Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
News
Sports
TV & Film
About Us
Contact Us
Copyright
© 2024 PodJoint
Podjoint Logo
US
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/d8/c0/ef/d8c0efcf-65a4-0b08-720d-c832ec1cf9da/mza_12267530477940931406.jpg/600x600bb.jpg
Security & GRC Decoded
Raj Krishnamurthy
22 episodes
6 days ago
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...
Show more...
Technology
Business
RSS
All content for Security & GRC Decoded is the property of Raj Krishnamurthy and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...
Show more...
Technology
Business
Episodes (20/22)
Security & GRC Decoded
How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...
Show more...
6 days ago
57 minutes

Security & GRC Decoded
Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue
In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions. He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through ...
Show more...
2 weeks ago
1 hour

Security & GRC Decoded
Why GRC Is More Than Compliance with Kenneth Moras | Head of Security GRC | Plaid
In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Kenneth Moras, Head of Security GRC at Plaid. Kenneth shares his journey from web developer and pen tester to building GRC and assurance teams at scale across leading companies like Adobe, Meta, and now Plaid. The conversation explores how GRC must balance governance, risk, and compliance as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth ...
Show more...
1 month ago
1 hour 19 minutes

Security & GRC Decoded
“This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple
How does a software engineer become a GRC leader? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Varun Gurnaney, Staff Security Engineer at Apple. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies. He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From bui...
Show more...
1 month ago
53 minutes

Security & GRC Decoded
Risk in Dollars: The Future of GRC Measurement
How does a network engineer become a GRC leader? Ramya Subramanian’s journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC & Privacy Operations at Freshworks, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down. Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing...
Show more...
2 months ago
54 minutes

Security & GRC Decoded
Compliance ≠ Security: It Sets the Foundation ft Evan Millman, Security GRC Manager @ Abnormal AI
What’s the true relationship between compliance and security? According to Evan Millman, compliance may not be security—but it’s the necessary starting point for building it. In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at Abnormal.AI, lessons from scaling GRC in fast-moving environments, and practical advice for anyone try...
Show more...
2 months ago
1 hour 13 minutes

Security & GRC Decoded
Cyber Economics and Keeping Up with Innovation ft Trupti Shiralkar (Cybersecurity Leader & Advisor)
What trade-offs are you willing to make in cybersecurity? In this episode of Security & GRC Decoded, host Raj Krishnamurthy is joined by Trupti Shiralkar, a seasoned cybersecurity leader and Advisory Board Member at Backslash Security, to explore how risk, ROI, and real-world constraints shape modern security programs. With decades of experience across AppSec, security architecture, and risk governance, Trupti brings a rare blend of deep technical insight and strategic thinking. The...
Show more...
3 months ago
59 minutes

Security & GRC Decoded
Why Security And GRC Teams Must Act Like Service Teams ft Jiphun Satapathy from Medallia
Jiphun Satapathy has built and scaled security organizations at AWS, Snowflake, and now Medallia. In this episode, he joins our host Raj to explore the evolving role of CISOs as strategic business leaders. They discuss the importance of treating security as a service organization, how to handle vendor noise, and why insider risk is often overlooked. You’ll hear practical advice for security and GRC leaders working in AI-first, high-growth environments—and how to maintain trust across engineer...
Show more...
3 months ago
1 hour 14 minutes

Security & GRC Decoded
Preetam Joshi Breaks Down ML, LLMs, AI Agents, and Governance Challenges
How do you make sense of security, governance, and risk in an age of black-box AI? This week, Raj is joined by Preetam Joshi, founder of Aimon Labs and machine learning veteran with experience at DRDO, Yahoo, Netflix, and Thumbtack. Together, they break down the technical evolution behind large language models (LLMs), explore the real challenges of explainability, and discuss why GRC teams must rethink risk in the age of autonomous reasoning systems. Preetam brings a rare mix of hands-on ML e...
Show more...
3 months ago
58 minutes

Security & GRC Decoded
RGC, Not GRC: Why Risk Comes First ft Ricky Waldron
What if compliance wasn't just about passing audits—but about building trust from the ground up? In this powerful episode of Security & GRC Decoded, Raj sits down with Ricky Waldron, Director of Security Audit & GRC at Navan, whose GRC experience spans tech giants like Microsoft, Disney, Oracle, and Smartsheet. Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine ...
Show more...
4 months ago
1 hour 19 minutes

Security & GRC Decoded
What Does ‘Technical’ Even Mean in GRC? ft Alan Luk @ Grammarly
Is it time to stop pretending GRC is technical? Alan Luk makes the case for a new kind of compliance leader—and it might surprise you. In this sharp and unfiltered episode of Security & GRC Decoded, Alan Luk, Director of GRC at Grammarly (and former Microsoft and PwC leader), joins Raj to dismantle common myths about GRC—and why even your engineers might be thinking about it all wrong. Drawing from over 20 years of experience, Alan makes the case for why GRC should be seen as a program ma...
Show more...
4 months ago
1 hour 10 minutes

