b></a></li></ul><p><br/></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode,<b> Raj Krishnamurthy</b> speaks with <b>Tony Martin-Vegue</b>, seasoned risk practitioner, speaker, and co-chair of the <b>FAIR Institute</b> San Francisco chapter. Tony shares decades of lessons learned from leading <b>cyber risk management</b> at <b>Netflix</b>,<b> Gap</b>, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions.</p><p>He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned.</p><p><b><br/>Key Takeaways<br/></b><br/></p><ol><li><b>CRQ doesn’t require perfection—start with what you have and refine over time.</b></li><li><b>The most effective risk programs focus on directionally correct data, not precision.</b></li><li><b>Good risk scenarios clearly define asset, threat, and effect to avoid misalignment.</b></li><li><b>Generative AI accelerates scenario development, data research, and model creation.</b></li><li><b>CISOs should demand more from risk teams—move beyond “pick a color” heat maps.</b></li></ol><p><b><br/>Topics Covered<br/></b><br/></p><ul><li><b>Cyber risk quantification (CRQ)</b></li><li><b>Monte Carlo simulations and modeling</b></li><li><b>Risk scenario design and measurement</b></li><li><b>GRC and compliance integration</b></li><li><b>Generative AI in risk management</b></li><li><b>Moving from qualitative to quantitative risk</b></li><li><b>Improving risk hygiene and maturity</b></li><li><b>CISO leadership and risk culture<br/></b><br/></li></ul><p><b>What You’ll Learn<br/></b><br/></p><ul><li><b>The difference between qualitative and quantitative risk methods</b></li><li><b>How to conduct your first risk quantification in Excel</b></li><li><b>Why Monte Carlo simulations are simpler than most think</b></li><li><b>How GRC, compliance, and security teams can collaborate effectively</b></li><li><b>The six levers that influence risk magnitude and frequency</b></li></ul><p>This podcast is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a>:</p><p><b>ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business. </b></p><p><b>Learn more at </b><a href='https://www.compliancecow.com/'><b>ComplianceCow.com</b></a></p><p><br/></p><p>Connect with our guest: <b>Tony Martin-Vegue on </b><a href='https://www.linkedin.com/in/tonymartinvegue'><b>LinkedIn</b></a></p><ul><li><b>Co-Chair, FAIR Institute San Francisco Chapter</b></li><li><b>Former Risk Leader at Netflix and Gap Inc.</b></li><li><b>Author, </b><b><em>From Heat Maps to Histograms</em></b><b> (coming 2026)</b></li></ul><p>Subscribe to<b> </b><b><em>Security &amp; GRC Decoded</em></b><b> </b>on your favorite platform:</p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=0f831f42f49d44aa&amp;nd=1&amp;dlsi=d667d878b7954d7a'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b></a></li><li><b>Explore all episodes: </b><a href='https://www.compliancecow.com/podcast/'><b>ComplianceCow.com/podcast</b></a></li></ul><p><br/></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/18018493-rethinking-risk-data-driven-decisions-for-modern-cisos-ft-tony-martin-vegue.mp3" length="43590002" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18018493</guid>
    <pubDate>Thu, 16 Oct 2025 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/18018493/transcript" type="text/html" />
    <itunes:duration>3629</itunes:duration>
    <itunes:keywords>Tony Martin-Vegue, cyber risk quantification, FAIR Institute, GRC, compliance automation, risk management, quantitative risk, Monte Carlo simulation, CISOs, cybersecurity leadership, ComplianceCow, Security and GRC Decoded</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why GRC Is More Than Compliance with Kenneth Moras | Head of Security GRC | Plaid</itunes:title>
    <title>Why GRC Is More Than Compliance with Kenneth Moras | Head of Security GRC | Plaid</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy sits down with Kenneth Moras, Head of Security GRC at Plaid. Kenneth shares his journey from web developer and pen tester to building GRC and assurance teams at scale across leading companies like Adobe, Meta, and now Plaid. The conversation explores how GRC must balance governance, risk, and compliance as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth ...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode of </b><b><em>Security &amp; GRC Decoded</em></b><b>, host Raj Krishnamurthy sits down with</b><a href='https://www.linkedin.com/in/kennethmoras/'><b> Kenneth Moras</b></a><b>, Head of Security GRC at Plaid. </b>Kenneth shares his journey from <b>web developer</b> and <b>pen tester</b> to building GRC and assurance teams at scale across leading companies like <b>Adobe</b>, <b>Meta</b>, and now <b>Plaid</b>.</p><p>The conversation explores how <b>GRC must balance governance, risk, and compliance</b> as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth also dives into the origins of the <b>Adobe Common Control Framework</b> (CCF), co-authoring the <b>Open Finance Data Security Standard</b> (OFDSS), and how Plaid applies these principles to secure the <b>future of fintech</b>.</p><p>From <b>reducing GRC toil</b> through engineering and automation, to the <b>role of AI</b> and<b> LLMs</b> in risk management, Kenneth makes the case that <b>GRC isn’t just about passing audits</b> — it’s about building trust, reducing risk, and enabling innovation.</p><p><b><br/>🔑 5 Key Takeaways</b></p><ul><li><b>🌐 Career Evolution: </b>Kenneth’s path from developer to GRC leader shows how diverse skills — from IT audit to consulting — strengthen risk leadership.<b><br/></b><br/></li><li><b>🏗️ Building Frameworks: </b>Adobe CCF and OFDSS highlight the importance of reducing complexity and standardizing security controls for scalability.<br/><br/></li><li><b>⚖️ Governance vs. Risk vs. Compliance: </b>These functions are distinct but must operate in harmony; misalignment creates organizational risk.<b><br/></b><br/></li><li><b>🤖 AI in GRC: </b>Generative AI and MCP tools are shifting GRC from “click ops” to “chat ops,” enabling faster risk assessment and reducing toil.<b><br/></b><br/></li><li><b>🚀 GRC as an Enabler: </b>Done right, GRC accelerates innovation by providing clarity, trust, and measurable security benefits.</li></ul><p><br/></p><p><b>📘 What You’ll Learn<br/></b><br/></p><ul><li><b>How to build a GRC program </b>from scratch in a hyper-growth company.<b><br/></b><br/></li><li><b>Why governance, risk, and compliance </b>require unique skill sets but interlock as checks and balances.<b><br/></b><br/></li><li><b>The story behind Adobe’s CCF and why Plaid </b>open-sourced OFDSS<b>.<br/></b><br/></li><li><b>How AI and automation </b>are changing GRC engineering and risk management.<br/><br/></li><li><b>What Kenneth looks for </b>when hiring the next generation of GRC professionals.<b><br/></b><br/></li></ul><p><b>📺 Watch more episodes: https://www.compliancecow.com/podcast</b></p><p><b>This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: www.compliancecow.com</b></p><p><b><br/>🔗 Connect With Our Guest: </b><a href='https://www.linkedin.com/in/kennethmoras/'><b>Kenneth Moras</b></a><b> | Head of Security GRC at Plaid</b></p><p><b><br/>⭐ Stay Connected:<br/></b><br/></p><p><b>Rate, review, and subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b></a><b><br/></b><br/></li></ul>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode of </b><b><em>Security &amp; GRC Decoded</em></b><b>, host Raj Krishnamurthy sits down with</b><a href='https://www.linkedin.com/in/kennethmoras/'><b> Kenneth Moras</b></a><b>, Head of Security GRC at Plaid. </b>Kenneth shares his journey from <b>web developer</b> and <b>pen tester</b> to building GRC and assurance teams at scale across leading companies like <b>Adobe</b>, <b>Meta</b>, and now <b>Plaid</b>.</p><p>The conversation explores how <b>GRC must balance governance, risk, and compliance</b> as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth also dives into the origins of the <b>Adobe Common Control Framework</b> (CCF), co-authoring the <b>Open Finance Data Security Standard</b> (OFDSS), and how Plaid applies these principles to secure the <b>future of fintech</b>.</p><p>From <b>reducing GRC toil</b> through engineering and automation, to the <b>role of AI</b> and<b> LLMs</b> in risk management, Kenneth makes the case that <b>GRC isn’t just about passing audits</b> — it’s about building trust, reducing risk, and enabling innovation.</p><p><b><br/>🔑 5 Key Takeaways</b></p><ul><li><b>🌐 Career Evolution: </b>Kenneth’s path from developer to GRC leader shows how diverse skills — from IT audit to consulting — strengthen risk leadership.<b><br/></b><br/></li><li><b>🏗️ Building Frameworks: </b>Adobe CCF and OFDSS highlight the importance of reducing complexity and standardizing security controls for scalability.<br/><br/></li><li><b>⚖️ Governance vs. Risk vs. Compliance: </b>These functions are distinct but must operate in harmony; misalignment creates organizational risk.<b><br/></b><br/></li><li><b>🤖 AI in GRC: </b>Generative AI and MCP tools are shifting GRC from “click ops” to “chat ops,” enabling faster risk assessment and reducing toil.<b><br/></b><br/></li><li><b>🚀 GRC as an Enabler: </b>Done right, GRC accelerates innovation by providing clarity, trust, and measurable security benefits.</li></ul><p><br/></p><p><b>📘 What You’ll Learn<br/></b><br/></p><ul><li><b>How to build a GRC program </b>from scratch in a hyper-growth company.<b><br/></b><br/></li><li><b>Why governance, risk, and compliance </b>require unique skill sets but interlock as checks and balances.<b><br/></b><br/></li><li><b>The story behind Adobe’s CCF and why Plaid </b>open-sourced OFDSS<b>.<br/></b><br/></li><li><b>How AI and automation </b>are changing GRC engineering and risk management.<br/><br/></li><li><b>What Kenneth looks for </b>when hiring the next generation of GRC professionals.<b><br/></b><br/></li></ul><p><b>📺 Watch more episodes: https://www.compliancecow.com/podcast</b></p><p><b>This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: www.compliancecow.com</b></p><p><b><br/>🔗 Connect With Our Guest: </b><a href='https://www.linkedin.com/in/kennethmoras/'><b>Kenneth Moras</b></a><b> | Head of Security GRC at Plaid</b></p><p><b><br/>⭐ Stay Connected:<br/></b><br/></p><p><b>Rate, review, and subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><ul><li><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b>Apple Podcasts</b></a><b><br/></b><br/></li></ul>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17892182-why-grc-is-more-than-compliance-with-kenneth-moras-head-of-security-grc-plaid.mp3" length="57030012" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17892182</guid>
    <pubDate>Thu, 02 Oct 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17892182/transcript" type="text/html" />
    <itunes:duration>4749</itunes:duration>
    <itunes:keywords>Kenneth Moras, Plaid, GRC, Governance Risk Compliance, Adobe CCF, OFDSS, Compliance, Risk Management, Security Engineering, Fintech Security, AI in GRC, ComplianceCow Podcast</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>“This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple</itunes:title>
    <title>“This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple</title>
    <itunes:summary><![CDATA[How does a software engineer become a GRC leader? In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy welcomes Varun Gurnaney, Staff Security Engineer at Apple. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies. He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From bui...]]></itunes:summary>
    <description><![CDATA[<p><b>How does a software engineer become a GRC leader? </b>In this episode of <em>Security &amp; GRC Decoded</em>, host Raj Krishnamurthy welcomes <a href='https://www.linkedin.com/in/varungurnaney/'>Varun Gurnaney</a>, Staff Security Engineer at <a href='https://www.apple.com'>Apple</a>. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies.</p><p>He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale.</p><p>🔑 5 Key Takeaways</p><ul><li><b>Compliance ≠ Security</b>: Passing audits is not enough — engineering-driven GRC is the future.</li><li><b>Start Small</b>: Automate one control well to prove value before scaling automation.</li><li><b>Bridging Teams</b>: Cultural friction between engineering, security, GRC, and audit is real — empathy and communication reduce the pain.</li><li><b>Audit Anxiety</b>: Audit automation is about reducing anxiety and toil as much as passing audits.</li><li><b>GRC Engineering is a Discipline</b>: Whether it lives inside GRC or security, automation is now essential.</li></ul><p>📚 What You’ll Learn</p><ul><li>How Varun transitioned from software engineering into GRC leadership</li><li>Why compliance automation looks different for SMBs, mid-market, and enterprises</li><li>The technical and cultural blockers between engineering and GRC</li><li>Practical strategies for proving automation value internally</li><li>How generative AI and coding agents will shape audit and compliance automation</li></ul><p><b>This podcast is brought to you by </b><a href='https://www.compliancecow.com?utm_source=chatgpt.com'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.</p><p>📺 <a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'>Watch more episodes</a> and learn from top leaders in the GRC space!</p><p><br/></p><p><b>Connect With Our Guest:</b><br/> <a href='https://www.linkedin.com/in/varungurnaney/?utm_source=chatgpt.com'>Varun Gurnaney</a> | Staff Security Engineer | <a href='https://www.apple.com?utm_source=chatgpt.com'>Apple</a><br/><br/></p><p>Rate, review, and share if you enjoyed the show!<br/>Subscribe to <em>Security &amp; GRC Decoded</em> wherever you get your podcasts:</p><ul><li><a href='https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL?utm_source=chatgpt.com'>Spotify</a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634?utm_source=chatgpt.com'>Apple Podcasts</a></li></ul>]]></description>
    <content:encoded><![CDATA[<p><b>How does a software engineer become a GRC leader? </b>In this episode of <em>Security &amp; GRC Decoded</em>, host Raj Krishnamurthy welcomes <a href='https://www.linkedin.com/in/varungurnaney/'>Varun Gurnaney</a>, Staff Security Engineer at <a href='https://www.apple.com'>Apple</a>. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies.</p><p>He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale.</p><p>🔑 5 Key Takeaways</p><ul><li><b>Compliance ≠ Security</b>: Passing audits is not enough — engineering-driven GRC is the future.</li><li><b>Start Small</b>: Automate one control well to prove value before scaling automation.</li><li><b>Bridging Teams</b>: Cultural friction between engineering, security, GRC, and audit is real — empathy and communication reduce the pain.</li><li><b>Audit Anxiety</b>: Audit automation is about reducing anxiety and toil as much as passing audits.</li><li><b>GRC Engineering is a Discipline</b>: Whether it lives inside GRC or security, automation is now essential.</li></ul><p>📚 What You’ll Learn</p><ul><li>How Varun transitioned from software engineering into GRC leadership</li><li>Why compliance automation looks different for SMBs, mid-market, and enterprises</li><li>The technical and cultural blockers between engineering and GRC</li><li>Practical strategies for proving automation value internally</li><li>How generative AI and coding agents will shape audit and compliance automation</li></ul><p><b>This podcast is brought to you by </b><a href='https://www.compliancecow.com?utm_source=chatgpt.com'><b>ComplianceCow</b></a> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.</p><p>📺 <a href='https://www.compliancecow.com/podcast?utm_source=chatgpt.com'>Watch more episodes</a> and learn from top leaders in the GRC space!</p><p><br/></p><p><b>Connect With Our Guest:</b><br/> <a href='https://www.linkedin.com/in/varungurnaney/?utm_source=chatgpt.com'>Varun Gurnaney</a> | Staff Security Engineer | <a href='https://www.apple.com?utm_source=chatgpt.com'>Apple</a><br/><br/></p><p>Rate, review, and share if you enjoyed the show!<br/>Subscribe to <em>Security &amp; GRC Decoded</em> wherever you get your podcasts:</p><ul><li><a href='https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL?utm_source=chatgpt.com'>Spotify</a></li><li><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1731815634?utm_source=chatgpt.com'>Apple Podcasts</a></li></ul>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17804264-this-grc-space-is-hot-with-varun-gurnaney-staff-security-engineer-at-apple.mp3" length="38561957" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17804264</guid>
    <pubDate>Thu, 11 Sep 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17804264/transcript" type="text/html" />
    <itunes:duration>3210</itunes:duration>
    <itunes:keywords>Varun Gurnaney, Apple, GRC engineering, compliance automation, audit automation, vulnerability management, security culture, DevSecOps, governance risk compliance, Security &amp; GRC Decoded, Raj Krishnamurthy</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Risk in Dollars: The Future of GRC Measurement ft Ramya Subramanian, Director of GRC @ Freshworks</itunes:title>
    <title>Risk in Dollars: The Future of GRC Measurement ft Ramya Subramanian, Director of GRC @ Freshworks</title>
    <itunes:summary><![CDATA[How does a network engineer become a GRC leader? Ramya Subramanian’s journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC &amp; Privacy Operations at Freshworks, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down. Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing...]]></itunes:summary>
    <description><![CDATA[<p><b>How does a network engineer become a GRC leader</b>? <a href='https://www.linkedin.com/in/ramya-subramanian-b0893012/?utm_source=chatgpt.com'><b>Ramya Subramanian’s</b></a> journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC &amp; Privacy Operations at <a href='https://www.freshworks.com/'>Freshworks</a>, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down.</p><p>Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing to business enabler. This episode is a playbook for anyone trying to modernize risk and compliance in fast-moving environments.</p><p><b><br/>5 Key Takeaways</b></p><ul><li><b>Engineer’s edge in GRC: </b>Why Ramya’s technical background makes her approach to governance unique.</li><li><b>Quantifying risk with dollars: </b>Why risk measurement needs financial context, not just “likelihood x impact.”</li><li><b>Automation as a path forward: </b>How Freshworks is reducing compliance toil for engineers.</li><li><b>Simplify policies and awareness: </b>Cutting policy docs by 90% and building bite-sized security training.</li><li><b>GRC as PR: </b>Storytelling and evangelism can reframe GRC as a business enabler, not a blocker.</li></ul><p><b>What You’ll Learn</b></p><ul><li><b>How GRC and security complement each other</b></li><li><b>Challenges of risk quantification and continuous measurement</b></li><li><b>Why engineers perceive GRC as compliance tax</b></li><li><b>How automation and GRC engineering can reduce manual effort</b></li><li><b>The cultural perception of GRC and how to change it</b></li></ul><p><b>⏱️ (Approximate) Timestamps</b></p><p><b>[00:01:43] From network engineer to GRC leader<br/> [00:03:37] How Ramya defines Governance, Risk, and Compliance<br/> [00:05:28] Quantifying risk: from controls to financial impact<br/> [00:07:41] Why continuous risk measurement is so hard<br/> [00:11:49] How others perceive GRC inside organizations<br/> [00:13:43] Changing the “policing” perception of GRC<br/> [00:17:50] Rewriting policies &amp; security awareness at Freshworks<br/> [00:19:38] Bringing auditors along the journey<br/> [00:21:33] Reducing compliance tax with automation<br/> [00:26:10] Why GRC needs engineering skills<br/> [00:29:58] Technical vs non-technical sides of GRC<br/> [00:31:47] Skills Ramya looks for when hiring<br/> [00:33:53] Generative AI’s impact on GRC<br/> [00:37:49] Dream GRC solution: context-aware automation<br/> [00:39:32] Building a business case for automation<br/> [00:44:00] Who should tell the GRC automation story?<br/> [00:45:54] Challenges with auditors in the AI era<br/> [00:46:49] From city editor to GRC leader — storytelling roots<br/> [00:52:26] Rajinikanth’s influence at Freshworks<br/><br/></b><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Ramya Subramanian | Director of GRC &amp; Privacy Operations</b> <b>|</b> <b>Freshworks<br/></b><a href='https://www.linkedin.com/in/ramya-subramanian-b0893012/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p>]]></description>
    <content:encoded><![CDATA[<p><b>How does a network engineer become a GRC leader</b>? <a href='https://www.linkedin.com/in/ramya-subramanian-b0893012/?utm_source=chatgpt.com'><b>Ramya Subramanian’s</b></a> journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC &amp; Privacy Operations at <a href='https://www.freshworks.com/'>Freshworks</a>, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down.</p><p>Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing to business enabler. This episode is a playbook for anyone trying to modernize risk and compliance in fast-moving environments.</p><p><b><br/>5 Key Takeaways</b></p><ul><li><b>Engineer’s edge in GRC: </b>Why Ramya’s technical background makes her approach to governance unique.</li><li><b>Quantifying risk with dollars: </b>Why risk measurement needs financial context, not just “likelihood x impact.”</li><li><b>Automation as a path forward: </b>How Freshworks is reducing compliance toil for engineers.</li><li><b>Simplify policies and awareness: </b>Cutting policy docs by 90% and building bite-sized security training.</li><li><b>GRC as PR: </b>Storytelling and evangelism can reframe GRC as a business enabler, not a blocker.</li></ul><p><b>What You’ll Learn</b></p><ul><li><b>How GRC and security complement each other</b></li><li><b>Challenges of risk quantification and continuous measurement</b></li><li><b>Why engineers perceive GRC as compliance tax</b></li><li><b>How automation and GRC engineering can reduce manual effort</b></li><li><b>The cultural perception of GRC and how to change it</b></li></ul><p><b>⏱️ (Approximate) Timestamps</b></p><p><b>[00:01:43] From network engineer to GRC leader<br/> [00:03:37] How Ramya defines Governance, Risk, and Compliance<br/> [00:05:28] Quantifying risk: from controls to financial impact<br/> [00:07:41] Why continuous risk measurement is so hard<br/> [00:11:49] How others perceive GRC inside organizations<br/> [00:13:43] Changing the “policing” perception of GRC<br/> [00:17:50] Rewriting policies &amp; security awareness at Freshworks<br/> [00:19:38] Bringing auditors along the journey<br/> [00:21:33] Reducing compliance tax with automation<br/> [00:26:10] Why GRC needs engineering skills<br/> [00:29:58] Technical vs non-technical sides of GRC<br/> [00:31:47] Skills Ramya looks for when hiring<br/> [00:33:53] Generative AI’s impact on GRC<br/> [00:37:49] Dream GRC solution: context-aware automation<br/> [00:39:32] Building a business case for automation<br/> [00:44:00] Who should tell the GRC automation story?<br/> [00:45:54] Challenges with auditors in the AI era<br/> [00:46:49] From city editor to GRC leader — storytelling roots<br/> [00:52:26] Rajinikanth’s influence at Freshworks<br/><br/></b><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Ramya Subramanian | Director of GRC &amp; Privacy Operations</b> <b>|</b> <b>Freshworks<br/></b><a href='https://www.linkedin.com/in/ramya-subramanian-b0893012/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17783961-risk-in-dollars-the-future-of-grc-measurement-ft-ramya-subramanian-director-of-grc-freshworks.mp3" length="39522152" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17783961</guid>
    <pubDate>Thu, 04 Sep 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17783961/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17783961/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17783961/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17783961/transcript.vtt" type="text/vtt" />
    <itunes:duration>3290</itunes:duration>
    <itunes:keywords>Ramya Subramanian, Freshworks, GRC podcast, risk quantification, compliance automation, GRC engineering, cybersecurity governance, compliance tax, security awareness, Rajinikanth Freshworks, Security &amp; GRC Decoded, Raj Krishnamurthy</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Compliance ≠ Security: It Sets the Foundation ft Evan Millman, Security GRC Manager @ Abnormal AI</itunes:title>
    <title>Compliance ≠ Security: It Sets the Foundation ft Evan Millman, Security GRC Manager @ Abnormal AI</title>
    <itunes:summary><![CDATA[What’s the true relationship between compliance and security? According to Evan Millman, compliance may not be security—but it’s the necessary starting point for building it. In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at Abnormal.AI, lessons from scaling GRC in fast-moving environments, and practical advice for anyone try...]]></itunes:summary>
    <description><![CDATA[<p><b>What’s the true relationship between compliance and security?</b> According to <a href='https://www.linkedin.com/in/evan-millman-cissp-2291261a/'>Evan Millman</a>, compliance may not be security—but it’s the necessary starting point for building it.</p><p>In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at <a href='https://abnormal.ai/'>Abnormal.AI</a>, lessons from scaling GRC in fast-moving environments, and practical advice for anyone trying to align controls with business objectives.</p><p><b><br/>5 Key Takeaways:</b></p><ul><li><b>Compliance is not the destination — </b>but it is the framework for real security conversations.</li><li><b>Say no to overkill — </b>Right-size controls based on business needs, not frameworks.</li><li><b>Decentralized GRC works — </b>but only if there’s shared ownership and trust.</li><li><b>“GRC therapy” is real — </b>and it starts with building internal relationships.</li><li><b> Metrics matter — </b>but only when they tell a story that drives action.</li></ul><p><b><br/>What You’ll Learn:</b></p><ul><li><b>Why compliance ≠ security (but still matters)</b></li><li><b>The pitfalls of checklist-first GRC programs</b></li><li><b>How to build GRC partnerships across product and engineering teams</b></li><li><b>Why business-aligned storytelling is the future of risk communication</b></li><li><b>How Abnormal Security approaches frameworks like SOC 2 and ISO 27001</b></li></ul><p><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Evan Millman | Security GRC Manager</b> <b>|</b> <b>Abnormal AI<br/></b><a href='https://www.linkedin.com/in/evan-millman-cissp-2291261a/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><b><br/>🕒 (Approximate) Timestamps<br/></b><br/></p><p><b>[00:02:40] What makes Evan passionate about security GRC?<br/> [00:04:30] How compliance ≠ security — and why that distinction matters<br/> [00:06:50] When GRC goes wrong: overkill, checklists, and inefficiency<br/> [00:10:15] Building trust by embedding security into product discussions<br/> [00:14:40] Right-sizing controls: starting with SOC 2 vs ISO 27001<br/> [00:18:10] Managing a decentralized GRC team at Abnormal<br/> [00:23:02] Metrics and storytelling — what the board actually wants<br/> [00:29:45] Why GRC leaders need emotional intelligence and empathy<br/> [00:35:20] What GRC professionals can learn from product managers<br/> [00:39:11] Evan’s advice to vendors trying to break into GRC<br/> [00:41:05] How GRC can (and should) enable product velocity<br/> [00:44:55] If he could wave a magic wand, what would Evan fix in GRC?</b></p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p><b>What’s the true relationship between compliance and security?</b> According to <a href='https://www.linkedin.com/in/evan-millman-cissp-2291261a/'>Evan Millman</a>, compliance may not be security—but it’s the necessary starting point for building it.</p><p>In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at <a href='https://abnormal.ai/'>Abnormal.AI</a>, lessons from scaling GRC in fast-moving environments, and practical advice for anyone trying to align controls with business objectives.</p><p><b><br/>5 Key Takeaways:</b></p><ul><li><b>Compliance is not the destination — </b>but it is the framework for real security conversations.</li><li><b>Say no to overkill — </b>Right-size controls based on business needs, not frameworks.</li><li><b>Decentralized GRC works — </b>but only if there’s shared ownership and trust.</li><li><b>“GRC therapy” is real — </b>and it starts with building internal relationships.</li><li><b> Metrics matter — </b>but only when they tell a story that drives action.</li></ul><p><b><br/>What You’ll Learn:</b></p><ul><li><b>Why compliance ≠ security (but still matters)</b></li><li><b>The pitfalls of checklist-first GRC programs</b></li><li><b>How to build GRC partnerships across product and engineering teams</b></li><li><b>Why business-aligned storytelling is the future of risk communication</b></li><li><b>How Abnormal Security approaches frameworks like SOC 2 and ISO 27001</b></li></ul><p><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Evan Millman | Security GRC Manager</b> <b>|</b> <b>Abnormal AI<br/></b><a href='https://www.linkedin.com/in/evan-millman-cissp-2291261a/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><b><br/>🕒 (Approximate) Timestamps<br/></b><br/></p><p><b>[00:02:40] What makes Evan passionate about security GRC?<br/> [00:04:30] How compliance ≠ security — and why that distinction matters<br/> [00:06:50] When GRC goes wrong: overkill, checklists, and inefficiency<br/> [00:10:15] Building trust by embedding security into product discussions<br/> [00:14:40] Right-sizing controls: starting with SOC 2 vs ISO 27001<br/> [00:18:10] Managing a decentralized GRC team at Abnormal<br/> [00:23:02] Metrics and storytelling — what the board actually wants<br/> [00:29:45] Why GRC leaders need emotional intelligence and empathy<br/> [00:35:20] What GRC professionals can learn from product managers<br/> [00:39:11] Evan’s advice to vendors trying to break into GRC<br/> [00:41:05] How GRC can (and should) enable product velocity<br/> [00:44:55] If he could wave a magic wand, what would Evan fix in GRC?</b></p><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17705532-compliance-security-it-sets-the-foundation-ft-evan-millman-security-grc-manager-abnormal-ai.mp3" length="53010113" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17705532</guid>
    <pubDate>Thu, 21 Aug 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17705532/transcript" type="text/html" />
    <itunes:duration>4414</itunes:duration>
    <itunes:keywords>compliance vs security, security GRC, GRC strategy, decentralized security, SOC 2, ISO 27001, Abnormal Security, risk metrics, board reporting, product security, security leadership, Raj Krishnamurthy, Security and GRC Decoded</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cyber Economics and Keeping Up with Innovation ft Trupti Shiralkar (Cybersecurity Leader &amp; Advisor)</itunes:title>
    <title>Cyber Economics and Keeping Up with Innovation ft Trupti Shiralkar (Cybersecurity Leader &amp; Advisor)</title>
    <itunes:summary><![CDATA[What trade-offs are you willing to make in cybersecurity?  In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy is joined by Trupti Shiralkar, a seasoned cybersecurity leader and Advisory Board Member at Backslash Security, to explore how risk, ROI, and real-world constraints shape modern security programs. With decades of experience across AppSec, security architecture, and risk governance, Trupti brings a rare blend of deep technical insight and strategic thinking. The...]]></itunes:summary>
    <description><![CDATA[<p>What trade-offs are you willing to make in cybersecurity?<br/> In this episode of <em>Security &amp; GRC Decoded</em>, host <b>Raj Krishnamurthy</b> is joined by <a href='https://www.linkedin.com/in/trupti-shiralkar-0a085a8/'><b>Trupti Shiralkar</b></a>, a seasoned cybersecurity leader and <b>Advisory Board Member at </b><a href='https://www.backslash.security/'><b>Backslash Security</b></a>, to explore how risk, ROI, and real-world constraints shape modern security programs. With decades of experience across AppSec, security architecture, and risk governance, Trupti brings a rare blend of deep technical insight and strategic thinking.</p><p>They dive into <b>cyber economics</b>, <b>AI-driven tooling</b>, and <b>why security storytelling may soon matter more than fear-based metrics</b>. Whether you&apos;re a security veteran or just entering the space, this is a must-listen on staying relevant and effective in the age of automation.</p><p><b>5 Key Takeaways</b></p><ul><li><b>Cybersecurity is about trade-offs – </b>No org can secure everything; knowing what to <em>ignore</em> is just as critical.</li><li><b>LLMs can’t fully replace layered defense – </b>Copilots help, but context and reachability still matter.</li><li><b>ROI matters more than ever – </b>Security teams must prove business value in language execs understand.</li><li><b>Storytelling wins boardrooms – </b>Fear, uncertainty, and doubt (FUD) is out. Framing risk with narrative is in.</li><li><b>Reinvent or be replaced – </b>AI won’t eliminate jobs—it’ll replace outdated versions of them.</li></ul><p><b><br/>What You’ll Learn</b></p><ul><li>How cyber economics helps frame decision-making</li><li>The evolving role of LLMs and software composition tools in vulnerability management</li><li>Why OWASP hasn’t solved insecure code after decades</li><li>How to prioritize reachability over volume</li><li>What developers and security pros should focus on to stay relevant</li></ul><p><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Trupti Shiralkar | </b>Advisory Board Member, Backslash Security<b><br/> </b><a href='https://www.linkedin.com/in/trupti-shiralkar-0a085a8/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><b>Timestamps (Approx)</b></p><p>[00:00] Intro<br/> [02:47] Why cyber economics goes beyond traditional budgeting<br/> [06:10] Introduction of grey swan events and the need for proactive innovation<br/> [10:10] Aligning compliance and security using LLMs<br/> [16:56] Reducing cognitive load in cybersecurity decision-making<br/> [20:00] Budgeting for innovation: Lessons from Trupti’s past security leadership<br/> [23:00] Difference between cyber economics and cyber risk quantification<br/> [33:50] The misunderstood strategic role of GRC<br/> [54:30] How meditation and mindfulness help navigate the security world<br/> [57:15] Trupti’s final shout-outs to historic and modern tech inspirations</p>]]></description>
    <content:encoded><![CDATA[<p>What trade-offs are you willing to make in cybersecurity?<br/> In this episode of <em>Security &amp; GRC Decoded</em>, host <b>Raj Krishnamurthy</b> is joined by <a href='https://www.linkedin.com/in/trupti-shiralkar-0a085a8/'><b>Trupti Shiralkar</b></a>, a seasoned cybersecurity leader and <b>Advisory Board Member at </b><a href='https://www.backslash.security/'><b>Backslash Security</b></a>, to explore how risk, ROI, and real-world constraints shape modern security programs. With decades of experience across AppSec, security architecture, and risk governance, Trupti brings a rare blend of deep technical insight and strategic thinking.</p><p>They dive into <b>cyber economics</b>, <b>AI-driven tooling</b>, and <b>why security storytelling may soon matter more than fear-based metrics</b>. Whether you&apos;re a security veteran or just entering the space, this is a must-listen on staying relevant and effective in the age of automation.</p><p><b>5 Key Takeaways</b></p><ul><li><b>Cybersecurity is about trade-offs – </b>No org can secure everything; knowing what to <em>ignore</em> is just as critical.</li><li><b>LLMs can’t fully replace layered defense – </b>Copilots help, but context and reachability still matter.</li><li><b>ROI matters more than ever – </b>Security teams must prove business value in language execs understand.</li><li><b>Storytelling wins boardrooms – </b>Fear, uncertainty, and doubt (FUD) is out. Framing risk with narrative is in.</li><li><b>Reinvent or be replaced – </b>AI won’t eliminate jobs—it’ll replace outdated versions of them.</li></ul><p><b><br/>What You’ll Learn</b></p><ul><li>How cyber economics helps frame decision-making</li><li>The evolving role of LLMs and software composition tools in vulnerability management</li><li>Why OWASP hasn’t solved insecure code after decades</li><li>How to prioritize reachability over volume</li><li>What developers and security pros should focus on to stay relevant</li></ul><p><em>This podcast is brought to you by </em><a href='https://www.compliancecow.com/'><b><em>ComplianceCow</em></b></a><em> — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. </em><b>Learn more: compliancecow.com</b></p><p>Connect With Our Guest:</p><p><b>Trupti Shiralkar | </b>Advisory Board Member, Backslash Security<b><br/> </b><a href='https://www.linkedin.com/in/trupti-shiralkar-0a085a8/'><b>Connect on LinkedIn</b></a></p><p><b>Rate, review, and share if you enjoyed the show!<br/>Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><b>Timestamps (Approx)</b></p><p>[00:00] Intro<br/> [02:47] Why cyber economics goes beyond traditional budgeting<br/> [06:10] Introduction of grey swan events and the need for proactive innovation<br/> [10:10] Aligning compliance and security using LLMs<br/> [16:56] Reducing cognitive load in cybersecurity decision-making<br/> [20:00] Budgeting for innovation: Lessons from Trupti’s past security leadership<br/> [23:00] Difference between cyber economics and cyber risk quantification<br/> [33:50] The misunderstood strategic role of GRC<br/> [54:30] How meditation and mindfulness help navigate the security world<br/> [57:15] Trupti’s final shout-outs to historic and modern tech inspirations</p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17619765-cyber-economics-and-keeping-up-with-innovation-ft-trupti-shiralkar-cybersecurity-leader-advisor.mp3" length="43194136" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17619765</guid>
    <pubDate>Thu, 07 Aug 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17619765/transcript" type="text/html" />
