The GRC Engineering Club's AntiCheckBox Podcast

Dr. Omar Sangurima

Compliance became a documentation ritual somewhere along the way. Screenshots, spreadsheets, a scramble every quarter, and a piece of paper at the end that tells you almost nothing about whether the control actually works. That job is getting automated out from under the people doing it, and good riddance. The AntiCheckbox Podcast is about the other version of this work. Controls as a data and engineering problem. Evidence that generates itself. Governance you can defend to a regulator, a board, or a plaintiff's attorney because the system produces the proof, not because somebody filled in a cell. Every week we sit down with the practitioners actually building this way. Auditors who got tired of asking for screenshots and learned to write code. Engineers who got handed a framework and refused to accept that it had to be miserable. The people writing the standards, the people running programs at scale, and the ones who lived through the audit that changed how they think. No vendor pitches. No certification worship. No pretending the current model is fine. If you work in GRC, security, risk, audit, privacy, or you are trying to get into any of it and cannot get a straight answer from anybody, this is for you. The show is the front door to the GRC Engineering Club, a community of practitioners doing this work in the open. Early episodes, the Slack, and The Convergence newsletter live at patreon.com/c/GRCEngineeringClub.

Episodes

  1. Oct 3

    AI Agents Will Use Every Permission You Give Them | Guest: Dan Barahona

    AI agents will use every permission you give them. Dan Barahona co-founded APIsec University and built it to more than 150,000 students. Now he runs AI Security University, where every course is free. On this episode of the AntiCheckbox Podcast, he makes the case for managing agents like employees, then names the place that comparison breaks: agents have no judgment. We start with the basics for anyone newer to the field. What an API is, and why Dan says we are not in a post API world but a hyper API world. APIs now have a new consumer, and it can press the same button ten thousand times. From there we get into permission creep, how shortcuts taken while vibe coding on a laptop end up in production, and why a guardrail that has to hold cannot live inside a model that is nondeterministic by design. Then the part that lands on GRC and third party risk. We vet vendors with pen test results, ISO certifications, and SOC 2 reports. An agent skill is instructions written in plain English. What is your review process scanning for there? Dan also makes the case for AI literacy beyond the security team, for the HR, finance, and operations staff who can now connect tools in seconds. KEY TAKEAWAYS We are not in a post API world. AI agents are a new consumer of your APIs, and they do not behave like people. Manage agents like employees: onboard them, credential them, monitor them, review them, and fire them when they fail. Agents have no judgment. A person handed excess permissions may never touch them. An agent will use all of them. Permission creep often starts on a laptop. Hard coded keys from a local prototype ship to production with the tool. Telling a model not to do something is not a control. A guardrail that has to hold belongs outside the model. Security teams should be the earliest adopters, so they understand a tool before the business asks to use it. An agent skill is plain English instructions. Vendor due diligence built around code and attestations does not cover it yet. AI literacy is everyone's job now. Shadow AI, data pasted into prompts, and meeting note takers are everyday risks. The EU AI Act requires organizations that provide or deploy AI to take measures supporting AI literacy for their staff. When an employee causes harm, ask where the protections, monitoring, and training were before blaming the employee. If it goes out under your name, it is your output, no matter which model wrote it. Match your review to the stakes. Free training can be sustainable. AI Security University keeps courses free for students and funds them through corporate training. FIND DAN BARAHONA LinkedIn: https://www.linkedin.com/in/rdbarahona/ AI Security University: https://aisec.university Free courses: https://aisec.university/courses Dan's site: https://danbarahona.com #AISecurity #GRCEngineering #AIGovernance #AgenticAI #APISecurity #ThirdPartyRisk #Cybersecurity #GRC #AntiCheckbox

  2. Sep 26

    Cybersecurity Doesn't Have An Interest Problem. It Has An Entry Problem | Harsh Kashiparekh

    Cybersecurity does not have an interest problem. It has an entry problem. Harsh Kashiparekh, founder of Securis360 and a former PwC risk and compliance consultant, built Securis Academy around that gap. His model goes straight to the security vendors, asks for not for resale seats on their platforms, and puts those seats in front of students at community colleges and universities before they ever apply for a job. Josh Mason, former Air Force pilot and founder of Noob Village at DEF CON, joins for the first part of the conversation with the structural argument. Accreditation requires a school to build a full, fixed path to a diploma, and security content changes faster than that model can serve on its own. Lauren Alex-Igwe co-hosts. She started as an IT auditor and pushes on the catch-22 every newcomer knows: you need experience to get the experience. We also get into the part most training companies would rather skip. How do you keep your compass pointed north in a space full of people selling shortcuts? Josh draws a hard line between two ways of funding this work and names what each one forces you to accept. Harsh explains why his courses are not free, on purpose. He also walks through which schools keep saying no, which ones say yes, and where this goes next, including a corporate version where a company picks its own stack and trains its team on it. One piece of news in this one. Securis Academy is building prep training for the GRC Engineering Club certifications and taking it into the university network it already works with. KEY TAKEAWAYS The workforce gap is an entry problem. People want in. The path in is the bottleneck. Vendors want students trained on their platforms. Twenty not for resale seats for a university is an easy yes for a lot of them. University accreditation locks in a full path. Security content moves faster than that path can be rewritten. Large universities have been slow to let third parties into their ecosystem. Community colleges have been the fastest to say yes. Real environments mix vendors, so training should be tool agnostic too. Consulting firms, including twenty person shops, are the natural hiring pull for students who have already touched the tools. No access to a tool is not a reason to skip it. Learn what the platform does and what its output looks like. New privacy laws are creating demand for privacy roles faster than anyone is training people to fill them. From the buyer side, one place to train blue team, threat intel, and GRC staff on different stacks beats managing five training vendors. FIND HARSH KASHIPAREKH LinkedIn: https://www.linkedin.com/in/harsh-kashiparekh-cisa-a4961528/ Securis360: https://securis360.com Securis Academy: https://securisacademy.com FIND JOSH MASON Noob Village: https://noobvillage.org #CybersecurityCareers #GRCEngineering #Cybersecurity #GRC #CyberSecurityTraining #WorkforceDevelopment #NoobVillage #AntiCheckbox

  3. Sep 20

    The People Getting Recruited In GRC Are Not More Experienced Than You | Guest: Dex Copeland

    Dex Copeland writes the GRC Engineering Club curriculum and runs the live sessions. He also walked into a senior GRC engineering interview, got asked what happens when a policy and the system it governs fall out of sync, and could not answer it. He did not get the job. Then he went and built the policy as code trainer that club members learn from now. He walks through all of it on this episode, including a ranking that will annoy half of cybersecurity: experience first, certification second, degree last. Lauren Alex-Igwe co-hosts and pushes him on the part most career advice skips. If two people both have real experience and only one of them gets recruited, what is actually different between them? Dex has an answer, and it has almost nothing to do with skill. We also get into where certifications stop working. His position is that a cert says you knew something at a point in time, and if you are not doing the work, the knowledge decays while the credential stays on your profile. He contrasts that with the CGE-P model, where the capstone ships on GitHub, and argues that hands on validation is a wake up call the wider certification industry has not answered yet. That is a pointed thing to say on a channel that runs its own certifications, and he says it anyway. The last stretch goes somewhere we did not plan. Four days at a beach with no desktop, no Claude, no GitHub, and Dex came back with a clear view of what AI governance is actually for. Not the framework. The people who have been doing the work for years and are afraid of what gets built next. KEY TAKEAWAYS Experience ranks first because it is where the friction is. Problem solving, conflict resolution, translating between technical and non technical people. A certification says you passed a test. Experience says you did the thing. The gap between people who apply for jobs and people who get recruited is usually not skill. One of them is better at showing the work in public. Chase certifications without doing the work and the knowledge decays while the credential stays on the profile. Contractors with twenty years on the job are opting out of mandated certs rather than pay to prove something their record already proves. You can tell within minutes whether someone teaching a course actually understands the material or is reading slides they did not write. The strongest signal that someone is ready to be coached is that they struggled first and can say exactly where they got stuck. Failing an interview question is a curriculum input, not an embarrassment. AI should augment the people already doing the work, not build the thing that makes them look replaceable. Transparency and review on AI output is the line between a deliverable and slop. Knowing when to stop is a skill, and nobody building something they care about comes by it naturally. FIND DEX COPELAND https://www.linkedin.com/in/dexcopeland/ CO-HOSTED BY LAUREN ALEX-IGWE https://www.linkedin.com/in/lauren-alex-igwe-18a66816b/ #GRC #GRCEngineering #CyberSecurityCareers #PolicyAsCode #AIGovernance #ComplianceAutomation #CISSP #CareerAdvice #Mentorship #GRCJobs

