Episodes

  • How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime
    Nov 13 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Mukund Sarma, Deputy CISO and Head of Product Security at Chime, to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity.


    5 Key Takeaways

    • GRC isn’t a blocker—it’s a mirror that keeps security honest and accountable.
    • Strong security engineering automatically strengthens compliance outcomes.
    • Friction between security and engineering fades when empathy drives collaboration.
    • “Shift left” works best when paved paths and automation support developers.
    • Practical controls and continuous validation create sustainable, scalable governance.

    What You’ll Learn

    • How to bridge silos between security, GRC, and engineering teams.
    • Why automation and continuous control monitoring are the future of compliance.
    • What “practical controls” really mean in modern DevSecOps environments.
    • How empathy and communication transform security culture.
    • Why compliance should follow great security engineering, not lead it.
    • Real-world examples from Chime’s approach to product security.

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Mukund Sarma | Deputy CISO and Head of Product Security | Chime
    Connect on LinkedIn: https://www.linkedin.com/in/sarmamukund/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:
    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr
    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569


    Show More Show Less
    57 mins
  • How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta
    Oct 30 2025

    How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.

    He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.


    5 Key Takeaways

    • Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are.
    • Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works.
    • Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits.
    • Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.
    • Define the Right Role: The best GRC teams act as a sparring partner --challenging, supportive, and focused on outcomes.

    What You’ll Learn

    • How to rebuild trust with engineering after “audit fatigue”
    • Practical ways to convert control requirements into product language
    • How to design evidence from logs, pipelines, and tickets you already have
    • When to push, when to partner, and how to escalate with credibility
    • Communicating risk trade-offs without killing roadmap velocity

    Connect With Our Guest:
    Tristan Ingold | Security GRC Program Manager | Meta


    This podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    Watch more episodes

    Rate, review, and share if you enjoyed the show!


    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts

    Show More Show Less
    57 mins
  • Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue
    Oct 16 2025

    In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions.

    He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned.


    Key Takeaways

    1. CRQ doesn’t require perfection—start with what you have and refine over time.
    2. The most effective risk programs focus on directionally correct data, not precision.
    3. Good risk scenarios clearly define asset, threat, and effect to avoid misalignment.
    4. Generative AI accelerates scenario development, data research, and model creation.
    5. CISOs should demand more from risk teams—move beyond “pick a color” heat maps.


    Topics Covered

    • Cyber risk quantification (CRQ)
    • Monte Carlo simulations and modeling
    • Risk scenario design and measurement
    • GRC and compliance integration
    • Generative AI in risk management
    • Moving from qualitative to quantitative risk
    • Improving risk hygiene and maturity
    • CISO leadership and risk culture

    What You’ll Learn

    • The difference between qualitative and quantitative risk methods
    • How to conduct your first risk quantification in Excel
    • Why Monte Carlo simulations are simpler than most think
    • How GRC, compliance, and security teams can collaborate effectively
    • The six levers that influence risk magnitude and frequency

    This podcast is brought to you by ComplianceCow:

    ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business.

    Learn more at ComplianceCow.com


    Connect with our guest: Tony Martin-Vegue on LinkedIn

    • Co-Chair, FAIR Institute San Francisco Chapter
    • Former Risk Leader at Netflix and Gap Inc.
    • Author, From Heat Maps to Histograms (coming 2026)

    Subscribe to Security & GRC Decoded on your favorite platform:

    • Spotify
    • Apple Podcasts
    • Explore all episodes: ComplianceCow.com/podcast



    Show More Show Less
    1 hr
  • Why GRC Is More Than Compliance with Kenneth Moras | Head of Security GRC | Plaid
    Oct 2 2025

    In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Kenneth Moras, Head of Security GRC at Plaid. Kenneth shares his journey from web developer and pen tester to building GRC and assurance teams at scale across leading companies like Adobe, Meta, and now Plaid.

    The conversation explores how GRC must balance governance, risk, and compliance as distinct but interdependent functions — and why great programs require clarity, collaboration, and simplicity. Kenneth also dives into the origins of the Adobe Common Control Framework (CCF), co-authoring the Open Finance Data Security Standard (OFDSS), and how Plaid applies these principles to secure the future of fintech.

    From reducing GRC toil through engineering and automation, to the role of AI and LLMs in risk management, Kenneth makes the case that GRC isn’t just about passing audits — it’s about building trust, reducing risk, and enabling innovation.


    🔑 5 Key Takeaways

    • 🌐 Career Evolution: Kenneth’s path from developer to GRC leader shows how diverse skills — from IT audit to consulting — strengthen risk leadership.

    • 🏗️ Building Frameworks: Adobe CCF and OFDSS highlight the importance of reducing complexity and standardizing security controls for scalability.

    • ⚖️ Governance vs. Risk vs. Compliance: These functions are distinct but must operate in harmony; misalignment creates organizational risk.

