Podcast charts
Published by Raj Krishnamurthy
How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Sunil Agrawal , CISO at Glean , to discuss why the traditional "security as friction" narrative is outdated. Sunil explains his philosophy that security functions as the brakes on a car—not to slow you down, but to provide the safety net that allows you to move faster. Drawing on three decades of leadership at companies like Netflix, Adobe, and Qualcomm, Sunil unpacks the critical shift in the post-Mythos threat landscape. As the window between vulnerability and exploit collapses from months to minutes, legacy tooling built for human triage is no longer viable. Sunil details how organizations must adapt, covering: Why "security as brakes" changes product velocity. The distinction between one-way vs. two-way doors in automated remediation. How to architect security programs for machine-speed threats. Why the conversation with the board is finally shifting from activity to risk. If you are looking to rethink your security posture for an agentic, AI-driven world, this episode provides the blueprint. Key Takeaways : The vulnerability-to-exploit window has compressed from roughly a year to 10–24 hours, and is heading toward minutes — which means remediation has to operate at machine speed. Every legacy security tool was designed for human consumption. In an agentic world, tools must generate high-confidence findings because no human is left to filter the false positives. Automated remediation belongs on two-way doors. One-way doors — anything unrecoverable — still need a human in the loop. Roughly 90% of enterprise AI work should be deterministic retrieval; the LLM should only handle the reasoning and summarization layer. Security teams were always outnumbered — 100 engineers to five defenders. AI is the first technology shift that closes that gap in the defender's favor. What You'll Learn : Why Sunil frames security as brakes rather than friction — and what that changes about product velocity How to decide which remediations can be safely automated and which cannot What "making your data AI-ready" actually means once security through obscurity disappears How enterprises are really deploying open-weight models, and where regulation forecloses the choice Why identifying your crown jewels is the prioritization discipline most security programs skip This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more : https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Sunil Agrawal | CISO | Glean Connect on LinkedIn : https://www.linkedin.com/in/sunilcagrawal/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with James Tabron , Director of GRC Engineering at Aquia , for a conversation almost nobody in this space is qualified to have: what GRC looks like from inside an engineering org. James spent two decades in IT before building GRC programs at SendGrid, Twilio, and Snapdocs — and then did something almost no GRC practitioner ever does. He crossed the aisle. A VP of engineering hired him into the engineering organization to build DevSecOps, and within a couple of years James was a Director of Software Engineering running five teams, 33 people, and the operations behind roughly 9 figures in revenue. Today he runs GRC engineering at Aquia, building continuous authority to operate (cATO) programs in the federal space. That combination gives him an unusually blunt read on why GRC keeps producing theater. His answer isn't that practitioners are lazy — it's that the incentives are working exactly as designed. Companies are rewarded for getting a SOC 2 as fast and cheaply as possible, and the market has quietly demonstrated that breaches rarely cost you customers. Compare that to federal, where an authority to operate means a third-party assessor, an authorizing official, a 500-page system security plan, and anywhere from 150 to 700+ NIST 800-53 controls, and the picture of which environment produces more real security gets uncomfortable fast. The conversation also covers continuous controls monitoring in a cATO model, why GRC teams have never touched DORA metrics, what agentic AI actually automates in an audit cycle, why James thinks incumbent GRC tools have three to five years to justify their price tag, and the skill he believes every aspiring GRC engineer is currently sleeping on: data engineering. Key Takeaways : GRC theater is an incentive problem, not a competence problem — the SaaS market rewards the fastest, cheapest attestation, and breaches rarely produce churn. Federal ATO environments produce less theater because accountability is enforced before a system ever reaches production, not after an incident. In a continuous ATO model, every control family should have an evidence pipeline — not just the handful of controls that are easy to monitor. Agentic workflows are a natural fit for audit prep, and offloading that tactical work is what finally makes experienced GRC professionals strategically valuable. The next differentiating skill for GRC engineers is data engineering — specifically the "T" in ETL. What You'll Learn : Why a product VP with no security mandate chose to hire a GRC leader into engineering How to translate compliance requirements into the tools and rituals engineers already use What continuous monitoring actually requires versus what most programs settle for Why traditional GRC has never measured DORA metrics — and whether it should Where the build-vs-buy line really sits for GRC tooling, and who gets to cross it Why technical acumen should come before framework knowledge in a GRC career This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more : https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : James Tabron | Director, GRC Engineering | Aquia LinkedIn : https://www.linkedin.com/in/jamestabron/ James is also VP of the GRC Engineering Club — a community for practitioners building in this space. Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with James Huang , Head of GRC at Gong , to explore how Governance, Risk, and Compliance has evolved from a traditional audit function into a strategic engineering discipline. Drawing on experience building GRC programs at Ernst & Young, Cisco, Salesforce, and Gong, James explains why modern GRC leaders must think beyond compliance checklists and focus instead on understanding risk, partnering with engineering, and building scalable security programs. The conversation covers common control frameworks, continuous controls monitoring, third-party risk, AI's impact on GRC, Mythos, automation, and why future GRC professionals need to become business translators rather than framework experts. Key Takeaways: Modern GRC should focus on understanding and reducing risk—not simply satisfying compliance frameworks. A Common Controls Framework only succeeds when engineering and business teams understand the risks behind each control. Continuous controls monitoring should improve security posture, not just make audits easier. AI is transforming GRC by increasing both operational efficiency and third-party risk complexity. Successful GRC leaders act as translators between business, engineering, security, and compliance teams. What You’ll Learn: Why compliance frameworks should always be interpreted through the lens of risk How to build scalable Common Control Frameworks across complex organizations What continuous controls monitoring should actually accomplish How AI is changing vendor risk management and security governance Why the future of GRC belongs to technically-minded business partners This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes: https://www.compliancecow.com/podcast Connect With Our Guests : James Huang | Head of GRC | Gong Connect on LinkedIn : https://www.linkedin.com/in/james-k-huang/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Rajiv Dattani and David Meyer from Artificial Intelligence Underwriting Company (AIUC) to explore one of the biggest unanswered questions in AI security: Can organizations actually trust AI agents? As enterprises rapidly deploy AI-powered products, copilots, and autonomous agents, traditional security assessments, compliance frameworks, and cyber insurance models are struggling to keep pace. Rajiv and David explain why insurers are beginning to exclude AI-related risks, why historical loss data no longer works in the age of AI, and how AIUC-1 was designed to become a trust and assurance framework for AI systems. The conversation explores AI certification, AI insurance, agent security testing, reliability, safety, accountability, statistical risk modeling, and the growing challenge of securing increasingly autonomous systems. Key Takeaways: Traditional cyber insurance models are struggling to underwrite AI risk because historical loss data becomes obsolete as models rapidly evolve. AIUC-1 combines governance controls, technical evaluations, and large-scale simulation testing to assess AI agent security and trustworthiness. AI assurance requires more than security controls—it must also evaluate reliability, safety, accountability, privacy, and societal impact. Statistical testing and large-scale simulations may become the foundation for measuring AI risk in probabilistic systems. The AI security community will play a critical role in shaping standards, liability models, and best practices for future AI deployments. What You’ll Learn: Why many insurance carriers are beginning to exclude AI-generated risks from cyber policies How AIUC-1 differs from frameworks like NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS How AI agents are tested through both black-box and white-box security evaluations Why reliability and hallucination risks become more important in multi-agent environments How AI certification may influence future insurance pricing, risk management, and enterprise adoption This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes: https://www.compliancecow.com/podcast Connect With Our Guests: Rajiv Dattani | Cofounder | AIUC David Meyer | GTM | AIUC Connect on LinkedIn: https://www.linkedin.com/in/rajiv-dattani/ https://www.linkedin.com/in/david-meyer-8586b17b/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal , Head of GRC at UiPath , to explore why the future of GRC looks far more like systems engineering than traditional audit management. Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together. This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year. Key Takeaways : Modern GRC programs must evolve from audit functions into engineering-driven reliability functions. Risk—not compliance—should be the central language for communicating with leadership teams. Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.” AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks. Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership. What You’ll Learn : Why Sheron believes compliance should be designed into products from day one How UiPath approaches continuous risk monitoring and GRC engineering Why AIUC-1 introduces a fundamentally different approach to AI assurance How GRC teams can become the “translation layer” between business and engineering Why future GRC practitioners must develop technical and systems-thinking skills This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Sheron Chakalakal | Head of GRC | UiPath Connect on LinkedIn: https://www.linkedin.com/in/sheronpaulc/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur , Principal of Security & Assurance Engineering at CoreWeave , to explore how AI-native infrastructure is fundamentally reshaping GRC. Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems. Key Takeaways: Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them. Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal. GRC must evolve into an infrastructure-level capability that continuously emits assurance signals. Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight. Future GRC teams must operate more like engineering and reliability functions rather than audit teams. What You’ll Learn: Why AI infrastructure makes traditional audits ineffective What “GRC as infrastructure” actually means in practice How to move from point-in-time audits to continuous assurance The difference between automation, CCM, and agentic GRC How to position GRC as a proactive, business-critical function This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes: https://www.compliancecow.com/podcast Connect With Our Guest: Jasmine Kaur | Principal of Security & Assurance Engineering | CoreWeave Connect on LinkedIn: https://www.linkedin.com/in/jask31/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Val Dobrushkin , Director of GRC at Tricentis , to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers. This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&A outcomes, and why solving for today while building for the future is the key to long-term success. Key Takeaways : Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls. SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity. GRC has a unique advantage over security in directly demonstrating business value and revenue impact. “Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition. Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early. What You’ll Learn : Why questionnaires and annual vendor reviews fail to capture real third-party risk How GRC teams can prove revenue impact through customer trust and assurance The hidden role of GRC in M&A, IPO readiness, and contract validation Why most GRC metrics fail and what meaningful measurement should look like How to implement a “solve now, build for future” strategy in fast-growing companies This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Val Dobrushkin | Director of GRC | Tricentis Connect on LinkedIn: https://www.linkedin.com/in/dobrushkin/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Dylan O’Dell , AVP Information Risk Officer at Manulife , to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions. Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why GRC needs to evolve beyond audits and control testing into automation, orchestration, and storytelling. This conversation explores how modern GRC teams can reduce operational friction, quantify real risk, and actually influence business outcomes. Key Takeaways : GRC today is overly focused on control testing rather than true risk management and decision-making. Automation should eliminate manual audit friction — not just make existing processes faster. The future GRC professional must combine technical awareness with storytelling, influence, and business understanding. Risk management should be rooted in probability and financial impact — not pass/fail compliance. GRC teams can unlock funding and influence by tying their work directly to revenue, cost savings, and business outcomes. What You’ll Learn : Why the “three lines of defense” model often breaks down in practice. How to translate technical data into meaningful business risk narratives. What modern GRC automation should actually look like (beyond tools). How to position GRC as a revenue enabler — not just a cost center. Why “start with why” is critical for influencing stakeholders and reducing friction. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more : https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Dylan O’Dell | AVP Information Risk Officer | Manulife Connect on LinkedIn: https://www.linkedin.com/in/dylan-odell-72a06412b/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security & GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogies to explain vulnerabilities, to reframing GRC as the “Draymond Green” of cybersecurity, Steven shows how the best security leaders translate complexity into clarity, help the business make better decisions, and meet people where they are instead of overwhelming them with jargon. Key Takeaways: Security and GRC succeed when they communicate clearly to humans, not when they simply present more technical detail. The best GRC teams act as guides that help the business make reasonable, compliant, cyber-conscious decisions. Metrics only matter when they drive a clear outcome or decision, not when they exist for their own sake. Strong GRC teams build trust by doing the hard, cross-functional work that others often avoid. Storytelling is a core security skill because people act on messages they understand, remember, and relate to. What You’ll Learn: Why Steven believes security is ultimately a human communication problem. How to tailor security messaging for engineering leaders, CISOs, and business stakeholders. What “guardrails not gates” looks like in a practical GRC program. How to think about data, metrics, and reporting without overwhelming your audience. Why AI may change the consumption layer of GRC, but not eliminate the human need for storytelling. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes: https://www.compliancecow.com/podcast Connect With Our Guest: Steven Asifo | Director of Security & GRC | Yahoo Connect on LinkedIn: https://www.linkedin.com/in/asifosays/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Bryan Culp , Senior Director of Customer Trust at Box , to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust. Bryan shares why the next two to three years will fundamentally change how GRC operates — driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business language. From managing both customer trust and third-party risk at Box, Bryan offers a rare dual perspective: how companies present assurance to customers while simultaneously evaluating vendors themselves. This conversation challenges the idea that certifications alone create security and makes the case for risk being the true language of leadership. Key Takeaways : Customer Trust is not traditional GRC — it translates security and compliance work into business confidence for customers. Certifications enable market access, but they do not eliminate breach risk. Risk must be communicated in executive language to influence real business decisions. Large financial institutions are beginning to demand real-time internal security metrics instead of snapshot audits. AI is transforming GRC workflows — not to cut people, but to enable deeper, higher-value analysis. What You’ll Learn : Why Bryan believes GRC will look materially different in the next 2–3 years. How Customer Trust functions differently from compliance and audit teams. Why certifications alone cannot prevent major security incidents. What “real-time assurance” could look like for large SaaS companies. How to think about AI and automation as long-term growth enablers in GRC. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Bryan Culp | Senior Director of Customer Trust | Box Connect on LinkedIn: https://www.linkedin.com/in/bryanculp/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Ryan Schoeller , Director of Security & GRC at Treasure Data , to challenge one of the most deeply rooted assumptions in the industry: that GRC should stay passive and “independent.” Drawing from his experience across startups, mid-market tech companies, and large enterprises, Ryan argues that the most effective GRC teams are the ones that actively participate in control monitoring, risk management, and operational decision-making. This conversation goes beyond audits and checklists, exploring how GRC can truly drive business value by protecting revenue, enabling growth, and embedding risk thinking into everyday operations. Key Takeaways : GRC delivers the most value when it actively participates in monitoring controls, not just validating them after the fact. Risk is the most critical — and most neglected — pillar of GRC, often confused with gaps or vulnerabilities. Strong relationships with engineering and business teams are essential for GRC to gain meaningful access to data. GRC engineering is not just about writing code; it’s about applying an engineering mindset to workflows, tooling, and processes. Automation alone is not a business case — value comes from how freed-up time is reinvested. What You’ll Learn : Why the “three lines of defense” model often breaks down in real organizations How GRC teams can reduce compliance theater by becoming more operational The difference between a vulnerability, a gap, and an actual risk How to build a business case for GRC automation that leadership will support Why front-ending GRC work (sales assurance, customer trust) often matters more than backend audit prep This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Ryan Schoeller | Director of Security & GRC | Treasure Data Connect on LinkedIn: https://www.linkedin.com/in/ryanschoeller/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
What if GRC shouldn’t sit inside Security at all —and what if the bigger problem isn’t automation, but what you do after you automate? In this episode, Raj Krishnamurthy sits down with Charles Nwatu (former Security GRC Engineering & Assurance leader at Netflix) for a candid, systems-level conversation about why “annual audit rituals” fail modern engineering, how GRC can produce high-fidelity signals that strengthen security decision-making , and why the next wave of GRC engineering is about analytics, specifications, and business impact —not just speeding up evidence collection. Key Takeaways : GRC is a continuous discipline—point-in-time compliance can help, but it can’t be the end state. Automation is necessary but not sufficient: the real value is in turning collected evidence into actionable insights. Specifications enable measurement—without clear expected behaviors, security metrics become inconsistent and hard to compare. GRC can feed security with high-fidelity signals (like identity/access review metadata) that improve posture beyond audit readiness. Third-party risk doesn’t “finish”—the goal is visibility, data lineage awareness, and making the mess less messy. What You’ll Learn : Where Charles believes GRC should sit org-wise—and why Security should be a “customer” of GRC What “shift-left GRC” looks like in practice (beyond annual audits) Why “efficiency savings” don’t automatically equal “security value” How to think about metrics, specifications, and risk in a shared language Why third-party risk management is “unsolvable,” and how to build guardrails anyway This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more : https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Charles Nwatu | GRC Engineering Leader Connect on LinkedIn: https://www.linkedin.com/in/cnwatu/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
GRC has long been seen as abstract, manual, and disconnected from how modern engineering teams actually work, but that narrative is breaking down. In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Akhila Chitiprolu , Head of Security & GRC at Sierra, to explore why GRC must be treated as an engineering discipline, not a compliance afterthought. Drawing from her experience across T-Mobile, Expedia, Stripe, and AI-native companies, Akhila explains how systems thinking, automation, and shared ownership can radically reduce compliance toil while increasing trust. This conversation goes deep into GRC engineering, audit realities, automation tradeoffs, and what the future of compliance looks like in an AI-driven world. Key Takeaways : GRC works best when treated as a system with inputs, processes, outputs, and feedback loops Automation should focus on intent and outcomes, not blindly speeding up broken manual processes GRC professionals act as a