  4. Sep 13

    Ten Years In GRC Without A Single Certification | Guest: Pradeep Reddy

    Pradeep Reddy went ten years into his career before he pursued a single certification. Twelve years in now, he has spent the last four mentoring people trying to break into GRC and security, and this episode is the closest thing we have published to an operating manual for that, on both sides of the call. His path was not a straight line. STEM, then commerce, then a master's in finance, then IT audit at KPMG almost by accident, third line of defense to second line, and eventually into information security risk management. Nobody along the way told him he needed a lead auditor cert or a CISA to have a career, and one of his early mentors gave him a piece of advice about credentials and careers that he still repeats. His position on learning is that it counts in any form. A podcast, a YouTube playlist, an article, somebody's LinkedIn timeline, a breach report you read closely enough to understand the root cause. What makes this one useful is that he has actually built a process. There is an intake step before the first call ever happens. There is documentation, because he ran it as a loose series of calls for a year and it did not work. There is a hiring calendar most people ignore. And there is a hard line on what a mentor can and cannot promise you, which is where we pushed him hardest. KEY TAKEAWAYS Why he asks for a set of answers in writing before the first mentoring call, and what those answers tell him. The thing that makes him tell somebody they are not ready yet. It is not skill level. Why he stopped running mentorship as a string of calls after a year of it not working, and what he replaced it with. The hiring calendar. Why January and February are slow, why March is the real deadline, and how far ahead of it you need to start. Using the NIST NICE framework to mentor. Start from the role somebody wants, work backward to the skills that role actually requires, and stop re-teaching the basics they already have. His pitch to employers: alongside the performance manager who evaluates you, put somebody whose only job is guidance, and the difference between advice from 30,000 feet and advice from 1,000 feet. How to spot a mentorship program that is working you. He is generous about it. We were less generous. What he says to anybody who asks him for a job guarantee, which is shorter and blunter than you would expect from him. Why he corrects people who say cybersecurity when they mean information security, and why that distinction matters on day one. What he actually gets out of mentoring. His answer is about a generational shift and it is not the answer most people give. FIND PRADEEP LinkedIn: https://www.linkedin.com/in/infosecpradeep/ #CyberSecurityCareers #GRC #Mentorship #GRCEngineering #AntiCheckbox #CyberSecurity #InfoSec #CareerChange #ITAudit #NICEFramework