    • 🤖 AI in GRC: Generative AI and MCP tools are shifting GRC from “click ops” to “chat ops,” enabling faster risk assessment and reducing toil.

    • 🚀 GRC as an Enabler: Done right, GRC accelerates innovation by providing clarity, trust, and measurable security benefits.


    📘 What You’ll Learn

    • How to build a GRC program from scratch in a hyper-growth company.

    • Why governance, risk, and compliance require unique skill sets but interlock as checks and balances.

    • The story behind Adobe’s CCF and why Plaid open-sourced OFDSS.

    • How AI and automation are changing GRC engineering and risk management.

    • What Kenneth looks for when hiring the next generation of GRC professionals.

    📺 Watch more episodes: https://www.compliancecow.com/podcast

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: www.compliancecow.com


    🔗 Connect With Our Guest:
    Kenneth Moras | Head of Security GRC at Plaid


    ⭐ Stay Connected:

    Rate, review, and subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts

    Show More Show Less
    1 hr and 19 mins
  • “This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple
    Sep 11 2025

    How does a software engineer become a GRC leader? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Varun Gurnaney, Staff Security Engineer at Apple. Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies.

    He discusses the cultural and technical gaps between security, engineering, GRC, and audit — and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale.

    🔑 5 Key Takeaways

    • Compliance ≠ Security: Passing audits is not enough — engineering-driven GRC is the future.
    • Start Small: Automate one control well to prove value before scaling automation.
    • Bridging Teams: Cultural friction between engineering, security, GRC, and audit is real — empathy and communication reduce the pain.
    • Audit Anxiety: Audit automation is about reducing anxiety and toil as much as passing audits.
    • GRC Engineering is a Discipline: Whether it lives inside GRC or security, automation is now essential.

    📚 What You’ll Learn

    • How Varun transitioned from software engineering into GRC leadership
    • Why compliance automation looks different for SMBs, mid-market, and enterprises
    • The technical and cultural blockers between engineering and GRC
    • Practical strategies for proving automation value internally
    • How generative AI and coding agents will shape audit and compliance automation

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    📺 Watch more episodes and learn from top leaders in the GRC space!


    Connect With Our Guest:
    Varun Gurnaney | Staff Security Engineer | Apple

    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    • Spotify
    • Apple Podcasts
    Show More Show Less
    54 mins
  • Risk in Dollars: The Future of GRC Measurement
    Sep 4 2025

    How does a network engineer become a GRC leader? Ramya Subramanian’s journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC & Privacy Operations at Freshworks, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down.

    Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing to business enabler. This episode is a playbook for anyone trying to modernize risk and compliance in fast-moving environments.


    5 Key Takeaways

    • Engineer’s edge in GRC: Why Ramya’s technical background makes her approach to governance unique.
    • Quantifying risk with dollars: Why risk measurement needs financial context, not just “likelihood x impact.”
    • Automation as a path forward: How Freshworks is reducing compliance toil for engineers.
    • Simplify policies and awareness: Cutting policy docs by 90% and building bite-sized security training.
    • GRC as PR: Storytelling and evangelism can reframe GRC as a business enabler, not a blocker.

    What You’ll Learn

    • How GRC and security complement each other
    • Challenges of risk quantification and continuous measurement
    • Why engineers perceive GRC as compliance tax
    • How automation and GRC engineering can reduce manual effort
    • The cultural perception of GRC and how to change it

    ⏱️ (Approximate) Timestamps

    [00:01:43] From network engineer to GRC leader
    [00:03:37] How Ramya defines Governance, Risk, and Compliance
    [00:05:28] Quantifying risk: from controls to financial impact
    [00:07:41] Why continuous risk measurement is so hard
    [00:11:49] How others perceive GRC inside organizations
    [00:13:43] Changing the “policing” perception of GRC
    [00:17:50] Rewriting policies & security awareness at Freshworks
    [00:19:38] Bringing auditors along the journey
    [00:21:33] Reducing compliance tax with automation
    [00:26:10] Why GRC needs engineering skills
    [00:29:58] Technical vs non-technical sides of GRC
    [00:31:47] Skills Ramya looks for when hiring
    [00:33:53] Generative AI’s impact on GRC
    [00:37:49] Dream GRC solution: context-aware automation
    [00:39:32] Building a business case for automation
    [00:44:00] Who should tell the GRC automation story?
    [00:45:54] Challenges with auditors in the AI era
    [00:46:49] From city editor to GRC leader — storytelling roots
    [00:52:26] Rajinikanth’s influence at Freshworks

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: compliancecow.com

    Connect With Our Guest:

    Ramya Subramanian | Director of GRC & Privacy Operations | Freshworks
    Connect on LinkedIn

    Rate, review, and share if you enjoyed the show!
    Subscribe to
    Security & GRC Decoded wherever you get your podcasts:

    Spotify and Apple Podcasts

    Show More Show Less
    55 mins
  • Compliance ≠ Security: It Sets the Foundation ft Evan Millman, Security GRC Manager @ Abnormal AI
    Aug 21 2025

    What’s the true relationship between compliance and security? According to Evan Millman, compliance may not be security—but it’s the necessary starting point for building it.