Security & GRC Decoded
No More Compliance Theater: Meet Real Security Compliance with Adam Brennick
Is it time to rethink SOC 2? (Spoiler: Adam thinks so—and he’s got the receipts.) In this insightful episode of Security & GRC Decoded, Adam Brennick, Director of Security Risk & Compliance at Cockroach Labs, joins Raj to challenge the status quo of SOC 2, compliance culture, and how GRC teams should operate in a modern, engineering-driven world. With a unique perspective from leading both security and GRC functions, Adam shares why today’s compliance efforts often miss the mark—and ...
Show more...
5 months ago
1 hour 19 minutes

Security & GRC Decoded
Can Compliance Be Cool? Harness's Andrew Spangler Thinks So
In this episode of Security and GRC Decoded, Raj Krishnamurthy sits down with Andrew Spangler, Director of Security and GRC at Harness, to explore how compliance engineering can go far beyond checkboxes—and actually drive innovation. Andrew shares his journey from building the compliance engineering function at Datadog to scaling automation and visibility across the SDLC at Harness. He dives into how using internal platforms for security workflows (aka “drinking your own champagne”) can unloc...
Show more...
5 months ago
54 minutes

Security & GRC Decoded
From Compliance to SBOMs: Josh Bressers’ Take on Security
In this episode, Raj Krishnamurthy sits down with Josh Bressers, VP of Security at Anchore and longtime leader in the open source security space. With decades of experience, Josh brings a candid and compelling perspective on everything from the chaos of early cybersecurity days to the nuanced challenges of SBOMs and compliance in today’s world. Josh reflects on how he entered the security world before there were formal certifications or programs, how community and curiosity fuel innovation in...
Show more...
6 months ago
1 hour 5 minutes

Security & GRC Decoded
From Cruise to Whatnot: Kieran Pierman’s GRC Playbook
In this episode, Raj Krishnamurthy sits down with Kieran Pierman, GRC & Security at Whatnot, and a former security, risk and compliance leader at Cruise and Dropbox, to explore fresh perspectives on Security & GRC. Kieran opens with a bold stance: data breaches, while critical, aren't the top threat they used to be. Instead, he argues, maintaining availability and service uptime is now paramount. Drawing from his unique experience building the foundational GRC program at Cruise, a pi...
Show more...
6 months ago
1 hour 2 minutes

Security & GRC Decoded
Is Your GRC Team Technical Enough? (Probably Not...) ft. Jeevan Singh @ Rippling
Ever wondered if your GRC team should be writing code? (Spoiler alert: Jeevan thinks they probably should.) In this eye-opening episode of Security & GRC Decoded, Jeevan Singh, Director of Security Engineering at Rippling, joins Raj to challenge traditional views of Governance, Risk, and Compliance (GRC). Jeevan passionately argues why GRC teams must become more technical, automated, and deeply integrated into engineering processes to truly protect and enable businesses. Drawing from his...
Show more...
7 months ago
1 hour 9 minutes

Security & GRC Decoded
Why GRC Teams Are Failing — And How to Fix It with Shobhit Mehta
In this episode, Raj Krishnamurthy interviews Shobhit Mehta, Director of Security and Compliance at Headspace, to uncover valuable insights into the evolving world of Governance, Risk, and Compliance (GRC). Shobhit shares his controversial perspective on GRC teams overburdening themselves, emphasizing the need for GRC professionals to expand their technical expertise and embrace a product management mindset. The conversation dives into proactive strategies for GRC success, the importance of ...
Show more...
7 months ago
55 minutes

Security & GRC Decoded
Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab
In this episode of Security & GRC Decoded, host Raj Krishnamurthy (CEO of ComplianceCow) sits down with Ayoub Fandi, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of GRC through an engineering lens. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing real-time data, automation, and developer-friendly p...
Show more...
8 months ago
52 minutes

Security & GRC Decoded
Security Unfiltered: Carlos Batista on GRC, Leadership, and Risk Realities
In this episode of Security & GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Carlos Batista—former CISO and AWS Security Engineering Leader—to explore the evolving landscape of security, governance, and risk management. Carlos shares his journey from leading security in highly regulated industries like banking and energy to championing large-scale security engineering at AWS. Together, they discuss how effective GRC programs can move beyond “checkbox” complianc...
Show more...
8 months ago
1 hour 2 minutes

Security & GRC Decoded
Security, Compliance & Customer Trust: The Evolution of GRC at Scale | feat. Abhay Kshirsagar from Salesforce
In this episode of Security & GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Abhay Kshirsagar, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of security, compliance, and customer assurance. Abhay shares his journey from IT audit and risk advisory to leading compliance automation, continuous monitoring, and customer assurance at industry giants like Cisco and now Salesforce. They discuss how compliance programs can...
Show more...
9 months ago
52 minutes

Security & GRC Decoded
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...