    <itunes:duration>3596</itunes:duration>
    <itunes:keywords>cybersecurity podcast, Trupti Shiralkar, AppSec, vulnerability management, cyber risk, compliance automation, explainable AI, LLM security, AI in security, Security and GRC Decoded, ComplianceCow, security ROI, OWASP, storytelling in security</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why Security And GRC Teams Must Act Like Service Teams ft Jiphun Satapathy from Medallia</itunes:title>
    <title>Why Security And GRC Teams Must Act Like Service Teams ft Jiphun Satapathy from Medallia</title>
    <itunes:summary><![CDATA[Jiphun Satapathy has built and scaled security organizations at AWS, Snowflake, and now Medallia. In this episode, he joins our host Raj to explore the evolving role of CISOs as strategic business leaders. They discuss the importance of treating security as a service organization, how to handle vendor noise, and why insider risk is often overlooked. You’ll hear practical advice for security and GRC leaders working in AI-first, high-growth environments—and how to maintain trust across engineer...]]></itunes:summary>
    <description><![CDATA[<p><a href='https://www.linkedin.com/in/jiphunsatapathy'><b>Jiphun Satapathy</b></a> has built and scaled security organizations at <b>AWS</b>, <b>Snowflake</b>, and now <a href='https://www.medallia.com/'><b>Medallia</b></a>. In this episode, he joins our host <b>Raj</b> to explore <b>the evolving role of CISOs as strategic business leaders</b>. They discuss the importance of <b>treating security as a service organization</b>, <b>how to handle vendor noise</b>, and <b>why insider risk is often overlooked</b>. You’ll hear practical advice for <b>security</b> and <b>GRC leaders</b> working in <b>AI-first</b>, <b>high-growth environments</b>—and <b>how to maintain trust across engineering, compliance, </b>and<b> executive teams</b>.</p><p><b><br/>Key Takeaways</b></p><ul><li><b>Security as a Service Function</b>: Security should empower—not block—the business. Jiphun shares how his team supports product, engineering, and sales.</li><li><b>Vendor Engagement Matters</b>: CISOs who ignore vendors miss out on innovation. But filtering the noise is key.</li><li><b>Insider Risk is Real</b>: Not rogue employees, but everyday developer behavior is a top source of risk.</li><li><b>Modern GRC Requires Technical Fluency</b>: Especially in AI-first companies, GRC teams must understand the tech stack to stay relevant.</li><li><b>Earn Trust Through Action: </b>Metrics matter, but culture and execution are what build credibility with boards, customers, and engineers.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How to build a risk-based security roadmap that keeps pace with rapid development</li><li>The role of security in shaping culture across a global org</li><li>How startups can engage CISOs without falling into FUD tactics</li></ul><p><b>This episode is brought to you by </b><a href='https://www.compliancecow.com'><b>ComplianceCow</b></a><b> — the smarter way to automate compliance and monitor controls.</b></p><p>-- <b>Learn more at compliancecow.com <br/>-- Connect with Jiphun on Linkedin:</b><a href='https://www.linkedin.com/in/jiphunsatapathy'><b> </b></a><a href='http://linkedin.com/in/jiphunsatapathy'><b>linkedin.com/in/jiphunsatapathy</b></a></p><p><b>🎧  Rate, review, and share if you enjoyed the show!<br/> 🎙 Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><br/></p><p>(<b>Approximate)</b> <b>Timestamps:</b></p><ul><li>[00:01:48] Jiphun challenges CISO aversion to vendor engagement</li><li>[00:03:25] Filtering vendors based on prioritized security needs</li><li>[00:06:24] Empowering teams with bottom-up decision-making</li><li>[00:08:15] Driving culture change and making security a productivity enabler</li><li>[00:11:33] MFA example showing how to improve both security and UX</li><li>[00:15:25] Treating internal stakeholders as customers</li><li>[00:21:02] Measuring risk with frameworks and metrics</li><li>[00:30:22] Using automation to align security cadence with CI/CD pipelines</li><li>[00:32:47] Insider risk and why it belongs on board slides</li><li>[00:42:33] Empowering devs by reducing vulnerability noise</li><li>[00:51:22] Why healthy paranoia is essential in AI adoption</li><li>[00:56:51] Why GRC teams must be technical in AI-first environments</li><li>[01:03:15] Advice to security startups: stop with the FUD</li><li>[01:07:02] Coping strategies for CISO stress and burnout</li><li>[01:09:60] Books and mentors that shaped Jiphun’s leadership journey</li></ul><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p><a href='https://www.linkedin.com/in/jiphunsatapathy'><b>Jiphun Satapathy</b></a> has built and scaled security organizations at <b>AWS</b>, <b>Snowflake</b>, and now <a href='https://www.medallia.com/'><b>Medallia</b></a>. In this episode, he joins our host <b>Raj</b> to explore <b>the evolving role of CISOs as strategic business leaders</b>. They discuss the importance of <b>treating security as a service organization</b>, <b>how to handle vendor noise</b>, and <b>why insider risk is often overlooked</b>. You’ll hear practical advice for <b>security</b> and <b>GRC leaders</b> working in <b>AI-first</b>, <b>high-growth environments</b>—and <b>how to maintain trust across engineering, compliance, </b>and<b> executive teams</b>.</p><p><b><br/>Key Takeaways</b></p><ul><li><b>Security as a Service Function</b>: Security should empower—not block—the business. Jiphun shares how his team supports product, engineering, and sales.</li><li><b>Vendor Engagement Matters</b>: CISOs who ignore vendors miss out on innovation. But filtering the noise is key.</li><li><b>Insider Risk is Real</b>: Not rogue employees, but everyday developer behavior is a top source of risk.</li><li><b>Modern GRC Requires Technical Fluency</b>: Especially in AI-first companies, GRC teams must understand the tech stack to stay relevant.</li><li><b>Earn Trust Through Action: </b>Metrics matter, but culture and execution are what build credibility with boards, customers, and engineers.</li></ul><p><b>What You’ll Learn</b></p><ul><li>How to build a risk-based security roadmap that keeps pace with rapid development</li><li>The role of security in shaping culture across a global org</li><li>How startups can engage CISOs without falling into FUD tactics</li></ul><p><b>This episode is brought to you by </b><a href='https://www.compliancecow.com'><b>ComplianceCow</b></a><b> — the smarter way to automate compliance and monitor controls.</b></p><p>-- <b>Learn more at compliancecow.com <br/>-- Connect with Jiphun on Linkedin:</b><a href='https://www.linkedin.com/in/jiphunsatapathy'><b> </b></a><a href='http://linkedin.com/in/jiphunsatapathy'><b>linkedin.com/in/jiphunsatapathy</b></a></p><p><b>🎧  Rate, review, and share if you enjoyed the show!<br/> 🎙 Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> wherever you get your podcasts:</b></p><p><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b>Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></p><p><br/></p><p>(<b>Approximate)</b> <b>Timestamps:</b></p><ul><li>[00:01:48] Jiphun challenges CISO aversion to vendor engagement</li><li>[00:03:25] Filtering vendors based on prioritized security needs</li><li>[00:06:24] Empowering teams with bottom-up decision-making</li><li>[00:08:15] Driving culture change and making security a productivity enabler</li><li>[00:11:33] MFA example showing how to improve both security and UX</li><li>[00:15:25] Treating internal stakeholders as customers</li><li>[00:21:02] Measuring risk with frameworks and metrics</li><li>[00:30:22] Using automation to align security cadence with CI/CD pipelines</li><li>[00:32:47] Insider risk and why it belongs on board slides</li><li>[00:42:33] Empowering devs by reducing vulnerability noise</li><li>[00:51:22] Why healthy paranoia is essential in AI adoption</li><li>[00:56:51] Why GRC teams must be technical in AI-first environments</li><li>[01:03:15] Advice to security startups: stop with the FUD</li><li>[01:07:02] Coping strategies for CISO stress and burnout</li><li>[01:09:60] Books and mentors that shaped Jiphun’s leadership journey</li></ul><p><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17502810-why-security-and-grc-teams-must-act-like-service-teams-ft-jiphun-satapathy-from-medallia.mp3" length="52859943" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17502810</guid>
    <pubDate>Tue, 05 Aug 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17502810/transcript" type="text/html" />
    <itunes:duration>4401</itunes:duration>
    <itunes:keywords>CISO, cybersecurity, GRC, insider risk, startup advice, vendor engagement, AI security, cloud security, secure software development, security culture, risk management, compliance automation, ServiceNow, security team leadership</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Preetam Joshi Breaks Down ML, LLMs, AI Agents, and Governance Challenges</itunes:title>
    <title>Preetam Joshi Breaks Down ML, LLMs, AI Agents, and Governance Challenges</title>
    <itunes:summary><![CDATA[How do you make sense of security, governance, and risk in an age of black-box AI? This week, Raj is joined by Preetam Joshi, founder of Aimon Labs and machine learning veteran with experience at DRDO, Yahoo, Netflix, and Thumbtack. Together, they break down the technical evolution behind large language models (LLMs), explore the real challenges of explainability, and discuss why GRC teams must rethink risk in the age of autonomous reasoning systems. Preetam brings a rare mix of hands-on ML e...]]></itunes:summary>
    <description><![CDATA[<p><b>How do you make sense of security, governance, and risk in an age of black-box AI? </b>This week, Raj is joined by <a href='https://www.linkedin.com/in/preetambjoshi/'><b>Preetam Joshi</b></a>, founder of <a href='https://www.aimon.ai/'><b>Aimon Labs</b></a> and machine learning veteran with experience at <b>DRDO</b>, <b>Yahoo</b>, <b>Netflix</b>, and <b>Thumbtack</b>. Together, they break down the technical evolution behind large language models (LLMs), explore the real challenges of explainability, and discuss why GRC teams must rethink risk in the age of autonomous reasoning systems.</p><p>Preetam brings a rare mix of hands-on ML expertise and practical experience deploying LLMs in enterprise environments. If you’ve been wondering how transformers work, what explainability really means, or why AI governance is still a mess — this episode is for you.</p><p><b> 5 Key Takeaways:</b></p><p>-<b>From DRDO to Netflix to Aimon Labs — </b>Preetam’s career journey shows the intersection of machine learning, security, and entrepreneurship.<b><br/>-How Transformers Work — </b>A simple breakdown of encoder/decoder architecture, embeddings, and attention mechanisms.<b><br/>-Explainability in AI — </b>What it meant in traditional ML... and why it’s nearly impossible with today’s LLMs.<b><br/>-Rule-Based Logic Isn’t Dead — </b>In high-stakes environments, deterministic systems still matter.<b><br/>-Bridging AI &amp; GRC — </b>Practical steps for model security, auditing, and compliance in non-deterministic systems.</p><p><b>📌 Take Action</b></p><ul><li><b>Visit </b><a href='https://www.ComplianceCow.com/podcast'><b>ComplianceCow.com/podcast</b></a><b> to catch all episodes<br/></b><br/></li><li><b>Connect with Preetam on</b><a href='https://www.linkedin.com/in/preetambjoshi/'><b> LinkedIn<br/></b></a><br/></li><li><b>Follow the show on</b><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b> Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></li></ul><p><b><em>Security &amp; GRC Decoded</em></b><b> is brought to you by</b><a href='https://www.compliancecow.com'><b> ComplianceCow</b></a><b> — the platform for proactive, automated compliance.</b></p><p><b>🎧 Subscribe, rate, and share if this episode sparked a thought.<br/></b><br/></p><p><b>⏱ Timestamps (approx.)</b></p><p><b>00:00 – Intro<br/> 01:11 – Welcome Preetam to the show<br/> 03:20 – What has been your favorite experience working in AI so far?<br/> 07:08 – What is transformer architecture and how does it work?<br/> 10:23 – How do LLMs solve problems like math or reasoning?<br/> 12:38 – Where do agents fit in the LLM ecosystem?<br/> 16:07 – How does reinforcement learning apply to AI models?<br/> 21:33 – What does explainability mean in ML?<br/> 24:55 – Can you explain the limitations of SHAP and parameter-level reasoning?<br/> 27:33 – What does GRC look like in the LLM age?<br/> 30:58 – What does AIMon Labs actually do?<br/> 35:00 – Why is reliability a challenge with LLMs?<br/> 39:15 – Where does GRC intersect with AI deployment and compliance?<br/> 41:30 – What is fine-tuning and when is it useful?<br/> 44:43 – Is Retrieval Augmented Generation (RAG) still relevant with longer context windows?<br/> 47:29 – How do we guard against LLM misuse and toxic output?<br/> 49:43 – How can LLMs overexpose sensitive company data?<br/> 53:28 – Advice for those starting a career in AI or ML<br/> 55:34 – What are your favorite models right now?<br/></b><br/></p>]]></description>
    <content:encoded><![CDATA[<p><b>How do you make sense of security, governance, and risk in an age of black-box AI? </b>This week, Raj is joined by <a href='https://www.linkedin.com/in/preetambjoshi/'><b>Preetam Joshi</b></a>, founder of <a href='https://www.aimon.ai/'><b>Aimon Labs</b></a> and machine learning veteran with experience at <b>DRDO</b>, <b>Yahoo</b>, <b>Netflix</b>, and <b>Thumbtack</b>. Together, they break down the technical evolution behind large language models (LLMs), explore the real challenges of explainability, and discuss why GRC teams must rethink risk in the age of autonomous reasoning systems.</p><p>Preetam brings a rare mix of hands-on ML expertise and practical experience deploying LLMs in enterprise environments. If you’ve been wondering how transformers work, what explainability really means, or why AI governance is still a mess — this episode is for you.</p><p><b> 5 Key Takeaways:</b></p><p>-<b>From DRDO to Netflix to Aimon Labs — </b>Preetam’s career journey shows the intersection of machine learning, security, and entrepreneurship.<b><br/>-How Transformers Work — </b>A simple breakdown of encoder/decoder architecture, embeddings, and attention mechanisms.<b><br/>-Explainability in AI — </b>What it meant in traditional ML... and why it’s nearly impossible with today’s LLMs.<b><br/>-Rule-Based Logic Isn’t Dead — </b>In high-stakes environments, deterministic systems still matter.<b><br/>-Bridging AI &amp; GRC — </b>Practical steps for model security, auditing, and compliance in non-deterministic systems.</p><p><b>📌 Take Action</b></p><ul><li><b>Visit </b><a href='https://www.ComplianceCow.com/podcast'><b>ComplianceCow.com/podcast</b></a><b> to catch all episodes<br/></b><br/></li><li><b>Connect with Preetam on</b><a href='https://www.linkedin.com/in/preetambjoshi/'><b> LinkedIn<br/></b></a><br/></li><li><b>Follow the show on</b><a href='https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr'><b> Spotify</b></a><b> and</b><a href='https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450'><b> Apple Podcasts</b></a></li></ul><p><b><em>Security &amp; GRC Decoded</em></b><b> is brought to you by</b><a href='https://www.compliancecow.com'><b> ComplianceCow</b></a><b> — the platform for proactive, automated compliance.</b></p><p><b>🎧 Subscribe, rate, and share if this episode sparked a thought.<br/></b><br/></p><p><b>⏱ Timestamps (approx.)</b></p><p><b>00:00 – Intro<br/> 01:11 – Welcome Preetam to the show<br/> 03:20 – What has been your favorite experience working in AI so far?<br/> 07:08 – What is transformer architecture and how does it work?<br/> 10:23 – How do LLMs solve problems like math or reasoning?<br/> 12:38 – Where do agents fit in the LLM ecosystem?<br/> 16:07 – How does reinforcement learning apply to AI models?<br/> 21:33 – What does explainability mean in ML?<br/> 24:55 – Can you explain the limitations of SHAP and parameter-level reasoning?<br/> 27:33 – What does GRC look like in the LLM age?<br/> 30:58 – What does AIMon Labs actually do?<br/> 35:00 – Why is reliability a challenge with LLMs?<br/> 39:15 – Where does GRC intersect with AI deployment and compliance?<br/> 41:30 – What is fine-tuning and when is it useful?<br/> 44:43 – Is Retrieval Augmented Generation (RAG) still relevant with longer context windows?<br/> 47:29 – How do we guard against LLM misuse and toxic output?<br/> 49:43 – How can LLMs overexpose sensitive company data?<br/> 53:28 – Advice for those starting a career in AI or ML<br/> 55:34 – What are your favorite models right now?<br/></b><br/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17467486-preetam-joshi-breaks-down-ml-llms-ai-agents-and-governance-challenges.mp3" length="42174053" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17467486</guid>
    <pubDate>Thu, 10 Jul 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17467486/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17467486/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17467486/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17467486/transcript.vtt" type="text/vtt" />
    <itunes:duration>3511</itunes:duration>
    <itunes:keywords>AI governance, explainability in AI, large language models, LLM, LLMs, gen ai, Preetam Joshi, Aimon Labs, Security and GRC Decoded, machine learning, model risk management, compliance automation, LLM security, Raj Krishnamurthy, ComplianceCow, reasoning m</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>RGC, Not GRC: Why Risk Comes First ft Ricky Waldron</itunes:title>
    <title>RGC, Not GRC: Why Risk Comes First ft Ricky Waldron</title>
    <itunes:summary><![CDATA[What if compliance wasn't just about passing audits—but about building trust from the ground up? In this powerful episode of Security &amp; GRC Decoded, Raj sits down with Ricky Waldron, Director of Security Audit &amp; GRC at Navan, whose GRC experience spans tech giants like Microsoft, Disney, Oracle, and Smartsheet. Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine ...]]></itunes:summary>