  5. Sep 10

    ISO 42001 will not make your AI safer | Guest: James Kavanagh

    James Kavanagh led the program that earned Amazon Web Services the first ISO 42001 certification of any global cloud provider. Then he sat down with us and said it plainly: you can implement that standard end to end and still not move the safety or the security of the systems you actually operate. Adding more standards does not fix it either. That is not a cheap shot at ISO. It is a shot at what he calls static governance, the belief that you can hold a system still, check it once a year, and call the result assurance. James spent 25 years across Microsoft and Amazon in engineering, security and regulatory roles, including the AWS team whose job was to understand every law and regulation on earth, translate it backward into engineering, and get the engineers to answer back in assurance language. Before any of that he was a chemical engineer designing plants and running operators through simulated disasters, which turns out to be the whole point. His argument is that an AI system is not just complicated. It is complex, it has emergent behavior, and it is unbounded, and we are standing inside the box we keep trying to draw around it. He calls the alternative adaptive governance, and he says it works at ten people and at Amazon scale. We pushed on the part that matters to this audience. If the standard is not the answer, what is. If your engineers are never going to read the impact assessment, what were we producing it for. And where exactly did cyber learn its lessons, given that the things we already knew keep getting relearned every five years. KEY TAKEAWAYS Adaptive governance, defined without the buzzwords: build governance that changes at the same rate as the system you are governing. Complicated, complex, unbounded. Why the third one is what actually breaks the annual audit model. Technical problems versus adaptive problems. An adaptive leadership frame you can use with your team on Monday. The behavioral model that scales down to a ten person shop: encourage, coach, sanction, and why the default response to bad behavior should be that you designed the system wrong. Three tiers of compliance behavior. Checkbox compliance, high integrity compliance, and a third tier that is worse than both. Why engineers never read the 50 page impact assessment, and what breaks when the management system and the engineering never meet. What actually made cyber more secure, and why it was not FedRAMP and it was not more prescriptive requirements. The engineering design rule every safety discipline treats as rule zero, and where AI at global scale is currently violating it. Straight career talk. AI governance is not a niche, it is not easy money, and right now the field has no experts. FIND JAMES LinkedIn: https://www.linkedin.com/in/jameskavanagh1/ AI Career Pro: https://governance.aicareer.pro Doing AI Governance newsletter: https://blog.aicareer.pro #AIGovernance #ISO42001 #GRCEngineering #AntiCheckbox #AdaptiveGovernance #AIRisk #AIGP #Compliance #CyberSecurity #ResponsibleAI

  6. Sep 6

    Will GRC Engineering Get Absorbed Into Cloud Security? | Guest: Damien Burks

    Damien Burks has been in tech for nineteen years, started programming at sixteen, and came onto a GRC show to argue that GRC engineering is going to get absorbed into cloud security engineering. Not the other way around. He is a senior cloud security engineer and the founder of the DevSec Blueprint. His case is that cloud security engineers are already being quietly rebranded as GRC engineers, because the old model was never going to hold. You write a policy, you enforce it through more writing, and nobody builds the thing that makes the policy true. The enforcement work is moving left toward the engineers and the SREs, where it can actually be codified against NIST, FedRAMP or whatever framework you answer to. His prediction is that GRC engineering has its DevSecOps moment. It bubbles, it blows up, it gets a category, and then it is just the new normal. KEY TAKEAWAYS Why GRC engineering ends up as a subset of cloud security engineering, and what he sees in the tooling that convinced him The thing he is genuinely worried about: scope creep in the cloud security generalist role, and why it lands hardest on people trying to get their first job Which cloud cert to chase depends on sector and geography. Azure for public sector, because government is a Microsoft shop. AWS if you are in North America. Google Cloud has taken over elsewhere Where GRC and DevSecOps actually overlap in practice, including a concrete example of failing a non-compliant build before it ever reaches AWS The four phases of the DevSec Blueprint, and why phase one is not technical at all Why he built the whole thing as documentation instead of video, and what that has to do with your first week on the job The career strategy phase he is shipping, and who it matters most for And the line that stopped the episode. Job security is a myth, which we have all heard before. It was the second half of that sentence that got us. FIND DAMIEN The DevSec Blueprint: https://devsecblueprint.com GitHub: https://github.com/devsecblueprint/devsecblueprint #CloudSecurity #GRCEngineering #CybersecurityCareers #DevSecOps #CloudSecurityEngineer #GRC #Terraform #DevSecBlueprint #AntiCheckboxPodcast Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

  7. Aug 30

    He Watched a Man Get Ejected 200 Feet Into the Air. Then He Chose GRC | Guest: Christopher Warner

    Chris Warner spent ten years in the Air Force doing electronic warfare. His first night on the flight line, he watched a man get shot out of an ejection seat 200 feet into the air. That was the moment policies and procedures stopped being paperwork to him and became life and death measurements. Three decades later he has run the bases across all sixteen critical infrastructure sectors. One of the largest SCADA systems in the world at a Department of Energy remote sensing lab. Five years as an asset owner in natural gas. NERC CIP rollout from the consulting side. Then gaming, and now OT, IT, and AI architecture. Lauren Alex-Igwe guest hosts and pushes on the question most of us in GRC never have to answer: what do you do when the risk register ends in someone not making it home? KEY TAKEAWAYS Policies are life and death measurements. Chris traces his whole GRC career to two incidents: the ejection seat, and the pipeline rupture in Bellingham, Washington that burned through a neighborhood when the SCADA system missed a pressure drop. Seventy-one percent of US critical infrastructure is owned and operated by private entities. Private entities have to turn a profit. Security is competing against margin, permanently. The highest-need targets are the lowest-resourced ones. Four IT people covering twenty towns across four counties, with nation-state actors already prepositioned and using them as a proving ground. Remediation funding exists if you know where to look. Several states tie money to NIST CSF alignment. Florida was among the first. Chris will not say IT/OT convergence. OSI layers do not map cleanly to Purdue or ISA-95. He calls it alignment, and the distinction changes how you scope a program. The first move is not framework selection. It is a box of donuts and a real relationship with the field guys. If you cannot break the wall down inside your own organization, you are not ready to pick a control set. AI will hurt before it helps. Organizations are deploying and rolling back, deploying and rolling back, and nobody is validating that the rollback actually happened. Know what you have before you plug in something new. Citizens have a lever most of us forget. Every state has a Public Utilities Commission with public meetings and boards, and the EPA keeps records on boil water alerts. Credentials are not the differentiator. Some of the best operators Chris has worked with never opened a book. RESOURCES Grid Down, Power Up: https://griddownpowerup.com NIST CSF 2.0: https://www.nist.gov/cyberframework NIST SP 800-82: https://csrc.nist.gov/pubs/sp/800/82/r3/final Call 811 before you dig: https://call811.com Mike Holcomb, who Chris credits by name: https://www.mikeholcomb.com GUESTS Chris Warner, USAF veteran, OT/ICS and critical infrastructure security https://www.linkedin.com/in/christopherwarnermba/ Lauren Alex-Igwe, guest host https://www.linkedin.com/in/lauren-alex-igwe-18a66816b/

  8. Aug 23

    The Auditor won't care that AI Pulled It | Guest: Alan Luk

    Alan Luk has been on both sides of the audit table, and he came on the AntiCheckbox Podcast with a take that runs against the current mood in GRC. Not everything should get AI'd. And the things that should are about to run headfirst into an audit profession that has not moved yet. The line most teams are not drawing: there is AI you use to learn and experiment, and there is AI you use to build something the business will actually rely on in an audit. Alan sets loose guardrails for his team specifically so nobody burns weeks on something that was never going to survive a control test. We also got into Delve, why the blast radius is everybody and not just one vendor, and the uncomfortable check on our own movement. If our answer to every problem is "AI all the things," we are not anti-checkbox anymore. We just built a new checkbox with better branding. KEY TAKEAWAYS Separate exploring from producing. Playing with a tool to upskill is not the same as shipping an evidence pipeline the business depends on. Say which one you are doing before you start. Augment the learning, do not replace it. If you have churned out the same deliverable ten times and your actual knowledge never got deeper, all you got better at was writing prompts. You are still accountable for the output. Know the questions before your auditor asks them. How deterministic is it. How reproducible. How repeatable. How consistent. How complete and accurate. You cannot spin up an agent to go pull evidence when you cannot say what source system it pulled from. Control owners are doing this too. AI is showing up inside control design and operating effectiveness, not just evidence collection. That gets assessed on its own terms, and the standard depends on how much certainty that control actually needs. The burden of proof is on us. Auditors are not going to wake up and announce a new model of assurance. The Big Four will not move first. Smaller firms are more willing to work with teams heading this direction, and the big firms will feel it when clients walk. But there is a floor, and the race to the cheapest possible SOC 2 is a big part of how we got here. If it leaves the department, it represents the department. That applies to whatever your agent just generated too. Alan is one of the few people posting from inside the work rather than above it. This one earned the reputation. Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