    In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at Abnormal.AI, lessons from scaling GRC in fast-moving environments, and practical advice for anyone trying to align controls with business objectives.


    5 Key Takeaways:

    • Compliance is not the destination — but it is the framework for real security conversations.
    • Say no to overkill — Right-size controls based on business needs, not frameworks.
    • Decentralized GRC works — but only if there’s shared ownership and trust.
    • “GRC therapy” is real — and it starts with building internal relationships.
    • Metrics matter — but only when they tell a story that drives action.


    What You’ll Learn:

    • Why compliance ≠ security (but still matters)
    • The pitfalls of checklist-first GRC programs
    • How to build GRC partnerships across product and engineering teams
    • Why business-aligned storytelling is the future of risk communication
    • How Abnormal Security approaches frameworks like SOC 2 and ISO 27001

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: compliancecow.com

    Connect With Our Guest:

    Evan Millman | Security GRC Manager | Abnormal AI
    Connect on LinkedIn

    Rate, review, and share if you enjoyed the show!
    Subscribe to
    Security & GRC Decoded wherever you get your podcasts:

    Spotify and Apple Podcasts


    🕒 (Approximate) Timestamps

    [00:02:40] What makes Evan passionate about security GRC?
    [00:04:30] How compliance ≠ security — and why that distinction matters
    [00:06:50] When GRC goes wrong: overkill, checklists, and inefficiency
    [00:10:15] Building trust by embedding security into product discussions
    [00:14:40] Right-sizing controls: starting with SOC 2 vs ISO 27001
    [00:18:10] Managing a decentralized GRC team at Abnormal
    [00:23:02] Metrics and storytelling — what the board actually wants
    [00:29:45] Why GRC leaders need emotional intelligence and empathy
    [00:35:20] What GRC professionals can learn from product managers
    [00:39:11] Evan’s advice to vendors trying to break into GRC
    [00:41:05] How GRC can (and should) enable product velocity
    [00:44:55] If he could wave a magic wand, what would Evan fix in GRC?


    Show More Show Less
    1 hr and 14 mins
  • Cyber Economics and Keeping Up with Innovation ft Trupti Shiralkar (Cybersecurity Leader & Advisor)
    Aug 7 2025

    What trade-offs are you willing to make in cybersecurity?
    In this episode of Security & GRC Decoded, host Raj Krishnamurthy is joined by Trupti Shiralkar, a seasoned cybersecurity leader and Advisory Board Member at Backslash Security, to explore how risk, ROI, and real-world constraints shape modern security programs. With decades of experience across AppSec, security architecture, and risk governance, Trupti brings a rare blend of deep technical insight and strategic thinking.

    They dive into cyber economics, AI-driven tooling, and why security storytelling may soon matter more than fear-based metrics. Whether you're a security veteran or just entering the space, this is a must-listen on staying relevant and effective in the age of automation.

    5 Key Takeaways

    • Cybersecurity is about trade-offs – No org can secure everything; knowing what to ignore is just as critical.
    • LLMs can’t fully replace layered defense – Copilots help, but context and reachability still matter.
    • ROI matters more than ever – Security teams must prove business value in language execs understand.
    • Storytelling wins boardrooms – Fear, uncertainty, and doubt (FUD) is out. Framing risk with narrative is in.
    • Reinvent or be replaced – AI won’t eliminate jobs—it’ll replace outdated versions of them.


    What You’ll Learn

    • How cyber economics helps frame decision-making
    • The evolving role of LLMs and software composition tools in vulnerability management
    • Why OWASP hasn’t solved insecure code after decades
    • How to prioritize reachability over volume
    • What developers and security pros should focus on to stay relevant

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: compliancecow.com

    Connect With Our Guest:

    Trupti Shiralkar | Advisory Board Member, Backslash Security
    Connect on LinkedIn

    Rate, review, and share if you enjoyed the show!
    Subscribe to
    Security & GRC Decoded wherever you get your podcasts:

    Spotify and Apple Podcasts

    Timestamps (Approx)

    [00:00] Intro
    [02:47] Why cyber economics goes beyond traditional budgeting
    [06:10] Introduction of grey swan events and the need for proactive innovation
    [10:10] Aligning compliance and security using LLMs
    [16:56] Reducing cognitive load in cybersecurity decision-making
    [20:00] Budgeting for innovation: Lessons from Trupti’s past security leadership
    [23:00] Difference between cyber economics and cyber risk quantification
    [33:50] The misunderstood strategic role of GRC
    [54:30] How meditation and mindfulness help navigate the security world
    [57:15] Trupti’s final shout-outs to historic and modern tech inspirations

    Show More Show Less
    1 hr