    <description><![CDATA[<p><b>What if compliance wasn&apos;t just about passing audits—but about building trust from the ground up?</b></p><p>In this powerful episode of <b><em>Security &amp; GRC Decoded</em></b>, Raj sits down with <a href='https://www.linkedin.com/in/rickywaldron/'><b>Ricky Waldron</b></a><b>, Director of Security Audit &amp; GRC at </b><a href='https://navan.com/'><b>Navan</b></a>, whose GRC experience spans tech giants like <b>Microsoft</b>, <b>Disney</b>, <b>Oracle</b>, and <b>Smartsheet</b>. Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine of trust, not a blocker.</p><p>From FedRAMP horror stories to generative AI workflows, this conversation dives deep into the future of governance, risk, and compliance—and why it&apos;s time for GRC teams to start thinking like engineers.<b><br/></b><br/></p><p><b>🔑 5 Key Takeaways</b></p><ul><li><b>💥 Compliance = </b>Security (If Done Right): Internal compliance based on risk and business needs often leads to stronger security outcomes than external certifications alone.</li><li><b>🤝 Stop Policing, Start Partnering: </b>GRC shouldn’t just point out problems—it should offer solutions and collaborate with teams to reduce risk.</li><li><b>📊 Quantify Risk to Speak Leadership’s Language: </b>Turn technical risk into business impact using frameworks like FAIR to get buy-in and budget.</li><li><b>⚙️ Automation Is GRC’s Future: </b>From policy drafting with AI to continuous control monitoring, GRC teams must become technical and leverage automation.</li><li><b>🧩 GRC as a Sales Enabler: </b>GRC isn&apos;t just an internal function—it builds trust with customers, shortens sales cycles, and helps close deals.</li></ul><p><b>✅ Take Action</b></p><ul><li><b>Explore risk-first approaches: </b>Lead with R in GRC to align controls with actual business risks.</li><li><b>Invest in automation: </b>Save engineering hours and scale audits with continuous evidence collection.</li><li><b>Use GenAI wisely: </b>Leverage it for speed, but ensure strong human review before anything goes to auditors.<b><br/></b><br/></li></ul><p><b>🔗 Powered by</b><a href='https://www.compliancecow.com'><b> ComplianceCow.com</b></a><b> – automate audits, collect evidence continuously, and shift GRC left.<br/> 🎧 Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> for weekly insights from today’s top compliance leaders.<br/> 💼 Connect with</b><a href='https://www.linkedin.com/in/rickywaldron/'><b> Ricky Waldron</b></a><b> on LinkedIn.</b></p><p><br/></p><p>⏱ Timestamps (approx.)</p><p>00:00 – Intro<br/> 01:35 – Hot take on GRC<br/> 04:31 – Why GRC &amp; Security clash<br/> 08:44 – GRC is storytelling<br/> 12:57 – Risk comes before compliance<br/> 16:08 – How to talk risk with execs<br/> 20:41 – Trust as a compliance goal<br/> 24:50 – Keeping your promises<br/> 27:54 – Why GRC struggles with automation<br/> 33:15 – Speaking engineers’ language<br/> 38:50 – GRC as the customer conduit<br/> 45:00 – GRC as sales enablement<br/> 47:15 – How Ricky learned FedRAMP<br/> 50:20 – What is FedRAMP 20X?<br/> 52:27 – Why OSCAL hasn’t taken off<br/> 56:15 – Would you use OSCAL commercially?<br/> 58:36 – GenAI in GRC workflows<br/> 1:02:31 – Using AI with auditors<br/> 1:06:45 – State of GRC tooling<br/> 1:12:30 – Getting budget for automation</p>]]></description>
    <content:encoded><![CDATA[<p><b>What if compliance wasn&apos;t just about passing audits—but about building trust from the ground up?</b></p><p>In this powerful episode of <b><em>Security &amp; GRC Decoded</em></b>, Raj sits down with <a href='https://www.linkedin.com/in/rickywaldron/'><b>Ricky Waldron</b></a><b>, Director of Security Audit &amp; GRC at </b><a href='https://navan.com/'><b>Navan</b></a>, whose GRC experience spans tech giants like <b>Microsoft</b>, <b>Disney</b>, <b>Oracle</b>, and <b>Smartsheet</b>. Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine of trust, not a blocker.</p><p>From FedRAMP horror stories to generative AI workflows, this conversation dives deep into the future of governance, risk, and compliance—and why it&apos;s time for GRC teams to start thinking like engineers.<b><br/></b><br/></p><p><b>🔑 5 Key Takeaways</b></p><ul><li><b>💥 Compliance = </b>Security (If Done Right): Internal compliance based on risk and business needs often leads to stronger security outcomes than external certifications alone.</li><li><b>🤝 Stop Policing, Start Partnering: </b>GRC shouldn’t just point out problems—it should offer solutions and collaborate with teams to reduce risk.</li><li><b>📊 Quantify Risk to Speak Leadership’s Language: </b>Turn technical risk into business impact using frameworks like FAIR to get buy-in and budget.</li><li><b>⚙️ Automation Is GRC’s Future: </b>From policy drafting with AI to continuous control monitoring, GRC teams must become technical and leverage automation.</li><li><b>🧩 GRC as a Sales Enabler: </b>GRC isn&apos;t just an internal function—it builds trust with customers, shortens sales cycles, and helps close deals.</li></ul><p><b>✅ Take Action</b></p><ul><li><b>Explore risk-first approaches: </b>Lead with R in GRC to align controls with actual business risks.</li><li><b>Invest in automation: </b>Save engineering hours and scale audits with continuous evidence collection.</li><li><b>Use GenAI wisely: </b>Leverage it for speed, but ensure strong human review before anything goes to auditors.<b><br/></b><br/></li></ul><p><b>🔗 Powered by</b><a href='https://www.compliancecow.com'><b> ComplianceCow.com</b></a><b> – automate audits, collect evidence continuously, and shift GRC left.<br/> 🎧 Subscribe to </b><b><em>Security &amp; GRC Decoded</em></b><b> for weekly insights from today’s top compliance leaders.<br/> 💼 Connect with</b><a href='https://www.linkedin.com/in/rickywaldron/'><b> Ricky Waldron</b></a><b> on LinkedIn.</b></p><p><br/></p><p>⏱ Timestamps (approx.)</p><p>00:00 – Intro<br/> 01:35 – Hot take on GRC<br/> 04:31 – Why GRC &amp; Security clash<br/> 08:44 – GRC is storytelling<br/> 12:57 – Risk comes before compliance<br/> 16:08 – How to talk risk with execs<br/> 20:41 – Trust as a compliance goal<br/> 24:50 – Keeping your promises<br/> 27:54 – Why GRC struggles with automation<br/> 33:15 – Speaking engineers’ language<br/> 38:50 – GRC as the customer conduit<br/> 45:00 – GRC as sales enablement<br/> 47:15 – How Ricky learned FedRAMP<br/> 50:20 – What is FedRAMP 20X?<br/> 52:27 – Why OSCAL hasn’t taken off<br/> 56:15 – Would you use OSCAL commercially?<br/> 58:36 – GenAI in GRC workflows<br/> 1:02:31 – Using AI with auditors<br/> 1:06:45 – State of GRC tooling<br/> 1:12:30 – Getting budget for automation</p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17400167-rgc-not-grc-why-risk-comes-first-ft-ricky-waldron.mp3" length="57150011" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17400167</guid>
    <pubDate>Thu, 26 Jun 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17400167/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17400167/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17400167/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17400167/transcript.vtt" type="text/vtt" />
    <itunes:duration>4759</itunes:duration>
    <itunes:keywords>compliance, security, GRC, governance risk compliance, risk management, audit readiness, FedRAMP, SOC 2, automation, continuous compliance, storytelling, cybersecurity, trust management, enterprise risk, control frameworks, shift left, GRC automation, AI </itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What Does ‘Technical’ Even Mean in GRC? ft Alan Luk @ Grammarly</itunes:title>
    <title>What Does ‘Technical’ Even Mean in GRC? ft Alan Luk @ Grammarly</title>
    <itunes:summary><![CDATA[Is it time to stop pretending GRC is technical? Alan Luk makes the case for a new kind of compliance leader—and it might surprise you. In this sharp and unfiltered episode of Security &amp; GRC Decoded, Alan Luk, Director of GRC at Grammarly (and former Microsoft and PwC leader), joins Raj to dismantle common myths about GRC—and why even your engineers might be thinking about it all wrong. Drawing from over 20 years of experience, Alan makes the case for why GRC should be seen as a program ma...]]></itunes:summary>
    <description><![CDATA[<p><b>Is it time to stop pretending GRC is technical? </b>Alan Luk makes the case for a new kind of compliance leader—and it might surprise you.</p><p>In this sharp and unfiltered episode of <em>Security &amp; GRC Decoded</em>, <a href='https://www.linkedin.com/in/alan-luk-4027b29/'>Alan Luk</a>, Director of GRC at <a href='https://www.grammarly.com/'>Grammarly</a> (and former Microsoft and PwC leader), joins Raj to dismantle common myths about GRC—and why even your engineers might be thinking about it all wrong.</p><p>Drawing from over 20 years of experience, Alan makes the case for why GRC should be seen as a <em>program management function</em>, not a technical one—and how that shift unlocks better controls, less friction with engineering, and less painful audits. From audit war stories to his vision for continuous assurance, Alan brings blunt honesty, practical insight, and some well-earned hot takes to the mic.</p><p>🔑 <b>Key Takeaways</b>:</p><p>✅ Why most companies—and even GRC pros—misunderstand what GRC is actually for<br/> ✅ How PM skills (not coding) unlock stronger GRC outcomes and happier engineers<br/> ✅ What good compliance teams do <em>before</em> audit season to avoid chaos<br/> ✅ Why control owners—not GRC—should own the metrics (and what to do if they don’t)<br/> ✅ A bold vision for the future: GRC as an observability layer, not an evidence factory</p><p>🎯 <b>Take Action</b>:</p><p>→ Rethink what GRC really <em>means</em> inside your org: is it a service, a blocker, or a translator?<br/> → Audit your compliance program’s audit readiness—do you have metrics or just screenshots?<br/> → Share this episode with your PMs, engineers, or auditors who still think GRC is just check-the-box</p><p>👉 Follow <em>Security &amp; GRC Decoded</em> for fresh insights on how to make your GRC program faster, smarter, and more resilient.<br/> 🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a>. Discover how ComplianceCow helps teams move from reactive compliance to proactive control automation.<br/> 🚀 Liking the show? Leave a rating and review to help us grow and keep bringing you bold GRC conversations.</p><p>💬 Connect with Alan Luk:<br/> 💼 LinkedIn: <a href='https://www.linkedin.com/in/alan-luk-4027b29/'>https://www.linkedin.com/in/alan-luk-4027b29/</a><br/> 🌐 Company: <a href='https://www.grammarly.com'>https://www.grammarly.com</a></p>]]></description>
    <content:encoded><![CDATA[<p><b>Is it time to stop pretending GRC is technical? </b>Alan Luk makes the case for a new kind of compliance leader—and it might surprise you.</p><p>In this sharp and unfiltered episode of <em>Security &amp; GRC Decoded</em>, <a href='https://www.linkedin.com/in/alan-luk-4027b29/'>Alan Luk</a>, Director of GRC at <a href='https://www.grammarly.com/'>Grammarly</a> (and former Microsoft and PwC leader), joins Raj to dismantle common myths about GRC—and why even your engineers might be thinking about it all wrong.</p><p>Drawing from over 20 years of experience, Alan makes the case for why GRC should be seen as a <em>program management function</em>, not a technical one—and how that shift unlocks better controls, less friction with engineering, and less painful audits. From audit war stories to his vision for continuous assurance, Alan brings blunt honesty, practical insight, and some well-earned hot takes to the mic.</p><p>🔑 <b>Key Takeaways</b>:</p><p>✅ Why most companies—and even GRC pros—misunderstand what GRC is actually for<br/> ✅ How PM skills (not coding) unlock stronger GRC outcomes and happier engineers<br/> ✅ What good compliance teams do <em>before</em> audit season to avoid chaos<br/> ✅ Why control owners—not GRC—should own the metrics (and what to do if they don’t)<br/> ✅ A bold vision for the future: GRC as an observability layer, not an evidence factory</p><p>🎯 <b>Take Action</b>:</p><p>→ Rethink what GRC really <em>means</em> inside your org: is it a service, a blocker, or a translator?<br/> → Audit your compliance program’s audit readiness—do you have metrics or just screenshots?<br/> → Share this episode with your PMs, engineers, or auditors who still think GRC is just check-the-box</p><p>👉 Follow <em>Security &amp; GRC Decoded</em> for fresh insights on how to make your GRC program faster, smarter, and more resilient.<br/> 🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by <a href='https://www.compliancecow.com'><b>ComplianceCow</b></a>. Discover how ComplianceCow helps teams move from reactive compliance to proactive control automation.<br/> 🚀 Liking the show? Leave a rating and review to help us grow and keep bringing you bold GRC conversations.</p><p>💬 Connect with Alan Luk:<br/> 💼 LinkedIn: <a href='https://www.linkedin.com/in/alan-luk-4027b29/'>https://www.linkedin.com/in/alan-luk-4027b29/</a><br/> 🌐 Company: <a href='https://www.grammarly.com'>https://www.grammarly.com</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17315851-what-does-technical-even-mean-in-grc-ft-alan-luk-grammarly.mp3" length="50525800" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17315851</guid>
    <pubDate>Thu, 12 Jun 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17315851/transcript" type="text/html" />
    <itunes:duration>4207</itunes:duration>
    <itunes:keywords>GRC, Compliance, Risk Management, Security Compliance, Continuous Assurance, Alan Luk, Grammarly, Compliance Automation, SOC 2, ISO 27001, Audit Readiness, Security and GRC Decoded, Program Management, Cybersecurity, Control Effectiveness, GRC Tools, Engi</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>No More Compliance Theater: Meet Real Security Compliance with Adam Brennick</itunes:title>
    <title>No More Compliance Theater: Meet Real Security Compliance with Adam Brennick</title>
    <itunes:summary><![CDATA[Is it time to rethink SOC 2? (Spoiler: Adam thinks so—and he’s got the receipts.)  In this insightful episode of Security &amp; GRC Decoded, Adam Brennick, Director of Security Risk &amp; Compliance at Cockroach Labs, joins Raj to challenge the status quo of SOC 2, compliance culture, and how GRC teams should operate in a modern, engineering-driven world. With a unique perspective from leading both security and GRC functions, Adam shares why today’s compliance efforts often miss the mark—and ...]]></itunes:summary>
    <description><![CDATA[<p><b>Is it time to rethink SOC 2? (Spoiler: Adam thinks so—and he’s got the receipts.)</b><br/> In this insightful episode of <em>Security &amp; GRC Decoded</em>, <a href='https://www.linkedin.com/in/adam-brennick-959352158/'><b>Adam Brennick</b></a>, Director of Security Risk &amp; Compliance at <a href='https://www.cockroachlabs.com/'><b>Cockroach Labs</b></a>, joins Raj to challenge the status quo of <b>SOC 2</b>, <b>compliance culture</b>, and <b>how GRC teams should operate in a modern, engineering-driven world</b>.</p><p>With a unique perspective from leading both security and GRC functions, Adam shares why today’s compliance efforts often miss the mark—and how we can fix that. From his hot takes on “a la carte” SOC 2 to building automation-first programs that actually reduce risk, Adam brings clarity, conviction, and practical wisdom to the mic.</p><p><b>Key Takeaways:</b></p><p>✅ Why SOC 2 should be customizable—and how that shift would improve both trust and transparency<br/> ✅ How GRC, security, and trust functions intersect (and where they often break down)<br/> ✅ The role of “vibe coding” and AI in enabling GRC engineering<br/> ✅ Real-world strategies for building a balanced, high-impact GRC team<br/> ✅ How to make a bulletproof business case for compliance automation using data (not just complaints)</p><p><b>Take Action:</b></p><p>→ Reflect on your own compliance program: Is it outcome-driven or check-the-box?<br/> → Re-evaluate how your GRC, security, and engineering teams collaborate<br/> → Share this episode with teammates who care about making compliance actually matter</p><p>👉 Follow <em>Security &amp; GRC Decoded</em> for fresh insights on how to make your GRC program faster, smarter, and more resilient.</p><p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by <a href='https://www.compliancecow.com'>ComplianceCow</a>. Discover how ComplianceCow helps teams move from reactive compliance to proactive control automation.</p><p>🚀 Liking the show? Leave a rating and review to help us grow and keep bringing you bold GRC conversations.</p><p>💬 Connect with Adam Brennick:<br/> 💼 LinkedIn: <a href='https://www.linkedin.com/in/adambrennick/'>https://www.linkedin.com/in/adam-brennick-959352158/</a><br/> 🌐 Company: <a href='https://www.cockroachlabs.com/'>https://www.cockroachlabs.com/</a></p>]]></description>
    <content:encoded><![CDATA[<p><b>Is it time to rethink SOC 2? (Spoiler: Adam thinks so—and he’s got the receipts.)</b><br/> In this insightful episode of <em>Security &amp; GRC Decoded</em>, <a href='https://www.linkedin.com/in/adam-brennick-959352158/'><b>Adam Brennick</b></a>, Director of Security Risk &amp; Compliance at <a href='https://www.cockroachlabs.com/'><b>Cockroach Labs</b></a>, joins Raj to challenge the status quo of <b>SOC 2</b>, <b>compliance culture</b>, and <b>how GRC teams should operate in a modern, engineering-driven world</b>.</p><p>With a unique perspective from leading both security and GRC functions, Adam shares why today’s compliance efforts often miss the mark—and how we can fix that. From his hot takes on “a la carte” SOC 2 to building automation-first programs that actually reduce risk, Adam brings clarity, conviction, and practical wisdom to the mic.</p><p><b>Key Takeaways:</b></p><p>✅ Why SOC 2 should be customizable—and how that shift would improve both trust and transparency<br/> ✅ How GRC, security, and trust functions intersect (and where they often break down)<br/> ✅ The role of “vibe coding” and AI in enabling GRC engineering<br/> ✅ Real-world strategies for building a balanced, high-impact GRC team<br/> ✅ How to make a bulletproof business case for compliance automation using data (not just complaints)</p><p><b>Take Action:</b></p><p>→ Reflect on your own compliance program: Is it outcome-driven or check-the-box?<br/> → Re-evaluate how your GRC, security, and engineering teams collaborate<br/> → Share this episode with teammates who care about making compliance actually matter</p><p>👉 Follow <em>Security &amp; GRC Decoded</em> for fresh insights on how to make your GRC program faster, smarter, and more resilient.</p><p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by <a href='https://www.compliancecow.com'>ComplianceCow</a>. Discover how ComplianceCow helps teams move from reactive compliance to proactive control automation.</p><p>🚀 Liking the show? Leave a rating and review to help us grow and keep bringing you bold GRC conversations.</p><p>💬 Connect with Adam Brennick:<br/> 💼 LinkedIn: <a href='https://www.linkedin.com/in/adambrennick/'>https://www.linkedin.com/in/adam-brennick-959352158/</a><br/> 🌐 Company: <a href='https://www.cockroachlabs.com/'>https://www.cockroachlabs.com/</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17238903-no-more-compliance-theater-meet-real-security-compliance-with-adam-brennick.mp3" length="57293943" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17238903</guid>
    <pubDate>Thu, 29 May 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17238903/transcript" type="text/html" />
    <itunes:duration>4771</itunes:duration>
    <itunes:keywords>GRC, SOC 2, compliance automation, security engineering, Cockroach Labs, Adam Brennick, Raj Krishnamurthy, security and compliance, GRC engineering, control automation, trust and assurance, risk management, audit readiness, security outcomes, vibe coding,</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Can Compliance Be Cool? Harness&#39;s Andrew Spangler Thinks So</itunes:title>
    <title>Can Compliance Be Cool? Harness&#39;s Andrew Spangler Thinks So</title>
