Ga naar de inhoud
PodcastsTechnologieSecurity & GRC Decoded

Security & GRC Decoded

Raj Krishnamurthy
Security & GRC Decoded
Nieuwste aflevering

39 afleveringen

  • Security & GRC Decoded

    Security Theater Isn't a Skills Problem. It's an Incentive Problem. ft James Tabron, Director of GRC Engineering @ Aquia

    18-08-2026 | 59 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with James Tabron, Director of GRC Engineering at Aquia, for a conversation almost nobody in this space is qualified to have: what GRC looks like from inside an engineering org.

    James spent two decades in IT before building GRC programs at SendGrid, Twilio, and Snapdocs — and then did something almost no GRC practitioner ever does. He crossed the aisle. A VP of engineering hired him into the engineering organization to build DevSecOps, and within a couple of years James was a Director of Software Engineering running five teams, 33 people, and the operations behind roughly 9 figures in revenue. Today he runs GRC engineering at Aquia, building continuous authority to operate (cATO) programs in the federal space.

    That combination gives him an unusually blunt read on why GRC keeps producing theater. His answer isn't that practitioners are lazy — it's that the incentives are working exactly as designed. Companies are rewarded for getting a SOC 2 as fast and cheaply as possible, and the market has quietly demonstrated that breaches rarely cost you customers. Compare that to federal, where an authority to operate means a third-party assessor, an authorizing official, a 500-page system security plan, and anywhere from 150 to 700+ NIST 800-53 controls, and the picture of which environment produces more real security gets uncomfortable fast.

    The conversation also covers continuous controls monitoring in a cATO model, why GRC teams have never touched DORA metrics, what agentic AI actually automates in an audit cycle, why James thinks incumbent GRC tools have three to five years to justify their price tag, and the skill he believes every aspiring GRC engineer is currently sleeping on: data engineering.

    Key Takeaways:

    GRC theater is an incentive problem, not a competence problem — the SaaS market rewards the fastest, cheapest attestation, and breaches rarely produce churn.
    Federal ATO environments produce less theater because accountability is enforced before a system ever reaches production, not after an incident.
    In a continuous ATO model, every control family should have an evidence pipeline — not just the handful of controls that are easy to monitor.
    Agentic workflows are a natural fit for audit prep, and offloading that tactical work is what finally makes experienced GRC professionals strategically valuable.
    The next differentiating skill for GRC engineers is data engineering — specifically the "T" in ETL.

    What You'll Learn:

    Why a product VP with no security mandate chose to hire a GRC leader into engineering
    How to translate compliance requirements into the tools and rituals engineers already use
    What continuous monitoring actually requires versus what most programs settle for
    Why traditional GRC has never measured DORA metrics — and whether it should
    Where the build-vs-buy line really sits for GRC tooling, and who gets to cross it
    Why technical acumen should come before framework knowledge in a GRC career

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest: James Tabron | Director, GRC Engineering | Aquia
    LinkedIn: https://www.linkedin.com/in/jamestabron/

    James is also VP of the GRC Engineering Club — a community for practitioners building in this space.

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong

    04-08-2026 | 46 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with James Huang, Head of GRC at Gong, to explore how Governance, Risk, and Compliance has evolved from a traditional audit function into a strategic engineering discipline.
    Drawing on experience building GRC programs at Ernst & Young, Cisco, Salesforce, and Gong, James explains why modern GRC leaders must think beyond compliance checklists and focus instead on understanding risk, partnering with engineering, and building scalable security programs. The conversation covers common control frameworks, continuous controls monitoring, third-party risk, AI's impact on GRC, Mythos, automation, and why future GRC professionals need to become business translators rather than framework experts.
    Key Takeaways:
    Modern GRC should focus on understanding and reducing risk—not simply satisfying compliance frameworks.
    A Common Controls Framework only succeeds when engineering and business teams understand the risks behind each control.
    Continuous controls monitoring should improve security posture, not just make audits easier.
    AI is transforming GRC by increasing both operational efficiency and third-party risk complexity.
    Successful GRC leaders act as translators between business, engineering, security, and compliance teams.
    What You’ll Learn:
    Why compliance frameworks should always be interpreted through the lens of risk
    How to build scalable Common Control Frameworks across complex organizations
    What continuous controls monitoring should actually accomplish
    How AI is changing vendor risk management and security governance
    Why the future of GRC belongs to technically-minded business partners
    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guests:
    James Huang | Head of GRC | Gong
    Connect on LinkedIn: https://www.linkedin.com/in/james-k-huang/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts:
    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC

    25-06-2026 | 38 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Rajiv Dattani and David Meyer from Artificial Intelligence Underwriting Company (AIUC) to explore one of the biggest unanswered questions in AI security:
    Can organizations actually trust AI agents?
    As enterprises rapidly deploy AI-powered products, copilots, and autonomous agents, traditional security assessments, compliance frameworks, and cyber insurance models are struggling to keep pace. Rajiv and David explain why insurers are beginning to exclude AI-related risks, why historical loss data no longer works in the age of AI, and how AIUC-1 was designed to become a trust and assurance framework for AI systems.
    The conversation explores AI certification, AI insurance, agent security testing, reliability, safety, accountability, statistical risk modeling, and the growing challenge of securing increasingly autonomous systems.

    Key Takeaways:
    Traditional cyber insurance models are struggling to underwrite AI risk because historical loss data becomes obsolete as models rapidly evolve.
    AIUC-1 combines governance controls, technical evaluations, and large-scale simulation testing to assess AI agent security and trustworthiness.
    AI assurance requires more than security controls—it must also evaluate reliability, safety, accountability, privacy, and societal impact.
    Statistical testing and large-scale simulations may become the foundation for measuring AI risk in probabilistic systems.
    The AI security community will play a critical role in shaping standards, liability models, and best practices for future AI deployments.

    What You’ll Learn:
    Why many insurance carriers are beginning to exclude AI-generated risks from cyber policies
    How AIUC-1 differs from frameworks like NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
    How AI agents are tested through both black-box and white-box security evaluations
    Why reliability and hallucination risks become more important in multi-agent environments
    How AI certification may influence future insurance pricing, risk management, and enterprise adoption

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guests:
    Rajiv Dattani | Cofounder | AIUC
    David Meyer | GTM | AIUC
    Connect on LinkedIn: https://www.linkedin.com/in/rajiv-dattani/
    https://www.linkedin.com/in/david-meyer-8586b17b/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts:
    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath

    02-06-2026 | 53 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal, Head of GRC at UiPath, to explore why the future of GRC looks far more like systems engineering than traditional audit management.
    Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together.
    This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year.

    Key Takeaways:
    Modern GRC programs must evolve from audit functions into engineering-driven reliability functions.
    Risk—not compliance—should be the central language for communicating with leadership teams.
    Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.”
    AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks.
    Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership.

    What You’ll Learn:
    Why Sheron believes compliance should be designed into products from day one
    How UiPath approaches continuous risk monitoring and GRC engineering
    Why AIUC-1 introduces a fundamentally different approach to AI assurance
    How GRC teams can become the “translation layer” between business and engineering
    Why future GRC practitioners must develop technical and systems-thinking skills

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guest:
    Sheron Chakalakal | Head of GRC | UiPath
    Connect on LinkedIn: https://www.linkedin.com/in/sheronpaulc/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave

    05-05-2026 | 54 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur, Principal of Security & Assurance Engineering at CoreWeave, to explore how AI-native infrastructure is fundamentally reshaping GRC.
    Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems.
    Key Takeaways:
    Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them.
    Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal.
    GRC must evolve into an infrastructure-level capability that continuously emits assurance signals.
    Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight.
    Future GRC teams must operate more like engineering and reliability functions rather than audit teams.
    What You’ll Learn:
    Why AI infrastructure makes traditional audits ineffective
    What “GRC as infrastructure” actually means in practice
    How to move from point-in-time audits to continuous assurance
    The difference between automation, CCM, and agentic GRC
    How to position GRC as a proactive, business-critical function
    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guest:
    Jasmine Kaur | Principal of Security & Assurance Engineering | CoreWeave
    Connect on LinkedIn: https://www.linkedin.com/in/jask31/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
Meer Technologie podcasts
Over Security & GRC Decoded
How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!
Podcast website

Luister naar Security & GRC Decoded, De Technoloog | BNR en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies