Episodes

  • Audit ≠ Security: Building Auditable Controls in a High-Velocity World ft Varun Prasad, Cloud Security & Privacy Assurance @ BDO
    Dec 30 2025

    Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil — but what if that mindset is holding security teams back? In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing link between fast-moving engineering teams and slow, annual audit cycles — and how organizations can stop treating audits as an afterthought and start using them as a trust-building mechanism.

    Key Takeaways:

    • Audits are designed to provide reasonable assurance, not eliminate all risk
    • The biggest failure in modern GRC is building controls that are automated but not auditable
    • Continuous controls monitoring only works if auditors can validate completeness and accuracy
    • Screenshots persist because they remain the clearest way to demonstrate system state over time
    • Security controls should be built to improve posture first — and explained clearly second

    What You’ll Learn:

    • Why audit skepticism is a feature, not a flaw
    • How internal and external audits serve fundamentally different purposes
    • Where continuous monitoring breaks down from an auditor’s perspective
    • What “auditable controls” actually mean in CI/CD environments
    • How AI can assist auditors without replacing human judgment

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Varun Prasad | Cloud Security & Privacy Assurance | BDO
    Connect on LinkedIn: https://www.linkedin.com/in/varunprasad/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts:

    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450


    Show More Show Less
    59 mins
  • Scaling GRC Without the Chaos: How to Build Programs That Don’t Break ft Tom Scuderi, Senior Manager of Security & GRC @ LTK
    Dec 16 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Tom Scuderi, Senior Manager of Security & GRC at LTK and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen—not dilute—your security program, and how to anchor leadership decisions with meaningful risk data.

    Key Takeaways

    • GRC only scales when its processes mirror how engineering teams already work.
    • SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise.
    • Curated visibility reduces friction and improves cross-functional trust.
    • Clarity in ownership is the backbone of a scalable GRC function.
    • Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program.

    What You’ll Learn

    • How Tom built and matured GRC programs across four different companies.
    • Why engineering alignment is essential for sustainable compliance.
    • How curated visibility replaces access sprawl and accelerates audits.
    • The difference between risk-driven and compliance-driven GRC.
    • Why automation only works when underlying processes are mature.
    • How to structure ownership to reduce bottlenecks during SOC 2 and similar frameworks.

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Tom Scuderi | Senior Manager of Security & GRC | LTK
    Connect on LinkedIn: https://www.linkedin.com/in/tom-scuderi/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify:

    https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683


    Apple Podcasts:

    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450


    #SecurityAndGRCDecoded #RajKrishnamurthy #TomScuderi #LTK #GRC #ScalingGRC #SOC2 #EngineeringAlignment #RiskManagement #SecurityLeadership #Compliance #GovernanceRiskCompliance #SecurityGRCPodcast #ComplianceCow


    Show More Show Less
    56 mins
  • Controls Are Promises: Rethinking GRC for Modern Security ft Sergio Alonso @ Rapid7
    Dec 2 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Sergio Alonso, a seasoned GRC and information security leader at Rapid7, whose 17–year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls should be treated as “promises” that teams must honor every day. This conversation explores scaling GRC in high-velocity environments, reducing compliance fatigue, applying zero-knowledge principles to trust, and building the next generation of context-driven risk programs.


    Key Takeaways

    • Automation is the only sustainable path to scaling GRC without increasing friction.
    • Controls should be viewed as “promises,” and audits as the consequence of keeping or breaking them.
    • Context — technical, business, and risk — is the primary driver of effective triage and prioritization.
    • GRC must evolve from a legacy function into a trust-driven, engineering-aligned discipline.
    • Zero-knowledge-style thinking may define the future of transparency and customer trust.

    What You’ll Learn

    • How to adapt legacy compliance experience for cloud, SaaS, and fast-moving tech companies.
    • Why automation, evidence APIs, and GRC engineering are becoming non-negotiable.
    • How to reduce compliance fatigue using “meet once, meet many” principles.
    • Why context is the key to reducing noise from security tools.
    • How to partner with engineers using empathy, clarity, and strong framing.
    • Why trust and transparency are reshaping GRC inside cybersecurity companies.

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Sergio Alonso | GRC & Information Security Leader | Rapid7
    Connect on LinkedIn: https://www.linkedin.com/in/salonsor/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5xuvsT8HdJsa2sbhAFZQhL

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450


    Show More Show Less
    56 mins
  • How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime
    Nov 13 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Mukund Sarma, Deputy CISO and Head of Product Security at Chime, to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity.


    5 Key Takeaways

    • GRC isn’t a blocker—it’s a mirror that keeps security honest and accountable.
    • Strong security engineering automatically strengthens compliance outcomes.
    • Friction between security and engineering fades when empathy drives collaboration.
    • “Shift left” works best when paved paths and automation support developers.
    • Practical controls and continuous validation create sustainable, scalable governance.

    What You’ll Learn

    • How to bridge silos between security, GRC, and engineering teams.
    • Why automation and continuous control monitoring are the future of compliance.
    • What “practical controls” really mean in modern DevSecOps environments.
    • How empathy and communication transform security culture.
    • Why compliance should follow great security engineering, not lead it.
    • Real-world examples from Chime’s approach to product security.

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Mukund Sarma | Deputy CISO and Head of Product Security | Chime
    Connect on LinkedIn: https://www.linkedin.com/in/sarmamukund/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:
    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr
    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569


    Show More Show Less
    57 mins
  • How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta
    Oct 30 2025

    How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.

    He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.


    5 Key Takeaways

    • Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are.
    • Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works.
    • Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits.
    • Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.
    • Define the Right Role: The best GRC teams act as a sparring partner --challenging, supportive, and focused on outcomes.