    <itunes:summary><![CDATA[In this episode of Security and GRC Decoded, Raj Krishnamurthy sits down with Andrew Spangler, Director of Security and GRC at Harness, to explore how compliance engineering can go far beyond checkboxes—and actually drive innovation. Andrew shares his journey from building the compliance engineering function at Datadog to scaling automation and visibility across the SDLC at Harness. He dives into how using internal platforms for security workflows (aka “drinking your own champagne”) can unloc...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode of </b><b><em>Security and GRC Decoded</em></b><b>, Raj Krishnamurthy sits down with </b><a href='https://www.linkedin.com/in/atspangler/'><b>Andrew Spangler</b></a><b>, Director of Security and GRC at </b><a href='https://www.harness.io/'><b>Harness</b></a><b>, to explore how compliance engineering can go far beyond checkboxes—and actually drive innovation.</b></p><p><b>Andrew shares his journey from building the compliance engineering function at Datadog to scaling automation and visibility across the SDLC at Harness. He dives into how using internal platforms for security workflows (aka “drinking your own champagne”) can unlock time savings and risk reduction, especially in areas like vulnerability management and secure software delivery.</b></p><p><b><br/>Key Takeaways:<br/></b><br/></p><p><b>✅ How compliance automation builds credibility and supports innovation.</b></p><p><b>✅ Lessons from building compliance engineering at Datadog.</b></p><p><b>✅ Harnessing the power of SBOMs and supply chain security.</b></p><p><b>✅ Practical uses of generative AI and ChatGPT for GRC workflows.</b></p><p><b>✅ The future of democratized threat modeling.</b></p><p><b>✅ Advice for new grads entering security and GRC.</b></p><p><b>✅ Podcast recommendations that go beyond the security bubble.</b></p><p><b>Whether you&apos;re leading a GRC team or just getting started in the field, this conversation will expand how you think about security, compliance, and the role of curiosity in technical leadership.</b></p><p><b>Listen now to learn how modern GRC teams are shaping the future of secure software delivery.<br/><br/></b><br/></p><p><b>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</b></p><p><a href='https://www.compliancecow.com/'><b>Learn More About How ComplianceCow Can Help Your GRC Team Today!<br/></b></a><b>Click Here 👉https://www.compliancecow.com/</b></p><p><b>🚀 Enjoying The Show?! 🚀</b></p><p><b>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</b></p><p><b>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</b></p><p><b><br/>Learn More / Connect with Andrew Spangler<br/></b><br/></p><p><b>If you enjoyed this conversation and want to learn more about Andrew Spangler, connect with him directly:</b></p><p><b>💼 LinkedIn:</b><a href='https://www.linkedin.com/in/atspangler/'><b> https://www.linkedin.com/in/atspangler/<br/></b></a><b>🌐 Company:</b><a href='https://www.headspace.com/'><b> </b></a><a href='https://www.harness.io/'><b>https://www.harness.io/</b></a></p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode of </b><b><em>Security and GRC Decoded</em></b><b>, Raj Krishnamurthy sits down with </b><a href='https://www.linkedin.com/in/atspangler/'><b>Andrew Spangler</b></a><b>, Director of Security and GRC at </b><a href='https://www.harness.io/'><b>Harness</b></a><b>, to explore how compliance engineering can go far beyond checkboxes—and actually drive innovation.</b></p><p><b>Andrew shares his journey from building the compliance engineering function at Datadog to scaling automation and visibility across the SDLC at Harness. He dives into how using internal platforms for security workflows (aka “drinking your own champagne”) can unlock time savings and risk reduction, especially in areas like vulnerability management and secure software delivery.</b></p><p><b><br/>Key Takeaways:<br/></b><br/></p><p><b>✅ How compliance automation builds credibility and supports innovation.</b></p><p><b>✅ Lessons from building compliance engineering at Datadog.</b></p><p><b>✅ Harnessing the power of SBOMs and supply chain security.</b></p><p><b>✅ Practical uses of generative AI and ChatGPT for GRC workflows.</b></p><p><b>✅ The future of democratized threat modeling.</b></p><p><b>✅ Advice for new grads entering security and GRC.</b></p><p><b>✅ Podcast recommendations that go beyond the security bubble.</b></p><p><b>Whether you&apos;re leading a GRC team or just getting started in the field, this conversation will expand how you think about security, compliance, and the role of curiosity in technical leadership.</b></p><p><b>Listen now to learn how modern GRC teams are shaping the future of secure software delivery.<br/><br/></b><br/></p><p><b>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</b></p><p><a href='https://www.compliancecow.com/'><b>Learn More About How ComplianceCow Can Help Your GRC Team Today!<br/></b></a><b>Click Here 👉https://www.compliancecow.com/</b></p><p><b>🚀 Enjoying The Show?! 🚀</b></p><p><b>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</b></p><p><b>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</b></p><p><b><br/>Learn More / Connect with Andrew Spangler<br/></b><br/></p><p><b>If you enjoyed this conversation and want to learn more about Andrew Spangler, connect with him directly:</b></p><p><b>💼 LinkedIn:</b><a href='https://www.linkedin.com/in/atspangler/'><b> https://www.linkedin.com/in/atspangler/<br/></b></a><b>🌐 Company:</b><a href='https://www.headspace.com/'><b> </b></a><a href='https://www.harness.io/'><b>https://www.harness.io/</b></a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17162317-can-compliance-be-cool-harness-s-andrew-spangler-thinks-so.mp3" length="39388538" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17162317</guid>
    <pubDate>Thu, 15 May 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17162317/transcript" type="text/html" />
    <itunes:duration>3278</itunes:duration>
    <itunes:keywords>GenAI Security, Compliance Engineering, Automation GRC, Risk Management, SBOMs, Supply Chain Security, AI in Security, Competitive Advantage Compliance, Scalable Security, Compliance Engineers, Datadog, Harness, Software Delivery, Vulnerability Management</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Compliance to SBOMs: Josh Bressers’ Take on Security</itunes:title>
    <title>From Compliance to SBOMs: Josh Bressers’ Take on Security</title>
    <itunes:summary><![CDATA[In this episode, Raj Krishnamurthy sits down with Josh Bressers, VP of Security at Anchore and longtime leader in the open source security space. With decades of experience, Josh brings a candid and compelling perspective on everything from the chaos of early cybersecurity days to the nuanced challenges of SBOMs and compliance in today’s world. Josh reflects on how he entered the security world before there were formal certifications or programs, how community and curiosity fuel innovation in...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/joshbressers/'><b>Josh Bressers</b></a>, VP of Security at <a href='https://anchore.com/'><b>Anchore</b></a> and longtime leader in the open source security space. With decades of experience, Josh brings a candid and compelling perspective on everything from the chaos of early cybersecurity days to the nuanced challenges of SBOMs and compliance in today’s world.</p><p>Josh reflects on how he entered the security world <em>before</em> there were formal certifications or programs, how community and curiosity fuel innovation in open source, and why the relationships you build are often the most valuable asset in your career. He also dives into exciting new work with the <b>SBOM Everywhere Working Group</b> and shares how <b>GenAI</b> is helping categorize the sprawling ecosystem of SBOM tools.</p><p><b>Key Takeaways</b>:<br/>✅ GRC teams often overburden themselves with audits.</p><p>✅ Embracing a product manager mindset helps GRC teams drive security initiatives.</p><p>✅ Technical knowledge empowers GRC professionals to enhance security programs.</p><p>✅ Changing perceptions of GRC within organizations is crucial for success.</p><p>✅ Proactive strategies can elevate GRC’s role and reputation.</p><p>✅ Integrating privacy into GRC frameworks strengthens compliance efforts.</p><p>✅ High Trust certification is achievable on a budget.</p><p>✅ Automation can significantly improve GRC efficiency and reduce redundancy.</p><p>✅ Overlapping audit timelines minimizes disruption and streamlines processes.</p><p>✅ Discipline from endurance sports fosters focus, resilience, and growth.</p><p>🎙️ <b>Security &amp; GRC Decoded</b> is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a>.</p><p><a href='https://www.compliancecow.com/'>Learn More About How ComplianceCow Can Help Your GRC Team Today!</a></p><p>🚀 <b>Enjoying The Show?!</b> 🚀</p><p>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p><p>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p><p><b>Learn More / Connect with Josh Bressers:</b><br/>If you enjoyed this conversation and want to dive deeper into Josh Bressers’s insights on GRC, cybersecurity, and building effective security programs, connect with him directly:</p><p>💼 LinkedIn:<a href='https://www.linkedin.com/in/shobhitmehta/'> https://www.linkedin.com/in/joshbressers/<br/></a>🌐 Company:<a href='https://www.headspace.com/'> </a><a href='https://anchore.com/'>https://anchore.com/</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, <b>Raj Krishnamurthy</b> sits down with <a href='https://www.linkedin.com/in/joshbressers/'><b>Josh Bressers</b></a>, VP of Security at <a href='https://anchore.com/'><b>Anchore</b></a> and longtime leader in the open source security space. With decades of experience, Josh brings a candid and compelling perspective on everything from the chaos of early cybersecurity days to the nuanced challenges of SBOMs and compliance in today’s world.</p><p>Josh reflects on how he entered the security world <em>before</em> there were formal certifications or programs, how community and curiosity fuel innovation in open source, and why the relationships you build are often the most valuable asset in your career. He also dives into exciting new work with the <b>SBOM Everywhere Working Group</b> and shares how <b>GenAI</b> is helping categorize the sprawling ecosystem of SBOM tools.</p><p><b>Key Takeaways</b>:<br/>✅ GRC teams often overburden themselves with audits.</p><p>✅ Embracing a product manager mindset helps GRC teams drive security initiatives.</p><p>✅ Technical knowledge empowers GRC professionals to enhance security programs.</p><p>✅ Changing perceptions of GRC within organizations is crucial for success.</p><p>✅ Proactive strategies can elevate GRC’s role and reputation.</p><p>✅ Integrating privacy into GRC frameworks strengthens compliance efforts.</p><p>✅ High Trust certification is achievable on a budget.</p><p>✅ Automation can significantly improve GRC efficiency and reduce redundancy.</p><p>✅ Overlapping audit timelines minimizes disruption and streamlines processes.</p><p>✅ Discipline from endurance sports fosters focus, resilience, and growth.</p><p>🎙️ <b>Security &amp; GRC Decoded</b> is brought to you by <a href='https://www.compliancecow.com/'><b>ComplianceCow</b></a>.</p><p><a href='https://www.compliancecow.com/'>Learn More About How ComplianceCow Can Help Your GRC Team Today!</a></p><p>🚀 <b>Enjoying The Show?!</b> 🚀</p><p>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p><p>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p><p><b>Learn More / Connect with Josh Bressers:</b><br/>If you enjoyed this conversation and want to dive deeper into Josh Bressers’s insights on GRC, cybersecurity, and building effective security programs, connect with him directly:</p><p>💼 LinkedIn:<a href='https://www.linkedin.com/in/shobhitmehta/'> https://www.linkedin.com/in/joshbressers/<br/></a>🌐 Company:<a href='https://www.headspace.com/'> </a><a href='https://anchore.com/'>https://anchore.com/</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17075846-from-compliance-to-sboms-josh-bressers-take-on-security.mp3" length="47415545" type="audio/mpeg" />
    <link>https://www.compliancecow.com/podcast/</link>
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17075846</guid>
    <pubDate>Thu, 01 May 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17075846/transcript" type="text/html" />
    <itunes:duration>3947</itunes:duration>
    <itunes:keywords>Josh Bressers, Security, Cybersecurity, Open Source, SBOM, GUAC, Grype, Red Hat, AI, GenAI, GRC, Compliance, Anchore, Podcast, Software Bill of Materials, OpenSSF, Tech, Technology, Culture, Security Culture, Policy Summarization, Community, Syft, SBOM Ev</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Cruise to Whatnot: Kieran Pierman’s GRC Playbook</itunes:title>
    <title>From Cruise to Whatnot: Kieran Pierman’s GRC Playbook</title>
    <itunes:summary><![CDATA[In this episode, Raj Krishnamurthy sits down with Kieran Pierman, GRC &amp; Security at Whatnot, and a former security, risk and compliance leader at Cruise and Dropbox, to explore fresh perspectives on Security &amp; GRC.  Kieran opens with a bold stance: data breaches, while critical, aren't the top threat they used to be. Instead, he argues, maintaining availability and service uptime is now paramount. Drawing from his unique experience building the foundational GRC program at Cruise, a pi...]]></itunes:summary>
    <description><![CDATA[<p data-pm-slice='1 1 []'>In this episode, <strong>Raj Krishnamurthy</strong> sits down with <a href='https://www.linkedin.com/in/kieranpierman/'>Kieran Pierman</a>, <strong>GRC &amp; Security</strong> at <a href='https://www.whatnot.com/'>Whatnot</a>, and a former security, risk and compliance leader at <strong>Cruise</strong> and <strong>Dropbox</strong>, to explore fresh perspectives on <strong>Security &amp; GRC</strong>.</p> <p>Kieran opens with a bold stance: data breaches, while critical, aren&apos;t the top threat they used to be. Instead, he argues, maintaining availability and service uptime is now paramount. Drawing from his unique experience building the foundational GRC program at Cruise, a pioneering self-driving car company, Kieran reveals how managing cybersecurity risks took on profound urgency—literally life-and-death implications—when securing autonomous vehicles.</p> <p>Throughout the conversation, Kieran shares actionable insights on:</p> <p>✅ Why availability and uptime are today&apos;s most critical security priorities.</p> <p>✅ How building GRC at Cruise required an uncompromising security posture due to the potential consequences of vehicle security breaches.</p> <p>✅ Why GRC should be seen as an engineering discipline rather than a checkbox function.</p> <p>✅ Practical strategies to shift GRC from a cost center to a profit-driving role.</p> <p>✅ The importance of automation, technical fluency, and proactive risk management.</p> <p>✅ Balancing preventative and detective controls to optimize both security and business agility.</p> <p> ✅ Tips on working effectively with auditors to enhance, rather than hinder, security maturity.</p> <p><em>Tune in to learn how adopting a proactive, engineering-minded approach can elevate your GRC program from compliance-driven to business-critical.</em></p> <p>🎙️ <strong><em>Security &amp; GRC Decoded</em></strong> is brought to you by <strong>ComplianceCow</strong>.</p> <p><a href='https://www.compliancecow.com/'>Learn how ComplianceCow can enhance your GRC efforts today!</a></p> <p>🚀 <strong>Enjoying the Show?!</strong> 🚀</p> <p>Don&apos;t forget to rate, review, and subscribe to ensure you don&apos;t miss out on expert insights from industry leaders shaping the future of security and compliance.</p> <div> <hr></hr></div> <p><strong>Learn More / Connect with Kieran Pierman</strong></p> <p>💼 LinkedIn: <a href='https://www.linkedin.com/in/kieranpierman/'>Kieran Pierman</a> <br/> 🌐 Company: <a href='https://www.whatnot.com/'>Whatnot</a></p>]]></description>
    <content:encoded><![CDATA[<p data-pm-slice='1 1 []'>In this episode, <strong>Raj Krishnamurthy</strong> sits down with <a href='https://www.linkedin.com/in/kieranpierman/'>Kieran Pierman</a>, <strong>GRC &amp; Security</strong> at <a href='https://www.whatnot.com/'>Whatnot</a>, and a former security, risk and compliance leader at <strong>Cruise</strong> and <strong>Dropbox</strong>, to explore fresh perspectives on <strong>Security &amp; GRC</strong>.</p> <p>Kieran opens with a bold stance: data breaches, while critical, aren&apos;t the top threat they used to be. Instead, he argues, maintaining availability and service uptime is now paramount. Drawing from his unique experience building the foundational GRC program at Cruise, a pioneering self-driving car company, Kieran reveals how managing cybersecurity risks took on profound urgency—literally life-and-death implications—when securing autonomous vehicles.</p> <p>Throughout the conversation, Kieran shares actionable insights on:</p> <p>✅ Why availability and uptime are today&apos;s most critical security priorities.</p> <p>✅ How building GRC at Cruise required an uncompromising security posture due to the potential consequences of vehicle security breaches.</p> <p>✅ Why GRC should be seen as an engineering discipline rather than a checkbox function.</p> <p>✅ Practical strategies to shift GRC from a cost center to a profit-driving role.</p> <p>✅ The importance of automation, technical fluency, and proactive risk management.</p> <p>✅ Balancing preventative and detective controls to optimize both security and business agility.</p> <p> ✅ Tips on working effectively with auditors to enhance, rather than hinder, security maturity.</p> <p><em>Tune in to learn how adopting a proactive, engineering-minded approach can elevate your GRC program from compliance-driven to business-critical.</em></p> <p>🎙️ <strong><em>Security &amp; GRC Decoded</em></strong> is brought to you by <strong>ComplianceCow</strong>.</p> <p><a href='https://www.compliancecow.com/'>Learn how ComplianceCow can enhance your GRC efforts today!</a></p> <p>🚀 <strong>Enjoying the Show?!</strong> 🚀</p> <p>Don&apos;t forget to rate, review, and subscribe to ensure you don&apos;t miss out on expert insights from industry leaders shaping the future of security and compliance.</p> <div> <hr></hr></div> <p><strong>Learn More / Connect with Kieran Pierman</strong></p> <p>💼 LinkedIn: <a href='https://www.linkedin.com/in/kieranpierman/'>Kieran Pierman</a> <br/> 🌐 Company: <a href='https://www.whatnot.com/'>Whatnot</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022587-from-cruise-to-whatnot-kieran-pierman-s-grc-playbook.mp3" length="45207458" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">d6d71e16-61ec-452f-b3bd-251b93018644</guid>
    <pubDate>Thu, 17 Apr 2025 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17022587/transcript" type="text/html" />
    <itunes:duration>3763</itunes:duration>
    <itunes:keywords>security,automation,compliance,cruise,audits,cybersecurity,availability,GRC,uptime,auditors,Risk Management,data breach,autonomous vehicles,incident response,self-driving cars,security engineering,security culture,proactive security,SOC 2</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Is Your GRC Team Technical Enough? (Probably Not...) ft. Jeevan Singh @ Rippling</itunes:title>