  9. Aug 16

    20 Years In Finance. Zero Right Answers. Hired Anyway | Guest: Sunil Karir

    Sunil Karir spent 20 years as an accountant before he ever touched cybersecurity. He got laid off, spoke to a couple of friends, took a handful of entry level courses, and then applied to ten jobs a day, every day, for about four months. When he finally landed an interview at an MSP, he got every single technical question wrong. TLS, the handshake, all the layers, all of it. The hiring manager asked him straight up why he should take him on. Sunil said "why not." He got the job. That is where this one opens, and it does not let up. We get into the part of a career pivot that nobody posts about: the nights and days learning Fortinet and Juniper on the job while your colleagues carry you, raising your hand for the ISO 27001 re-cert nobody else wanted, and figuring out that the audit brain you built over two decades in finance was the asset the whole time. We also spend real time on where he and I overlap outside the work. Immigrant parents, the family shop, four in the morning, on time is late, and the question every one of us got handed back with a 70 percent test score: what happened to the other 30. Then the harder part, which is figuring out what to keep from all that and what to leave behind when you are the parent now. If you are trying to break in, or you are already in GRC and wondering why the screenshots feel hollow, this one is for you. Key Takeaways Attitude gets you in the door. It does not keep you in the room. Sunil's take is that talent gets you so far and then the only thing left is outworking the people around you. The pivot is not a hack. Ten applications a day, every day, at every level, including the ones you have no business applying to. Four months of that before the LinkedIn message that changed everything. The move that redirected his whole career was volunteering for a compliance project nobody else wanted. He ran an ISO 27001 recert between himself and Google, and found the discipline he actually belonged in. Certs still carry bargaining power because they give an employer a little reassurance when they cannot evaluate you technically. But do the work before the cert, not instead of it. Thirty people in his training cohort. Two got jobs in cyber. That gap is not talent. His closing advice: go learn privacy. GDPR is still the global reference point, it gets you into contract conversations, and it is the substrate underneath most of what is happening in AI governance right now. Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

  10. Aug 8

    Checkbox Compliance Is Better Than Nothing | AI Gov From The Trenches w/ Chris van der Heijden

    Our guest builds AI governance for a living and he told us that checkbox compliance is better than nothing. On this show. We let it ride, because the context changes the whole argument. Chris van der Heijden is not talking about a Fortune 500 with a compliance function. He is talking about the three to ten person startups shipping the AI features the rest of us are about to buy. Every governance guide in existence is written for enterprises, or at minimum for mildly mature companies. The teams actually generating the risk have none of that, and most of them believe they need a full compliance team before they can even start. Chris spent four years building a data clean room for sports sponsorship data. Encrypted computation on fan records, rights holders on one side, brands on the other. He exited earlier this year and now runs Vaiking AI, helping startups build governance that fits on a runway instead of a roadmap. His framework is called privacy by design from the trenches, and the tell that he actually lived it is that policy is the third pillar, not the first. Worth noting, this was Chris's first podcast appearance ever. You would not know it. Key Takeaways Governance debt is worse than technical debt. Function creep pushes a use case into a higher risk bracket under the EU AI Act, and Chris's argument is that you cannot pay it down after the fact because the artifacts had to exist at the moment the decision was made. The entry price is lower than founders think. A register, a few small policies, and real conversations about what gets recorded where. Chris built a full ISMS anyway, and the return was not the certificate. It was clearing enterprise due diligence questionnaires without the deal stalling. Every party in the chain had an incentive not to care. Rights holders wanted sponsors, brands wanted conversions, fans wanted their team to win. Nobody was going to ask for data minimization, so the platform in the middle had to enforce it on all sides. Chris van der Heijden, founder of Vaiking AI https://vaiking.ai https://www.linkedin.com/in/cfvdheijden/ Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