    What You’ll Learn

    • How to rebuild trust with engineering after “audit fatigue”
    • Practical ways to convert control requirements into product language
    • How to design evidence from logs, pipelines, and tickets you already have
    • When to push, when to partner, and how to escalate with credibility
    • Communicating risk trade-offs without killing roadmap velocity

    Connect With Our Guest:
    Tristan Ingold | Security GRC Program Manager | Meta


    This podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    Watch more episodes

    Rate, review, and share if you enjoyed the show!


    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts

    Show More Show Less
    57 mins
  • Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue
    Oct 16 2025

    In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions.

    He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned.


    Key Takeaways

    1. CRQ doesn’t require perfection—start with what you have and refine over time.
    2. The most effective risk programs focus on directionally correct data, not precision.
    3. Good risk scenarios clearly define asset, threat, and effect to avoid misalignment.
    4. Generative AI accelerates scenario development, data research, and model creation.
    5. CISOs should demand more from risk teams—move beyond “pick a color” heat maps.


    Topics Covered

    • Cyber risk quantification (CRQ)
    • Monte Carlo simulations and modeling
    • Risk scenario design and measurement
    • GRC and compliance integration
    • Generative AI in risk management
    • Moving from qualitative to quantitative risk
    • Improving risk hygiene and maturity
    • CISO leadership and risk culture

    What You’ll Learn

    • The difference between qualitative and quantitative risk methods
    • How to conduct your first risk quantification in Excel
    • Why Monte Carlo simulations are simpler than most think
    • How GRC, compliance, and security teams can collaborate effectively
    • The six levers that influence risk magnitude and frequency

    This podcast is brought to you by ComplianceCow:

    ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business.

    Learn more at ComplianceCow.com


    Connect with our guest: Tony Martin-Vegue on LinkedIn

    • Co-Chair, FAIR Institute San Francisco Chapter
    • Former Risk Leader at Netflix and Gap Inc.
    • Author, From Heat Maps to Histograms (coming 2026)

    Subscribe to Security & GRC Decoded on your favorite platform:

    • Spotify
    • Apple Podcasts
    • Explore all episodes: ComplianceCow.com/podcast



    Show More Show Less
    1 hr
  • Why GRC Is More Than Compliance with Kenneth Moras | Head of Security GRC | Plaid
    Oct 2 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Kenneth Moras, Head of Security GRC at Plaid. Kenneth shares his journey from web developer and pen tester to building GRC and assurance teams at scale across leading companies like Adobe, Meta, and now Plaid.

    The conversation explores how GRC must balance governance, risk, and compliance as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth also dives into the origins of the Adobe Common Control Framework (CCF), co-authoring the Open Finance Data Security Standard (OFDSS), and how Plaid applies these principles to secure the future of fintech.

    From reducing GRC toil through engineering and automation, to the role of AI and LLMs in risk management, Kenneth makes the case that GRC isn’t just about passing audits — it’s about building trust, reducing risk, and enabling innovation.


    🔑 5 Key Takeaways

    • 🌐 Career Evolution: Kenneth’s path from developer to GRC leader shows how diverse skills — from IT audit to consulting — strengthen risk leadership.

    • 🏗️ Building Frameworks: Adobe CCF and OFDSS highlight the importance of reducing complexity and standardizing security controls for scalability.

    • ⚖️ Governance vs. Risk vs. Compliance: These functions are distinct but must operate in harmony; misalignment creates organizational risk.

    • 🤖 AI in GRC: Generative AI and MCP tools are shifting GRC from “click ops” to “chat ops,” enabling faster risk assessment and reducing toil.

    • 🚀 GRC as an Enabler: Done right, GRC accelerates innovation by providing clarity, trust, and measurable security benefits.


    📘 What You’ll Learn

    • How to build a GRC program from scratch in a hyper-growth company.

    • Why governance, risk, and compliance require unique skill sets but interlock as checks and balances.

    • The story behind Adobe’s CCF and why Plaid open-sourced OFDSS.

    • How AI and automation are changing GRC engineering and risk management.

    • What Kenneth looks for when hiring the next generation of GRC professionals.

    📺 Watch more episodes: https://www.compliancecow.com/podcast

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: www.compliancecow.com


    🔗 Connect With Our Guest:
    Kenneth Moras | Head of Security GRC at Plaid


    ⭐ Stay Connected:

    Rate, review, and subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts

    Show More Show Less
    1 hr and 19 mins
  • “This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple
    Sep 11 2025

    How does a software engineer become a GRC leader? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Varun Gurnaney, Staff Security Engineer at Apple. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies.

    He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale.

    🔑 5 Key Takeaways

    • Compliance ≠ Security: Passing audits is not enough — engineering-driven GRC is the future.
    • Start Small: Automate one control well to prove value before scaling automation.
    • Bridging Teams: Cultural friction between engineering, security, GRC, and audit is real — empathy and communication reduce the pain.
    • Audit Anxiety: Audit automation is about reducing anxiety and toil as much as passing audits.
    • GRC Engineering is a Discipline: Whether it lives inside GRC or security, automation is now essential.

    📚 What You’ll Learn

    • How Varun transitioned from software engineering into GRC leadership
    • Why compliance automation looks different for SMBs, mid-market, and enterprises
    • The technical and cultural blockers between engineering and GRC
    • Practical strategies for proving automation value internally
    • How generative AI and coding agents will shape audit and compliance automation

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    📺 Watch more episodes and learn from top leaders in the GRC space!


    Connect With Our Guest:
    Varun Gurnaney | Staff Security Engineer | Apple

    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts
    Show More Show Less
    54 mins