    <title>Is Your GRC Team Technical Enough? (Probably Not...) ft. Jeevan Singh @ Rippling</title>
    <itunes:summary><![CDATA[Ever wondered if your GRC team should be writing code? (Spoiler alert: Jeevan thinks they probably should.) In this eye-opening episode of Security &amp; GRC Decoded, Jeevan Singh, Director of Security Engineering at Rippling, joins Raj to challenge traditional views of Governance, Risk, and Compliance (GRC).  Jeevan passionately argues why GRC teams must become more technical, automated, and deeply integrated into engineering processes to truly protect and enable businesses. Drawing from his...]]></itunes:summary>
    <description><![CDATA[<p data-pm-slice='1 1 []'>Ever wondered if your GRC team should be writing code? (Spoiler alert: Jeevan thinks they probably should.) In this eye-opening episode of Security &amp; GRC Decoded, Jeevan Singh, Director of Security Engineering at Rippling, joins Raj to challenge traditional views of Governance, Risk, and Compliance (GRC).</p> <p>Jeevan passionately argues why GRC teams must become more technical, automated, and deeply integrated into engineering processes to truly protect and enable businesses. Drawing from his experience at Segment and Rippling, he provides actionable insights and real-world examples to transform compliance from a bureaucratic burden into a proactive, engineering-driven function.</p> <p><strong>Key Takeaways:</strong></p> <p>✅ Why having technical GRC teams leads to dramatically stronger security outcomes</p> <p>✅ How automating compliance tasks can eliminate toil and boost productivity</p> <p>✅ Practical steps to shift your compliance culture from reactive to proactive</p> <p>✅ The real difference between CVSS and CWSS vulnerability scoring systems</p> <p>✅ Strategies for fostering productive friction between GRC and engineering teams</p> <p><strong>Take Action:</strong></p> <ul data-spread='false'> <li> <p>Assess your own GRC team’s technical depth: Could automation improve your compliance posture?</p> </li> <li> <p>Discuss these insights with your security and engineering leaders</p> </li> <li> <p>Share this episode with your team and spark important conversations around GRC innovation</p> </li> </ul> <p data-pm-slice='1 1 []'>👉 <strong>Follow Security &amp; GRC Decoded</strong> to stay ahead on the latest insights and trends in security, compliance, and risk management.</p> <p>🎙️ <strong>Security &amp; GRC Decoded</strong> is brought to you by <a href='https://compliancecow.com'>ComplianceCow</a>. Learn how ComplianceCow can elevate your GRC team today!</p> <p>🚀 <strong>Enjoying The Show?</strong> Rate and review the podcast to support the show and let us know you&apos;re enjoying the content!</p> <p>💬 <strong>Connect with Jeevan Singh:</strong> </p> <p data-start='230' data-end='323'>💼 <strong data-start='233' data-end='246'>LinkedIn:</strong> <a href='https://www.linkedin.com/in/jeevansecurity/' data-start='247' data-end='264'>https://www.linkedin.com/in/jeevansecurity/</a><br data-start='264' data-end='267'/> 🌐 <strong data-start='270' data-end='282'>Company:</strong> <a href='https://www.rippling.com/'>https://www.rippling.com/</a></p>]]></description>
    <content:encoded><![CDATA[<p data-pm-slice='1 1 []'>Ever wondered if your GRC team should be writing code? (Spoiler alert: Jeevan thinks they probably should.) In this eye-opening episode of Security &amp; GRC Decoded, Jeevan Singh, Director of Security Engineering at Rippling, joins Raj to challenge traditional views of Governance, Risk, and Compliance (GRC).</p> <p>Jeevan passionately argues why GRC teams must become more technical, automated, and deeply integrated into engineering processes to truly protect and enable businesses. Drawing from his experience at Segment and Rippling, he provides actionable insights and real-world examples to transform compliance from a bureaucratic burden into a proactive, engineering-driven function.</p> <p><strong>Key Takeaways:</strong></p> <p>✅ Why having technical GRC teams leads to dramatically stronger security outcomes</p> <p>✅ How automating compliance tasks can eliminate toil and boost productivity</p> <p>✅ Practical steps to shift your compliance culture from reactive to proactive</p> <p>✅ The real difference between CVSS and CWSS vulnerability scoring systems</p> <p>✅ Strategies for fostering productive friction between GRC and engineering teams</p> <p><strong>Take Action:</strong></p> <ul data-spread='false'> <li> <p>Assess your own GRC team’s technical depth: Could automation improve your compliance posture?</p> </li> <li> <p>Discuss these insights with your security and engineering leaders</p> </li> <li> <p>Share this episode with your team and spark important conversations around GRC innovation</p> </li> </ul> <p data-pm-slice='1 1 []'>👉 <strong>Follow Security &amp; GRC Decoded</strong> to stay ahead on the latest insights and trends in security, compliance, and risk management.</p> <p>🎙️ <strong>Security &amp; GRC Decoded</strong> is brought to you by <a href='https://compliancecow.com'>ComplianceCow</a>. Learn how ComplianceCow can elevate your GRC team today!</p> <p>🚀 <strong>Enjoying The Show?</strong> Rate and review the podcast to support the show and let us know you&apos;re enjoying the content!</p> <p>💬 <strong>Connect with Jeevan Singh:</strong> </p> <p data-start='230' data-end='323'>💼 <strong data-start='233' data-end='246'>LinkedIn:</strong> <a href='https://www.linkedin.com/in/jeevansecurity/' data-start='247' data-end='264'>https://www.linkedin.com/in/jeevansecurity/</a><br data-start='264' data-end='267'/> 🌐 <strong data-start='270' data-end='282'>Company:</strong> <a href='https://www.rippling.com/'>https://www.rippling.com/</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022590-is-your-grc-team-technical-enough-probably-not-ft-jeevan-singh-rippling.mp3" length="50325527" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">9609c446-a195-4f6d-81e4-09157b9bf337</guid>
    <pubDate>Thu, 03 Apr 2025 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17022590/transcript" type="text/html" />
    <itunes:duration>4190</itunes:duration>
    <itunes:keywords>automation,compliance,cybersecurity,GRC,Rippling,CVSS,Risk Management,Security Training,Security Leadership,Vulnerability Management,security engineering,security culture,Threat Modeling,Security  GRC Decoded,Security Podcast,Raj Krishnamurthy</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why GRC Teams Are Failing — And How to Fix It with Shobhit Mehta</itunes:title>
    <title>Why GRC Teams Are Failing — And How to Fix It with Shobhit Mehta</title>
    <itunes:summary><![CDATA[In this episode, Raj Krishnamurthy interviews Shobhit Mehta, Director of Security and Compliance at Headspace, to uncover valuable insights into the evolving world of Governance, Risk, and Compliance (GRC). Shobhit shares his controversial perspective on GRC teams overburdening themselves, emphasizing the need for GRC professionals to expand their technical expertise and embrace a product management mindset.  The conversation dives into proactive strategies for GRC success, the importance of ...]]></itunes:summary>
    <description><![CDATA[<p data-start='141' data-end='551'>In this episode, Raj Krishnamurthy interviews <a href='https://www.linkedin.com/in/shobhitmehta/'>Shobhit Mehta</a>, Director of Security and Compliance at <a href='https://www.headspace.com/'>Headspace</a>, to uncover valuable insights into the evolving world of Governance, Risk, and Compliance (GRC). Shobhit shares his controversial perspective on GRC teams overburdening themselves, emphasizing the need for GRC professionals to expand their technical expertise and embrace a product management mindset.</p> <p data-start='553' data-end='911'>The conversation dives into proactive strategies for GRC success, the importance of integrating privacy into compliance frameworks, and actionable tips for achieving High Trust certification on a budget. Shobhit also reflects on how his endurance sports journey has shaped his approach to discipline and resilience in both his personal and professional life.</p> <p data-start='913' data-end='1012'>Tune in to learn how automation, innovation, and strategic thinking can transform your GRC efforts.</p> <h3 data-start='1014' data-end='1038'><strong data-start='1018' data-end='1036'>Key Takeaways:</strong></h3> <p data-start='1039' data-end='1812'>✅ <span class='MuiTypography-root MuiTypography-bodyMedium css-9y6kil e1de0imv0'>GRC teams often overburden themselves with audits.<br/></span></p> <p data-start='1039' data-end='1812'>✅ Embracing a product manager mindset helps GRC teams drive security initiatives.</p> <p data-start='1039' data-end='1812'>✅ Technical knowledge empowers GRC professionals to enhance security programs.</p> <p data-start='1039' data-end='1812'>✅ Changing perceptions of GRC within organizations is crucial for success.</p> <p data-start='1039' data-end='1812'>✅ Proactive strategies can elevate GRC’s role and reputation.</p> <p data-start='1039' data-end='1812'>✅ Integrating privacy into GRC frameworks strengthens compliance efforts.</p> <p data-start='1039' data-end='1812'>✅ High Trust certification is achievable on a budget.</p> <p data-start='1039' data-end='1812'>✅ Automation can significantly improve GRC efficiency and reduce redundancy.</p> <p data-start='1039' data-end='1812'>✅ Overlapping audit timelines minimizes disruption and streamlines processes.</p> <p data-start='1039' data-end='1812'>✅ Discipline from endurance sports fosters focus, resilience, and growth.</p> <p data-start='1814' data-end='1887' data-is-last-node='' data-is-only-node=''><strong data-start='1814' data-end='1887' data-is-last-node=''>Listen now to gain actionable insights and elevate your GRC strategy.<br/> <br/></strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'><a href='https://www.compliancecow.com/'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'><strong data-start='1746' data-end='1814' data-is-last-node=''>🚀 Enjoying The Show?! 🚀</strong></strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <h3 data-start='0' data-end='48'><span style='font-size: 12pt;'><strong data-start='4' data-end='46'>Learn More / Connect with Shobhit Mehta</strong></span></h3> <p data-start='49' data-end='228'>If you enjoyed this conversation and want to dive deeper into Shobit Mehta’s insights on GRC, cybersecurity, and building effective security programs, connect with him directly:</p> <p data-start='230' data-end='323'>💼 <strong data-start='233' data-end='246'>LinkedIn:</strong></p>]]></description>
    <content:encoded><![CDATA[<p data-start='141' data-end='551'>In this episode, Raj Krishnamurthy interviews <a href='https://www.linkedin.com/in/shobhitmehta/'>Shobhit Mehta</a>, Director of Security and Compliance at <a href='https://www.headspace.com/'>Headspace</a>, to uncover valuable insights into the evolving world of Governance, Risk, and Compliance (GRC). Shobhit shares his controversial perspective on GRC teams overburdening themselves, emphasizing the need for GRC professionals to expand their technical expertise and embrace a product management mindset.</p> <p data-start='553' data-end='911'>The conversation dives into proactive strategies for GRC success, the importance of integrating privacy into compliance frameworks, and actionable tips for achieving High Trust certification on a budget. Shobhit also reflects on how his endurance sports journey has shaped his approach to discipline and resilience in both his personal and professional life.</p> <p data-start='913' data-end='1012'>Tune in to learn how automation, innovation, and strategic thinking can transform your GRC efforts.</p> <h3 data-start='1014' data-end='1038'><strong data-start='1018' data-end='1036'>Key Takeaways:</strong></h3> <p data-start='1039' data-end='1812'>✅ <span class='MuiTypography-root MuiTypography-bodyMedium css-9y6kil e1de0imv0'>GRC teams often overburden themselves with audits.<br/></span></p> <p data-start='1039' data-end='1812'>✅ Embracing a product manager mindset helps GRC teams drive security initiatives.</p> <p data-start='1039' data-end='1812'>✅ Technical knowledge empowers GRC professionals to enhance security programs.</p> <p data-start='1039' data-end='1812'>✅ Changing perceptions of GRC within organizations is crucial for success.</p> <p data-start='1039' data-end='1812'>✅ Proactive strategies can elevate GRC’s role and reputation.</p> <p data-start='1039' data-end='1812'>✅ Integrating privacy into GRC frameworks strengthens compliance efforts.</p> <p data-start='1039' data-end='1812'>✅ High Trust certification is achievable on a budget.</p> <p data-start='1039' data-end='1812'>✅ Automation can significantly improve GRC efficiency and reduce redundancy.</p> <p data-start='1039' data-end='1812'>✅ Overlapping audit timelines minimizes disruption and streamlines processes.</p> <p data-start='1039' data-end='1812'>✅ Discipline from endurance sports fosters focus, resilience, and growth.</p> <p data-start='1814' data-end='1887' data-is-last-node='' data-is-only-node=''><strong data-start='1814' data-end='1887' data-is-last-node=''>Listen now to gain actionable insights and elevate your GRC strategy.<br/> <br/></strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'><a href='https://www.compliancecow.com/'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></strong></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'><strong data-start='1746' data-end='1814' data-is-last-node=''>🚀 Enjoying The Show?! 🚀</strong></strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <h3 data-start='0' data-end='48'><span style='font-size: 12pt;'><strong data-start='4' data-end='46'>Learn More / Connect with Shobhit Mehta</strong></span></h3> <p data-start='49' data-end='228'>If you enjoyed this conversation and want to dive deeper into Shobit Mehta’s insights on GRC, cybersecurity, and building effective security programs, connect with him directly:</p> <p data-start='230' data-end='323'>💼 <strong data-start='233' data-end='246'>LinkedIn:</strong></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022626-why-grc-teams-are-failing-and-how-to-fix-it-with-shobhit-mehta.mp3" length="40149338" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">0755ce84-10c9-4826-b862-9016f77cfbbc</guid>
    <pubDate>Thu, 20 Mar 2025 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17022626/transcript" type="text/html" />
    <itunes:duration>3342</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab</itunes:title>
    <title>Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy (CEO of ComplianceCow) sits down with Ayoub Fandi, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of GRC through an engineering lens. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing real-time data, automation, and developer-friendly p...]]></itunes:summary>
    <description><![CDATA[<p data-start='0' data-end='615'>In this episode of <em data-start='45' data-end='69'>Security &amp; GRC Decoded</em>, host <strong data-start='76' data-end='97'>Raj Krishnamurthy</strong> (CEO of ComplianceCow) sits down with <a href='https://www.linkedin.com/in/ayoubfandi/'><strong data-start='136' data-end='151'>Ayoub Fandi</strong></a>, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of <strong data-start='285' data-end='320' data-is-only-node=''>GRC through an engineering lens</strong>. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing <strong data-start='481' data-end='512'>real-time data, automation,</strong> and <strong data-start='517' data-end='549'>developer-friendly processes</strong> is the key to building stronger security and compliance programs.</p> <p data-start='617' data-end='1002'>He also reveals his <em data-start='637' data-end='652'>controversial</em> perspective on external certifications—explaining why they can sometimes feel overrated—and makes the case for <strong data-start='764' data-end='800'>continuous, risk-based assurance</strong> that truly reflects an organization’s security posture. If you’ve ever felt the “cognitive dissonance” of outdated compliance controls in a modern engineering world, this conversation is a must-listen.</p> <p data-start='1004' data-end='1770'><strong data-start='1004' data-end='1021'>Key Takeaways</strong><br data-start='1021' data-end='1024'/> ✅ <strong data-start='1026' data-end='1063'>Bridging the Gap with Engineering</strong>: How GRC teams can embed themselves into developers’ workflows (e.g., JIRA, pull requests) to gain more accurate data and achieve real-time compliance insights.<br data-start='1224' data-end='1227'/> ✅ <strong data-start='1229' data-end='1261'>Continuous vs. Annual Audits</strong>: The advantages of leveraging APIs and automation to monitor control effectiveness in near real-time, instead of relying on point-in-time evidence.<br data-start='1409' data-end='1412'/> ✅ <strong data-start='1414' data-end='1452'>Rethinking External Certifications</strong>: Why these certifications can be a misleading representation of true security and how GRC professionals can ensure audits deliver real value.<br data-start='1594' data-end='1597'/> ✅ <strong data-start='1599' data-end='1632'>Building a Modern GRC Program</strong>: Practical tips on designing policies and controls that align with fast-paced, cloud-native environments—minus the “waterfall mentality.”</p> <p data-start='1772' data-end='1999'>Tune in to hear why <strong data-start='1792' data-end='1811'>GRC must evolve</strong> alongside today’s DevOps-driven world, and how you can unlock greater efficiency, credibility, and trust by adopting an <strong data-start='1932' data-end='1962'>engineering-first approach</strong> to governance, risk, and compliance.<br/> <br/></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p data-start='1746' data-end='1814' data-is-last-node=''><a href='https://www.compliancecow.com/'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></p> <p data-start='5' data-end='203'><strong data-start='5' data-end='30'><strong data-start='1577' data-end='1643'>🎙️</strong> Follow Ayoub Fandi:</strong><br data-start='30' data-end='33'/> Stay connected with Carlos’s insights and experiences by following him on LinkedIn:<br data-star=''/></p>]]></description>