middleware layer between engineers, auditors, and customers Not all controls should be automated — but 70% can be, with humans in the loop where it matters The future of GRC depends on engineering mindset, context, and trust, not checklists What You’ll Learn : Why GRC is fundamentally a systems engineering problem How to reduce engineering toil without weakening audit posture When automation helps — and when it creates false efficiency How GRC teams should approach AI, agents, and non-deterministic systems Practical ways to build a GRC engineering function over time This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Akhila Chitiprolu | Head of Security & GRC | Sierra Connect on LinkedIn : https://www.linkedin.com/in/akhilachitiprolu/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , Raj Krishnamurthy sits down with Vivek Madan to unpack what it really means to run a modern GRC program inside a global cybersecurity company. Drawing from his journey across networking, security engineering, risk, and compliance, Vivek shares how GRC can function as a true business enabler—opening markets, accelerating revenue, and strengthening trust. This conversation stands out for its practical frameworks, real-world stories, and honest discussion about friction between engineering, security, auditors, and compliance teams, giving listeners a grounded view of how GRC works when it’s done right. Key Takeaways : GRC works best when it is positioned as a growth enabler that unlocks new markets, not just a compliance checkbox. Strong governance establishes foundational rules that allow security and risk decisions to scale consistently across the business. Storytelling is a critical GRC skill—people align with compliance when they understand the “why,” not just the requirement. Common controls frameworks reduce complexity when designed intentionally across global, application-specific, and product-specific needs. Automation matters, but process automation is just as important as technical automation to reduce compliance friction. What You’ll Learn : How GRC enables business expansion into regulated and global markets Why compliance resistance exists—and how to overcome it A practical 50–35–15 model for common controls frameworks How to balance continuous assurance with annual audits What modern GRC leaders look for when hiring talent This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Vivek Madan | Director of Security, Risk, and Compliance | Fortinet Connect on LinkedIn : https://www.linkedin.com/in/vivek-madan-cissp-ccsp/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil — but what if that mindset is holding security teams back? In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing link between fast-moving engineering teams and slow, annual audit cycles — and how organizations can stop treating audits as an afterthought and start using them as a trust-building mechanism. Key Takeaways : Audits are designed to provide reasonable assurance, not eliminate all risk The biggest failure in modern GRC is building controls that are automated but not auditable Continuous controls monitoring only works if auditors can validate completeness and accuracy Screenshots persist because they remain the clearest way to demonstrate system state over time Security controls should be built to improve posture first — and explained clearly second What You’ll Learn : Why audit skepticism is a feature, not a flaw How internal and external audits serve fundamentally different purposes Where continuous monitoring breaks down from an auditor’s perspective What “auditable controls” actually mean in CI/CD environments How AI can assist auditors without replacing human judgment This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Varun Prasad | Cloud Security & Privacy Assurance | BDO Connect on LinkedIn : https://www.linkedin.com/in/varunprasad/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts : Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Tom Scuderi , Senior Manager of Security & GRC at LTK and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen—not dilute—your security program, and how to anchor leadership decisions with meaningful risk data. Key Takeaways GRC only scales when its processes mirror how engineering teams already work. SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise. Curated visibility reduces friction and improves cross-functional trust. Clarity in ownership is the backbone of a scalable GRC function. Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program. What You’ll Learn How Tom built and matured GRC programs across four different companies. Why engineering alignment is essential for sustainable compliance. How curated visibility replaces access sprawl and accelerates audits. The difference between risk-driven and compliance-driven GRC. Why automation only works when underlying processes are mature. How to structure ownership to reduce bottlenecks during SOC 2 and similar frameworks. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection , eliminate screenshots , and scale your program with confidence . Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Tom Scuderi | Senior Manager of Security & GRC | LTK Connect on LinkedIn : https://www.linkedin.com/in/tom-scuderi/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 #SecurityAndGRCDecoded #RajKrishnamurthy #TomScuderi #LTK #GRC #ScalingGRC #SOC2 #EngineeringAlignment #RiskManagement #SecurityLeadership #Compliance #GovernanceRiskCompliance #SecurityGRCPodcast #ComplianceCow