  11. Aug 1

    People Don't Scale: Tamelia Hutchinson on the 40 Year "Fad" of GRC Engineering

    We asked Tamelia Hutchinson whether GRC engineering is a fad or here to stay. She answered with a question of her own: what is your definition of GRC engineering? Everything after that was worth the price of admission. Tamelia has spent about twenty years in security and compliance, accidentally at first and then on purpose. In this one she splits GRC engineering into its process side and its technical side, argues neither one is going anywhere, and lands on a phrase that is going to live in our head for a while: it has been a fad for forty years, so it is a fad in the geological sense. We get into the thing nobody warns you about, which is that if you automate a bad process, you are just automating your demise. You get to the cliff faster. Tamelia walks through why software led transformation stalls when the people on the receiving end were never brought along, what she does when there is no internal proof of concept to point at, and the specific question she asks to get a stakeholder to imagine a different way of working instead of defending the current one. She also breaks down how she actually learned to talk to leadership, which was not from a book. It was from sitting in rooms with people who were better at it than she was, listening for what connected, and then adapting it rather than copying it. Her line on that: copying someone else's delivery is like wearing somebody else's pants who says they are going to fit you. And then there is the part we did not see coming. Leadership asked her how they would know the investment in compliance and security had paid off. Her answer was that they would know when they could let her go. When the maturity is high enough and the toil is reduced enough that her position is not needed. Her reasoning is the whole thesis of this show compressed into three words: people don't scale. The GRC Engineering Club is a community of practitioners treating governance, risk, and compliance as an engineering discipline instead of a documentation ritual. Subscribe for new episodes of the AntiCheckbox Podcast every week. #GRC #GRCEngineering #Cybersecurity #Compliance #RiskManagement #SecurityLeadership #DevSecOps #Automation --- Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

  12. Jul 28

    The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran from Locktivity

    "We have this weird model where it's like hand me a SOC 2 or answer a questionnaire, tell me everything's good, let's shake hands and move on. And then we forgot to enable 2FA..." In this episode of the Anti Checkbox Podcast, O sits down with Rachel Curran to dismantle the current state of Third-Party Risk Management (TPRM). Rachel brings a brutally honest perspective to the industry, explaining why the traditional reliance on massive questionnaires and point-in-time compliance frameworks is nothing more than "security theater." We discuss why small 10-to-12 person startups are being sold a false narrative that they need a SOC 2 or ISO certification just to do business. Instead, Rachel argues for a return to first principles: focusing on continuous monitoring of core security hygiene, like Multi-Factor Authentication (MFA), which can stop the vast majority of breaches. We also explore how a transparent, right-sized security program acts as a "trust marketplace" that can actually help companies close six-figure deals. Key Takeaways: Security Theater: Why passing around massive questionnaires and point-in-time SOC 2 reports completely fails to stop actual breaches. The MFA Mandate: Why prioritizing basic hygiene like MFA and encryption is infinitely more valuable than completing 250-point compliance checklists. Advice for Startups: Why tiny companies should avoid the trap of pursuing expensive SOC 2 certifications and instead invest in a few hours of expert consulting to nail down core business risks. Selling with Security: How treating third-party risk as a competitive differentiator can get you budget, build trust, and help your company close major enterprise deals. Learn GRC Engineering: - GRC Engineering 101: https://grcengclub.com/learn/grc-engineering-101 - How to Break Into GRC Engineering: https://grcengclub.com/learn/how-to-break-into-grc-engineering - GRC Engineer Salary Guide: https://grcengclub.com/learn/grc-engineering-salary - GRC vs Traditional GRC: https://grcengclub.com/learn/grc-vs-traditional-grc Website: https://grcengclub.com Merch: https://grcengclub.com/merch Patreon: https://www.patreon.com/cw/GRCEngineeringClub LinkedIn: https://www.linkedin.com/company/grc-engineering-club/

About

Compliance became a documentation ritual somewhere along the way. Screenshots, spreadsheets, a scramble every quarter, and a piece of paper at the end that tells you almost nothing about whether the control actually works. That job is getting automated out from under the people doing it, and good riddance. The AntiCheckbox Podcast is about the other version of this work. Controls as a data and engineering problem. Evidence that generates itself. Governance you can defend to a regulator, a board, or a plaintiff's attorney because the system produces the proof, not because somebody filled in a cell. Every week we sit down with the practitioners actually building this way. Auditors who got tired of asking for screenshots and learned to write code. Engineers who got handed a framework and refused to accept that it had to be miserable. The people writing the standards, the people running programs at scale, and the ones who lived through the audit that changed how they think. No vendor pitches. No certification worship. No pretending the current model is fine. If you work in GRC, security, risk, audit, privacy, or you are trying to get into any of it and cannot get a straight answer from anybody, this is for you. The show is the front door to the GRC Engineering Club, a community of practitioners doing this work in the open. Early episodes, the Slack, and The Convergence newsletter live at patreon.com/c/GRCEngineeringClub.

You Might Also Like