    <content:encoded><![CDATA[<p data-start='0' data-end='615'>In this episode of <em data-start='45' data-end='69'>Security &amp; GRC Decoded</em>, host <strong data-start='76' data-end='97'>Raj Krishnamurthy</strong> (CEO of ComplianceCow) sits down with <a href='https://www.linkedin.com/in/ayoubfandi/'><strong data-start='136' data-end='151'>Ayoub Fandi</strong></a>, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of <strong data-start='285' data-end='320' data-is-only-node=''>GRC through an engineering lens</strong>. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing <strong data-start='481' data-end='512'>real-time data, automation,</strong> and <strong data-start='517' data-end='549'>developer-friendly processes</strong> is the key to building stronger security and compliance programs.</p> <p data-start='617' data-end='1002'>He also reveals his <em data-start='637' data-end='652'>controversial</em> perspective on external certifications—explaining why they can sometimes feel overrated—and makes the case for <strong data-start='764' data-end='800'>continuous, risk-based assurance</strong> that truly reflects an organization’s security posture. If you’ve ever felt the “cognitive dissonance” of outdated compliance controls in a modern engineering world, this conversation is a must-listen.</p> <p data-start='1004' data-end='1770'><strong data-start='1004' data-end='1021'>Key Takeaways</strong><br data-start='1021' data-end='1024'/> ✅ <strong data-start='1026' data-end='1063'>Bridging the Gap with Engineering</strong>: How GRC teams can embed themselves into developers’ workflows (e.g., JIRA, pull requests) to gain more accurate data and achieve real-time compliance insights.<br data-start='1224' data-end='1227'/> ✅ <strong data-start='1229' data-end='1261'>Continuous vs. Annual Audits</strong>: The advantages of leveraging APIs and automation to monitor control effectiveness in near real-time, instead of relying on point-in-time evidence.<br data-start='1409' data-end='1412'/> ✅ <strong data-start='1414' data-end='1452'>Rethinking External Certifications</strong>: Why these certifications can be a misleading representation of true security and how GRC professionals can ensure audits deliver real value.<br data-start='1594' data-end='1597'/> ✅ <strong data-start='1599' data-end='1632'>Building a Modern GRC Program</strong>: Practical tips on designing policies and controls that align with fast-paced, cloud-native environments—minus the “waterfall mentality.”</p> <p data-start='1772' data-end='1999'>Tune in to hear why <strong data-start='1792' data-end='1811'>GRC must evolve</strong> alongside today’s DevOps-driven world, and how you can unlock greater efficiency, credibility, and trust by adopting an <strong data-start='1932' data-end='1962'>engineering-first approach</strong> to governance, risk, and compliance.<br/> <br/></p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p data-start='1746' data-end='1814' data-is-last-node=''><a href='https://www.compliancecow.com/'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></p> <p data-start='5' data-end='203'><strong data-start='5' data-end='30'><strong data-start='1577' data-end='1643'>🎙️</strong> Follow Ayoub Fandi:</strong><br data-start='30' data-end='33'/> Stay connected with Carlos’s insights and experiences by following him on LinkedIn:<br data-star=''/></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022627-engineering-better-relationships-why-we-should-shift-grc-left-w-ayoub-fandi-gitlab.mp3" length="37852343" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">59ddd6a8-ef9c-458a-8d81-314831d0bde7</guid>
    <pubDate>Thu, 06 Mar 2025 13:11:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17022627/transcript" type="text/html" />
    <itunes:duration>3150</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Unfiltered: Carlos Batista on GRC, Leadership, and Risk Realities</itunes:title>
    <title>Security Unfiltered: Carlos Batista on GRC, Leadership, and Risk Realities</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Carlos Batista—former CISO and AWS Security Engineering Leader—to explore the evolving landscape of security, governance, and risk management.  Carlos shares his journey from leading security in highly regulated industries like banking and energy to championing large-scale security engineering at AWS. Together, they discuss how effective GRC programs can move beyond “checkbox” complianc...]]></itunes:summary>
    <description><![CDATA[<p data-start='0' data-end='250'><strong data-start='0' data-end='250'>In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with <a href='https://www.linkedin.com/in/carlos-m-batista/'>Carlos Batista</a>—former CISO and AWS Security Engineering Leader—to explore the evolving landscape of security, governance, and risk management.</strong></p> <p data-start='252' data-end='627'>Carlos shares his journey from leading security in highly regulated industries like banking and energy to championing large-scale security engineering at AWS. Together, they discuss how effective GRC programs can move beyond “checkbox” compliance to become true business enablers—accelerating growth, deepening customer trust, and supporting innovation across the enterprise.</p> <p data-start='629' data-end='1378'><strong data-start='629' data-end='655'>Key takeaways include:</strong><br data-start='655' data-end='658'/> ✅ <strong data-start='660' data-end='707'>Security Awareness &amp; Practical Investments:</strong> Why Carlos believes traditional security awareness can be overrated, and how investing in secure-by-design infrastructure may deliver more value.<br data-start='853' data-end='856'/> ✅ <strong data-start='858' data-end='890'>Third-Party Risk Management:</strong> Insights on why TPRM remains fractured, and what it’ll take to move from endless vendor questionnaires to streamlined trust and assurance.<br data-start='1029' data-end='1032'/> ✅ <strong data-start='1034' data-end='1063'>CISO Stress &amp; Leadership:</strong> How security leaders can manage the personal and legal pressures of the role, build credibility, and foster healthy collaboration with engineering teams.<br data-start='1217' data-end='1220'/> ✅ <strong data-start='1222' data-end='1240'>Future of GRC:</strong> From infrastructure-as-code to automagically patching vulnerabilities—where Carlos sees security, compliance, and governance headed next.</p> <p data-start='1380' data-end='1575'>Tune in to hear practical insights, real-world strategies, and a fresh perspective on the intersection of security, compliance, and business success in today’s fast-changing regulatory landscape.</p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p data-start='1746' data-end='1814' data-is-last-node=''><a href='https://www.compliancecow.com'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></p> <p data-start='5' data-end='203'><strong data-start='5' data-end='30'><strong data-start='1577' data-end='1643'>🎙️</strong> Follow Carlos Batista:</strong><br data-start='30' data-end='33'/> Stay connected with Carlos’s insights and experiences by following him on LinkedIn:<br data-start='116' data-end='119'/> <a href='https://www.linkedin.com/in/carlos-m-batista/' target='_new' rel='noopener' data-start='119' data-end='201'>linkedin.com/in/carlos-m-batista/</a></p>]]></description>
    <content:encoded><![CDATA[<p data-start='0' data-end='250'><strong data-start='0' data-end='250'>In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with <a href='https://www.linkedin.com/in/carlos-m-batista/'>Carlos Batista</a>—former CISO and AWS Security Engineering Leader—to explore the evolving landscape of security, governance, and risk management.</strong></p> <p data-start='252' data-end='627'>Carlos shares his journey from leading security in highly regulated industries like banking and energy to championing large-scale security engineering at AWS. Together, they discuss how effective GRC programs can move beyond “checkbox” compliance to become true business enablers—accelerating growth, deepening customer trust, and supporting innovation across the enterprise.</p> <p data-start='629' data-end='1378'><strong data-start='629' data-end='655'>Key takeaways include:</strong><br data-start='655' data-end='658'/> ✅ <strong data-start='660' data-end='707'>Security Awareness &amp; Practical Investments:</strong> Why Carlos believes traditional security awareness can be overrated, and how investing in secure-by-design infrastructure may deliver more value.<br data-start='853' data-end='856'/> ✅ <strong data-start='858' data-end='890'>Third-Party Risk Management:</strong> Insights on why TPRM remains fractured, and what it’ll take to move from endless vendor questionnaires to streamlined trust and assurance.<br data-start='1029' data-end='1032'/> ✅ <strong data-start='1034' data-end='1063'>CISO Stress &amp; Leadership:</strong> How security leaders can manage the personal and legal pressures of the role, build credibility, and foster healthy collaboration with engineering teams.<br data-start='1217' data-end='1220'/> ✅ <strong data-start='1222' data-end='1240'>Future of GRC:</strong> From infrastructure-as-code to automagically patching vulnerabilities—where Carlos sees security, compliance, and governance headed next.</p> <p data-start='1380' data-end='1575'>Tune in to hear practical insights, real-world strategies, and a fresh perspective on the intersection of security, compliance, and business success in today’s fast-changing regulatory landscape.</p> <p data-start='1577' data-end='1744'><strong data-start='1577' data-end='1643'>🎙️ Security &amp; GRC Decoded is brought to you by ComplianceCow.</strong></p> <p data-start='1577' data-end='1744'>Make sure to rate and review the show to let us know you&apos;re enjoying the content!</p> <p data-start='1577' data-end='1744'>Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p data-start='1746' data-end='1814' data-is-last-node=''><a href='https://www.compliancecow.com'><strong data-start='1746' data-end='1814' data-is-last-node=''>Learn More About How ComplianceCow Can Help Your GRC Team Today!</strong></a></p> <p data-start='5' data-end='203'><strong data-start='5' data-end='30'><strong data-start='1577' data-end='1643'>🎙️</strong> Follow Carlos Batista:</strong><br data-start='30' data-end='33'/> Stay connected with Carlos’s insights and experiences by following him on LinkedIn:<br data-start='116' data-end='119'/> <a href='https://www.linkedin.com/in/carlos-m-batista/' target='_new' rel='noopener' data-start='119' data-end='201'>linkedin.com/in/carlos-m-batista/</a></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022628-security-unfiltered-carlos-batista-on-grc-leadership-and-risk-realities.mp3" length="45183363" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">d98c13eb-c54d-45d4-9f37-b81e795cc58f</guid>
    <pubDate>Thu, 20 Feb 2025 12:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2489040/17022628/transcript" type="text/html" />
    <itunes:duration>3761</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Navigating DeepSeek’s AI Risks: Insights for Security &amp; Compliance Teams</itunes:title>
    <title>Navigating DeepSeek’s AI Risks: Insights for Security &amp; Compliance Teams</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, Raj Krishnamurthy, CEO of ComplianceCow, sits down with Walter Haydock, CEO of StackAware, to discuss the evolving landscape of AI security, governance, risk, and compliance (GRC). Walter shares insights on emerging AI threats, the importance of ISO 42001 certification, and the challenges organizations face when integrating AI into their security and compliance programs.  Key topics include:   DeepSeek and AI Privacy Risks Regulatory Challenges i...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <em>Security &amp; GRC Decoded</em>, <strong>Raj Krishnamurthy</strong>, CEO of ComplianceCow, sits down with <strong>Walter Haydock</strong>, CEO of <strong>StackAware</strong>, to discuss the evolving landscape of <strong>AI security, governance, risk, and compliance (GRC)</strong>. Walter shares insights on emerging AI threats, the importance of <strong>ISO 42001 certification</strong>, and the challenges organizations face when integrating AI into their security and compliance programs.</p> <p>Key topics include:</p> <ul> <li><strong>DeepSeek and AI Privacy Risks</strong></li> <li><strong>Regulatory Challenges in AI Security &amp; Compliance</strong></li> <li><strong>The Intersection of AI Governance and GRC</strong></li> <li><strong>Building a Business Case for AI Security Programs</strong></li> <li><strong>How Security &amp; GRC Teams Can Adapt to Rapid AI Developments</strong></li> </ul> <p>This episode is packed with <strong>practical insights</strong> for security leaders, compliance professionals, and anyone navigating the risks and opportunities of <strong>AI-driven security</strong>.</p> <p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by ComplianceCow. Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p><a href='https://www.compliancecow.com'><strong>Learn more about ComplianceCow and how we can help your GRC teams!</strong></a><br/> <br/></p> <p>💡 <strong>Connect with Walter Haydock</strong> 💡</p> <p>For more insights on AI security, governance, and compliance, follow <strong>Walter Haydock</strong>:<br/> 🔗 <strong>LinkedIn</strong>: <a href='https://www.linkedin.com/in/walter-haydock/'>Walter Haydock</a><br/> 📖 <strong>Blog</strong>: <a href='https://blog.stackaware.com/' target='_new' rel='noopener'>Deploy Securely</a><br/> <strong>📷 Instagram</strong>: <a href='https://www.instagram.com/walter.haydock/'>@walter.haydock</a><br/>  🌐 <strong>Company Website: <a href='https://stackaware.com/'>StackAware</a></strong></p> <p>Stay updated on <strong>AI risk management, compliance automation, and emerging security threats</strong> by checking out his latest content! 🚀<br/> <br/></p> <h4><strong>⏳ Timestamps &amp; Key Moments</strong></h4> <p><strong>[00:00] – Introduction</strong></p> <ul> <li>Host <strong>Raj Krishnamurthy</strong> welcomes <strong>Walter Haydock</strong>, CEO of <strong>StackAware</strong>.</li> <li>Overview of today’s discussion: <strong>AI security, governance, and compliance trends</strong>.</li> </ul> <p><strong>[01:30] – DeepSeek Controversy &amp; AI Security Risks</strong></p> <ul> <li>What is <strong>DeepSeek</strong> and why is it concerning for <strong>AI security &amp; privacy</strong>?</li> <li>The risks of <strong>AI-generated synthetic data and compliance implications</strong>.</li> </ul> <p><strong>[04:15] – The Evolution of AI SaaS &amp; Security Challenges</strong></p> <ul> <li>The rise of <strong>AI-powered SaaS tools</strong> and the <strong>security risks they introduce</strong>.</li> <li>AI adoption <strong>without security &amp; compliance considerations</strong>.</li> </ul> <p><strong>[07:10] – Walter’s Background: From Physical Security to AI Governance</strong></p> <ul> <li>Transition from <strong>defense &amp; physical security</strong> to <strong>cybersecurity &amp; AI GRC</strong>.</li> <li>The importance of <strong>risk intelligence and automation</strong> in modern security.</li> </ul> <p><strong>[10:25] – The Intersection of AI, GRC, &amp; Security Governance</strong></p> <ul> <li>Who should own <strong>AI governance</strong>? Security teams, compliance, or legal?</li> <li>How AI <strong>challenges traditional risk management frameworks</strong>.</li> </ul> <p><strong>[13:40] – AI &amp; Compliance: The Role of ISO 42001</strong></p> <ul> <li>What is <strong>ISO 42001</strong> and how does it apply to AI governance?</li> <li>How companies can <strong>align AI security strategies with compliance</strong>.</li> </ul> <p><str></str></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <em>Security &amp; GRC Decoded</em>, <strong>Raj Krishnamurthy</strong>, CEO of ComplianceCow, sits down with <strong>Walter Haydock</strong>, CEO of <strong>StackAware</strong>, to discuss the evolving landscape of <strong>AI security, governance, risk, and compliance (GRC)</strong>. Walter shares insights on emerging AI threats, the importance of <strong>ISO 42001 certification</strong>, and the challenges organizations face when integrating AI into their security and compliance programs.</p> <p>Key topics include:</p> <ul> <li><strong>DeepSeek and AI Privacy Risks</strong></li> <li><strong>Regulatory Challenges in AI Security &amp; Compliance</strong></li> <li><strong>The Intersection of AI Governance and GRC</strong></li> <li><strong>Building a Business Case for AI Security Programs</strong></li> <li><strong>How Security &amp; GRC Teams Can Adapt to Rapid AI Developments</strong></li> </ul> <p>This episode is packed with <strong>practical insights</strong> for security leaders, compliance professionals, and anyone navigating the risks and opportunities of <strong>AI-driven security</strong>.</p> <p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by ComplianceCow. Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p><a href='https://www.compliancecow.com'><strong>Learn more about ComplianceCow and how we can help your GRC teams!</strong></a><br/> <br/></p> <p>💡 <strong>Connect with Walter Haydock</strong> 💡</p> <p>For more insights on AI security, governance, and compliance, follow <strong>Walter Haydock</strong>:<br/> 🔗 <strong>LinkedIn</strong>: <a href='https://www.linkedin.com/in/walter-haydock/'>Walter Haydock</a><br/> 📖 <strong>Blog</strong>: <a href='https://blog.stackaware.com/' target='_new' rel='noopener'>Deploy Securely</a><br/> <strong>📷 Instagram</strong>: <a href='https://www.instagram.com/walter.haydock/'>@walter.haydock</a><br/>  🌐 <strong>Company Website: <a href='https://stackaware.com/'>StackAware</a></strong></p> <p>Stay updated on <strong>AI risk management, compliance automation, and emerging security threats</strong> by checking out his latest content! 🚀<br/> <br/></p> <h4><strong>⏳ Timestamps &amp; Key Moments</strong></h4> <p><strong>[00:00] – Introduction</strong></p> <ul> <li>Host <strong>Raj Krishnamurthy</strong> welcomes <strong>Walter Haydock</strong>, CEO of <strong>StackAware</strong>.</li> <li>Overview of today’s discussion: <strong>AI security, governance, and compliance trends</strong>.</li> </ul> <p><strong>[01:30] – DeepSeek Controversy &amp; AI Security Risks</strong></p> <ul> <li>What is <strong>DeepSeek</strong> and why is it concerning for <strong>AI security &amp; privacy</strong>?</li> <li>The risks of <strong>AI-generated synthetic data and compliance implications</strong>.</li> </ul> <p><strong>[04:15] – The Evolution of AI SaaS &amp; Security Challenges</strong></p> <ul> <li>The rise of <strong>AI-powered SaaS tools</strong> and the <strong>security risks they introduce</strong>.</li> <li>AI adoption <strong>without security &amp; compliance considerations</strong>.</li> </ul> <p><strong>[07:10] – Walter’s Background: From Physical Security to AI Governance</strong></p> <ul> <li>Transition from <strong>defense &amp; physical security</strong> to <strong>cybersecurity &amp; AI GRC</strong>.</li> <li>The importance of <strong>risk intelligence and automation</strong> in modern security.</li> </ul> <p><strong>[10:25] – The Intersection of AI, GRC, &amp; Security Governance</strong></p> <ul> <li>Who should own <strong>AI governance</strong>? Security teams, compliance, or legal?</li> <li>How AI <strong>challenges traditional risk management frameworks</strong>.</li> </ul> <p><strong>[13:40] – AI &amp; Compliance: The Role of ISO 42001</strong></p> <ul> <li>What is <strong>ISO 42001</strong> and how does it apply to AI governance?</li> <li>How companies can <strong>align AI security strategies with compliance</strong>.</li> </ul> <p><str></str></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022630-navigating-deepseek-s-ai-risks-insights-for-security-compliance-teams.mp3" length="28983575" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">3bf9d29b-6fcd-422d-918a-94bcac2a8da7</guid>