In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Sergio Alonso , a seasoned GRC and information security leader at Rapid7 , whose 17–year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls should be treated as “promises” that teams must honor every day. This conversation explores scaling GRC in high-velocity environments, reducing compliance fatigue, applying zero-knowledge principles to trust, and building the next generation of context-driven risk programs. Key Takeaways Automation is the only sustainable path to scaling GRC without increasing friction. Controls should be viewed as “promises,” and audits as the consequence of keeping or breaking them. Context — technical, business, and risk — is the primary driver of effective triage and prioritization. GRC must evolve from a legacy function into a trust-driven, engineering-aligned discipline. Zero-knowledge-style thinking may define the future of transparency and customer trust. What You’ll Learn How to adapt legacy compliance experience for cloud, SaaS, and fast-moving tech companies. Why automation, evidence APIs, and GRC engineering are becoming non-negotiable. How to reduce compliance fatigue using “meet once, meet many” principles. Why context is the key to reducing noise from security tools. How to partner with engineers using empathy, clarity, and strong framing. Why trust and transparency are reshaping GRC inside cybersecurity companies. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com Watch more episodes: https://www.compliancecow.com/podcast Connect With Our Guest: Sergio Alonso | GRC & Information Security Leader | Rapid7 Connect on LinkedIn: https://www.linkedin.com/in/salonsor/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Mukund Sarma , Deputy CISO and Head of Product Security at Chime , to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity. 5 Key Takeaways GRC isn’t a blocker—it’s a mirror that keeps security honest and accountable. Strong security engineering automatically strengthens compliance outcomes. Friction between security and engineering fades when empathy drives collaboration. “Shift left” works best when paved paths and automation support developers. Practical controls and continuous validation create sustainable, scalable governance. What You’ll Learn How to bridge silos between security, GRC, and engineering teams. Why automation and continuous control monitoring are the future of compliance. What “practical controls” really mean in modern DevSecOps environments. How empathy and communication transform security culture. Why compliance should follow great security engineering, not lead it. Real-world examples from Chime’s approach to product security. This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection , eliminate screenshots , and scale your program with confidence . Learn more: https://www.compliancecow.com Watch more episodes : https://www.compliancecow.com/podcast Connect With Our Guest : Mukund Sarma | Deputy CISO and Head of Product Security | Chime Connect on LinkedIn: https://www.linkedin.com/in/sarmamukund/ Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify : https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr Apple Podcasts : https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold , Security GRC Program Manager at Meta . Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time. 5 Key Takeaways Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are. Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works. Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits. Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs. Define the Right Role: The best GRC teams act as a sparring partner -- challenging, supportive, and focused on outcomes. What You’ll Learn How to rebuild trust with engineering after “audit fatigue” Practical ways to convert control requirements into product language How to design evidence from logs, pipelines, and tickets you already have When to push, when to partner, and how to escalate with credibility Communicating risk trade-offs without killing roadmap velocity Connect With Our Guest : Tristan Ingold | Security GRC Program Manager | Meta This podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Watch more episodes Rate, review, and share if you enjoyed the show ! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify Apple Podcasts
In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue , seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix , Gap , and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions. He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned. Key Takeaways CRQ doesn’t require perfection—start with what you have and refine over time. The most effective risk programs focus on directionally correct data, not precision. Good risk scenarios clearly define asset, threat, and effect to avoid misalignment. Generative AI accelerates scenario development, data research, and model creation. CISOs should demand more from risk teams—move beyond “pick a color” heat maps. Topics Covered Cyber risk quantification (CRQ) Monte Carlo simulations and modeling Risk scenario design and measurement GRC and compliance integration Generative AI in risk management Moving from qualitative to quantitative risk Improving risk hygiene and maturity CISO leadership and risk culture What You’ll Learn The difference between qualitative and quantitative risk methods How to conduct your first risk quantification in Excel Why Monte Carlo simulations are simpler than most think How GRC, compliance, and security teams can collaborate effectively The six levers that influence risk magnitude and frequency This podcast is brought to you by ComplianceCow : ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business. Learn more at ComplianceCow.com Connect with our guest: Tony Martin-Vegue on LinkedIn Co-Chair, FAIR Institute San Francisco Chapter Former Risk Leader at Netflix and Gap Inc. Author, From Heat Maps to Histograms (coming 2026) Subscribe to Security & GRC Decoded on your favorite platform: Spotify Apple Podcasts Explore all episodes: ComplianceCow.com/podcast
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 21, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.