    <pubDate>Thu, 06 Feb 2025 12:00:00 -0600</pubDate>
    <itunes:duration>2411</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security, Compliance &amp; Customer Trust: The Evolution of GRC at Scale | feat. Abhay Kshirsagar from Salesforce</itunes:title>
    <title>Security, Compliance &amp; Customer Trust: The Evolution of GRC at Scale | feat. Abhay Kshirsagar from Salesforce</title>
    <itunes:summary><![CDATA[In this episode of Security &amp; GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Abhay Kshirsagar, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of security, compliance, and customer assurance.  Abhay shares his journey from IT audit and risk advisory to leading compliance automation, continuous monitoring, and customer assurance at industry giants like Cisco and now Salesforce. They discuss how compliance programs can...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <em>Security &amp; GRC Decoded</em>, host <strong>Raj Krishnamurthy</strong>, CEO of ComplianceCow, sits down with <strong>Abhay Kshirsagar</strong>, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of <strong>security, compliance, and customer assurance</strong>.</p> <p>Abhay shares his journey from IT audit and risk advisory to leading <strong>compliance automation, continuous monitoring, and customer assurance</strong> at industry giants like Cisco and now Salesforce. They discuss <strong>how compliance programs can move beyond checkboxes to become strategic enablers of business growth</strong>, unlocking new markets, influencing revenue, and strengthening customer trust.</p> <p>Key takeaways include:<br/> ✅ <strong>Compliance Automation &amp; Risk Reduction:</strong> How automation is transforming GRC processes and reducing engineering burdens.<br/> ✅ <strong>Customer Assurance as a Competitive Advantage:</strong> Why transparency and trust are becoming business differentiators.<br/> ✅ <strong>Metrics That Matter:</strong> How compliance teams can track and demonstrate their impact beyond regulatory requirements.<br/> ✅ <strong>Future of GRC:</strong> The shift towards <strong>predictive security, self-service platforms, and risk-driven compliance models.</strong></p> <p>Tune in to hear practical insights, real-world strategies, and a fresh perspective on the <strong>intersection of security, compliance, and business success</strong> in today&apos;s fast-changing regulatory landscape.</p> <p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by ComplianceCow. Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p><a href='https://www.compliancecow.com'>Learn More About How ComplianceCow Can Help Your GRC Team Today!</a></p> <h3><strong>📌 Episode Timestamps</strong></h3> <p><strong>00:00 - Introduction</strong></p> <ul> <li>Host <strong>Raj Krishnamurthy</strong> introduces the episode and guest <strong>Abhay Kshirsagar</strong>, Director of Security Services &amp; Tools at Salesforce.</li> </ul> <p><strong>02:15 - Abhay’s Background &amp; Journey into Security &amp; GRC</strong></p> <ul> <li>From <strong>Temple University</strong> to IT Audit &amp; Cybersecurity.</li> <li>Early career in <strong>risk advisory</strong> and SOX ITGC.</li> <li>Transition to <strong>Silicon Valley</strong> and working on <strong>SOC 2 &amp; ISO 27001</strong>.</li> </ul> <p><strong>08:45 - Joining Cisco &amp; Building the Cloud Controls Framework (CCF)</strong></p> <ul> <li>Creating <strong>Cisco’s CCF</strong> and open-sourcing it.</li> <li>Moving from compliance into <strong>product security and automation</strong>.</li> </ul> <p><strong>13:30 - Defining Security, Compliance &amp; Customer Assurance</strong></p> <ul> <li><strong>Security = Protection</strong>, <strong>Compliance = Following Rules</strong>, <strong>Assurance = Transparency</strong>.</li> <li>How these functions overlap and why <strong>customer assurance</strong> is critical.</li> </ul> <p><strong>18:50 - GRC &amp; Its Role in Business Growth</strong></p> <ul> <li>How compliance unlocks <strong>market access &amp; revenue growth</strong>.</li> <li>The <strong>real value of security &amp; compliance programs</strong> beyond checkboxes.</li> </ul> <p><strong>23:20 - Customer Assurance &amp; Measuring Customer Trust</strong></p> <ul> <li><strong>“What makes customers sad”</strong> – tracking gaps in compliance programs.</li> <li>Why <strong>SOC 2 isn’t enough</strong> for modern <strong>supply chain security</strong>.</li> </ul> <p><strong>28:00 - Industry Trends: Automation, Transparency &amp; Supply Chain Security</strong></p> <ul> <li>The rise of <strong>compliance automation</strong> and reducing engineering burdens.</li> <li>The role of <strong>SBOM (Software Bill of Materials) &amp; SSDF</strong> in supply chain security.</li> </ul> <p><strong>34:10 - The Challenge of Security Transparency</strong></p> <ul> <li>How to</li></ul>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <em>Security &amp; GRC Decoded</em>, host <strong>Raj Krishnamurthy</strong>, CEO of ComplianceCow, sits down with <strong>Abhay Kshirsagar</strong>, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of <strong>security, compliance, and customer assurance</strong>.</p> <p>Abhay shares his journey from IT audit and risk advisory to leading <strong>compliance automation, continuous monitoring, and customer assurance</strong> at industry giants like Cisco and now Salesforce. They discuss <strong>how compliance programs can move beyond checkboxes to become strategic enablers of business growth</strong>, unlocking new markets, influencing revenue, and strengthening customer trust.</p> <p>Key takeaways include:<br/> ✅ <strong>Compliance Automation &amp; Risk Reduction:</strong> How automation is transforming GRC processes and reducing engineering burdens.<br/> ✅ <strong>Customer Assurance as a Competitive Advantage:</strong> Why transparency and trust are becoming business differentiators.<br/> ✅ <strong>Metrics That Matter:</strong> How compliance teams can track and demonstrate their impact beyond regulatory requirements.<br/> ✅ <strong>Future of GRC:</strong> The shift towards <strong>predictive security, self-service platforms, and risk-driven compliance models.</strong></p> <p>Tune in to hear practical insights, real-world strategies, and a fresh perspective on the <strong>intersection of security, compliance, and business success</strong> in today&apos;s fast-changing regulatory landscape.</p> <p>🎙️ <em>Security &amp; GRC Decoded</em> is brought to you by ComplianceCow. Subscribe now for expert insights from industry leaders shaping the future of security &amp; compliance.</p> <p><a href='https://www.compliancecow.com'>Learn More About How ComplianceCow Can Help Your GRC Team Today!</a></p> <h3><strong>📌 Episode Timestamps</strong></h3> <p><strong>00:00 - Introduction</strong></p> <ul> <li>Host <strong>Raj Krishnamurthy</strong> introduces the episode and guest <strong>Abhay Kshirsagar</strong>, Director of Security Services &amp; Tools at Salesforce.</li> </ul> <p><strong>02:15 - Abhay’s Background &amp; Journey into Security &amp; GRC</strong></p> <ul> <li>From <strong>Temple University</strong> to IT Audit &amp; Cybersecurity.</li> <li>Early career in <strong>risk advisory</strong> and SOX ITGC.</li> <li>Transition to <strong>Silicon Valley</strong> and working on <strong>SOC 2 &amp; ISO 27001</strong>.</li> </ul> <p><strong>08:45 - Joining Cisco &amp; Building the Cloud Controls Framework (CCF)</strong></p> <ul> <li>Creating <strong>Cisco’s CCF</strong> and open-sourcing it.</li> <li>Moving from compliance into <strong>product security and automation</strong>.</li> </ul> <p><strong>13:30 - Defining Security, Compliance &amp; Customer Assurance</strong></p> <ul> <li><strong>Security = Protection</strong>, <strong>Compliance = Following Rules</strong>, <strong>Assurance = Transparency</strong>.</li> <li>How these functions overlap and why <strong>customer assurance</strong> is critical.</li> </ul> <p><strong>18:50 - GRC &amp; Its Role in Business Growth</strong></p> <ul> <li>How compliance unlocks <strong>market access &amp; revenue growth</strong>.</li> <li>The <strong>real value of security &amp; compliance programs</strong> beyond checkboxes.</li> </ul> <p><strong>23:20 - Customer Assurance &amp; Measuring Customer Trust</strong></p> <ul> <li><strong>“What makes customers sad”</strong> – tracking gaps in compliance programs.</li> <li>Why <strong>SOC 2 isn’t enough</strong> for modern <strong>supply chain security</strong>.</li> </ul> <p><strong>28:00 - Industry Trends: Automation, Transparency &amp; Supply Chain Security</strong></p> <ul> <li>The rise of <strong>compliance automation</strong> and reducing engineering burdens.</li> <li>The role of <strong>SBOM (Software Bill of Materials) &amp; SSDF</strong> in supply chain security.</li> </ul> <p><strong>34:10 - The Challenge of Security Transparency</strong></p> <ul> <li>How to</li></ul>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022629-security-compliance-customer-trust-the-evolution-of-grc-at-scale-feat-abhay-kshirsagar-from-salesforce.mp3" length="38127551" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">3dd9399f-2ae3-4f69-bfa7-1f76a92b74ee</guid>
    <pubDate>Thu, 06 Feb 2025 12:00:00 -0600</pubDate>
    <itunes:duration>3173</itunes:duration>
    <itunes:keywords>Salesforce,cybersecurity podcast,Salesforce Security,Security  GRC Decoded,ComplianceCow Podcast,GRC Podcast,Security Podcast,Abhay Kshirsagar,Raj Krishnamurthy,Compliancecow</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Risk-Based to Trust-Based: Evolving GRC with Netflix’s Mosi Platt</itunes:title>
    <title>From Risk-Based to Trust-Based: Evolving GRC with Netflix’s Mosi Platt</title>
    <itunes:summary><![CDATA[In the premiere episode of Security &amp; GRC Decoded, host Raj Krishnamurthy sits down with Mosi Platt, Senior Security Compliance Engineer at Netflix, to explore his unconventional journey into security and governance, risk, and compliance (GRC). From his first exposure to computers in his aunt’s home lab to becoming a leader in IT audits and compliance, Mosi shares the pivotal moments that shaped his career.  Together, they unpack the realities vs. myths of security governance, why risk qu...]]></itunes:summary>
    <description><![CDATA[<p>In the premiere episode of <em>Security &amp; GRC Decoded</em>, host Raj Krishnamurthy sits down with <strong>Mosi Platt, Senior Security Compliance Engineer at Netflix</strong>, to explore his unconventional journey into security and governance, risk, and compliance (GRC). From his first exposure to computers in his aunt’s home lab to becoming a leader in IT audits and compliance, Mosi shares the pivotal moments that shaped his career.</p> <p>Together, they unpack the <strong>realities vs. myths of security governance</strong>, why <strong>risk quantification is still an unresolved debate</strong>, and how <strong>security and GRC teams can move from reactive compliance to proactive trust-building</strong>. They also dive into the <strong>SEC’s cybersecurity materiality rules, digital transformation in compliance, and the shift from risk-based to trust-based security models</strong>.</p> <p>This episode is packed with insights for security leaders, compliance professionals, and anyone looking to <strong>understand the evolving landscape of security and GRC</strong>. Tune in to learn how <strong>leading with truth, adapting to change, and embracing value creation</strong> can transform the way organizations approach compliance and security assurance.</p> <p>🎧 <strong>Listen now and decode the future of Security &amp; GRC!</strong></p> <p><strong><a href='https://www.compliancecow.com'>Learn more about ComplianceCow and how we can help your GRC teams!</a></strong></p> <h3><strong>🎤 Guest Contact Information:</strong></h3> <p><strong>Mosi Platt</strong><br/> Senior Security Compliance Engineer at Netflix<br/> 🔗 <strong>LinkedIn:</strong> <a href='https://www.linkedin.com/in/mosi-k-platt/' target='_new' rel='noopener'>https://www.linkedin.com/in/mosi-k-platt/</a></p> <p> </p> <p class='p1'><span class='s1'>⏱</span> Timestamps:</p> <p class='p1'>0:00<span class='Apple-converted-space'> </span> Introduction &amp; Host<br/> 0:38<span class='Apple-converted-space'> </span> Mosi’s Journey (IT Training to Security Consulting)<br/> 6:50<span class='Apple-converted-space'> </span> Early Career in Compliance (IT Audits)<br/> 10:44 Defining Security &amp; GRC (3 Pillars)<br/> 12:38 Myth of Security Governance (CISO Oversight)<br/> 14:48 State of GRC Today (Risk Quantification &amp; SEC Regs)<br/> 19:30 SEC Cybersecurity Materiality Rules<br/> 24:12 Adapting GRC Strategies (People, Process, Tech)<br/> 30:10 Building a Security GRC Program (ISO 27001 Steps)<br/> 35:00 Risk-Based vs. Trust-Based Security<br/> 41:55 Getting Executive Buy-In (Truth vs. Fear)<br/> 45:28 Inheriting a GRC Program (Evaluate &amp; Optimize)<br/> 49:17 Future of GRC &amp; Digital Transformation<br/> 52:37 The Perfect GRC Solution (Automated Compliance)<br/> 56:00 Recommended Books &amp; Podcasts<br/> 58:30 Final Thoughts &amp; Key Takeaways</p> <h3>🔗 Additional Resources:</h3> <p>📚 <strong>Books:</strong></p> <ul> <li data-stringify-indent='0' data-stringify-border='0'> <em data-stringify-type='italic'>Investments Unlimited</em> by IT Revolution: <a class='c-link' href='https://itrevolution.com/product/investments-unlimited/' target='_blank' rel='noopener noreferrer' data-stringify-link='https://itrevolution.com/product/investments-unlimited/' data-sk='tooltip_parent'>https://itrevolution.com/product/investments-unlimited/</a></li> <li data-stringify-indent='0' data-stringify-border='0'> <em data-stringify-type='italic'>Emergency Skin</em> by N.K. Jemisin (Audiobook): <a href='https://www.audible.com/pd/Emergency-Skin-Audiobook/1978650841'>https://www.audible.com/pd/Emergency-Skin-Audiobook/1978650841</a><span style='font-family: -apple-system, BlinkMacSystemFont, &apos;Segoe UI&apos;, Roboto, Oxygen, Ubuntu, Cantarell, &apos;Open Sans&apos;, &apos;Helvetica Neue&apos;, sans-serif;'><br/> </span></li> </ul> <p><span style='font-family: -apple-system, BlinkMacSystemFont, &apos;Segoe UI&apos;, Roboto, Oxygen, Ubuntu, Cantarell, &apos;Open Sans&apos;, &apos;Helvetica Neue&apos;, sans-serif;'> 🎧 </span><strong style='font-family: -app&lt;/truncato-artificial-root&gt;'></p>]]></description>
    <content:encoded><![CDATA[<p>In the premiere episode of <em>Security &amp; GRC Decoded</em>, host Raj Krishnamurthy sits down with <strong>Mosi Platt, Senior Security Compliance Engineer at Netflix</strong>, to explore his unconventional journey into security and governance, risk, and compliance (GRC). From his first exposure to computers in his aunt’s home lab to becoming a leader in IT audits and compliance, Mosi shares the pivotal moments that shaped his career.</p> <p>Together, they unpack the <strong>realities vs. myths of security governance</strong>, why <strong>risk quantification is still an unresolved debate</strong>, and how <strong>security and GRC teams can move from reactive compliance to proactive trust-building</strong>. They also dive into the <strong>SEC’s cybersecurity materiality rules, digital transformation in compliance, and the shift from risk-based to trust-based security models</strong>.</p> <p>This episode is packed with insights for security leaders, compliance professionals, and anyone looking to <strong>understand the evolving landscape of security and GRC</strong>. Tune in to learn how <strong>leading with truth, adapting to change, and embracing value creation</strong> can transform the way organizations approach compliance and security assurance.</p> <p>🎧 <strong>Listen now and decode the future of Security &amp; GRC!</strong></p> <p><strong><a href='https://www.compliancecow.com'>Learn more about ComplianceCow and how we can help your GRC teams!</a></strong></p> <h3><strong>🎤 Guest Contact Information:</strong></h3> <p><strong>Mosi Platt</strong><br/> Senior Security Compliance Engineer at Netflix<br/> 🔗 <strong>LinkedIn:</strong> <a href='https://www.linkedin.com/in/mosi-k-platt/' target='_new' rel='noopener'>https://www.linkedin.com/in/mosi-k-platt/</a></p> <p> </p> <p class='p1'><span class='s1'>⏱</span> Timestamps:</p> <p class='p1'>0:00<span class='Apple-converted-space'> </span> Introduction &amp; Host<br/> 0:38<span class='Apple-converted-space'> </span> Mosi’s Journey (IT Training to Security Consulting)<br/> 6:50<span class='Apple-converted-space'> </span> Early Career in Compliance (IT Audits)<br/> 10:44 Defining Security &amp; GRC (3 Pillars)<br/> 12:38 Myth of Security Governance (CISO Oversight)<br/> 14:48 State of GRC Today (Risk Quantification &amp; SEC Regs)<br/> 19:30 SEC Cybersecurity Materiality Rules<br/> 24:12 Adapting GRC Strategies (People, Process, Tech)<br/> 30:10 Building a Security GRC Program (ISO 27001 Steps)<br/> 35:00 Risk-Based vs. Trust-Based Security<br/> 41:55 Getting Executive Buy-In (Truth vs. Fear)<br/> 45:28 Inheriting a GRC Program (Evaluate &amp; Optimize)<br/> 49:17 Future of GRC &amp; Digital Transformation<br/> 52:37 The Perfect GRC Solution (Automated Compliance)<br/> 56:00 Recommended Books &amp; Podcasts<br/> 58:30 Final Thoughts &amp; Key Takeaways</p> <h3>🔗 Additional Resources:</h3> <p>📚 <strong>Books:</strong></p> <ul> <li data-stringify-indent='0' data-stringify-border='0'> <em data-stringify-type='italic'>Investments Unlimited</em> by IT Revolution: <a class='c-link' href='https://itrevolution.com/product/investments-unlimited/' target='_blank' rel='noopener noreferrer' data-stringify-link='https://itrevolution.com/product/investments-unlimited/' data-sk='tooltip_parent'>https://itrevolution.com/product/investments-unlimited/</a></li> <li data-stringify-indent='0' data-stringify-border='0'> <em data-stringify-type='italic'>Emergency Skin</em> by N.K. Jemisin (Audiobook): <a href='https://www.audible.com/pd/Emergency-Skin-Audiobook/1978650841'>https://www.audible.com/pd/Emergency-Skin-Audiobook/1978650841</a><span style='font-family: -apple-system, BlinkMacSystemFont, &apos;Segoe UI&apos;, Roboto, Oxygen, Ubuntu, Cantarell, &apos;Open Sans&apos;, &apos;Helvetica Neue&apos;, sans-serif;'><br/> </span></li> </ul> <p><span style='font-family: -apple-system, BlinkMacSystemFont, &apos;Segoe UI&apos;, Roboto, Oxygen, Ubuntu, Cantarell, &apos;Open Sans&apos;, &apos;Helvetica Neue&apos;, sans-serif;'> 🎧 </span><strong style='font-family: -app&lt;/truncato-artificial-root&gt;'></p>]]></content:encoded>
    <enclosure url="https://dts.podtrac.com/redirect.mp3/www.buzzsprout.com/2489040/episodes/17022631-from-risk-based-to-trust-based-evolving-grc-with-netflix-s-mosi-platt.mp3" length="45954490" type="audio/mpeg" />
    <itunes:author>Raj Krishnamurthy</itunes:author>
    <guid isPermaLink="false">003dc6f2-e647-4eac-bb22-8bc2591c149e</guid>
    <pubDate>Thu, 06 Feb 2025 11:40:00 -0600</pubDate>
    <itunes:duration>3826</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType></itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
