Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
The GRC Podcast

The GRC Podcast

Mark Graziano

Governance, Risk, and Compliance (GRC) is boring, uninspiring and bureaucratic – at least that’s what you’ve probably been told. In reality, GRC is a dynamic security discipline, which requires professionals to develop a deep understanding of their business, products, colleagues, and customers to be successful. Join Mark Graziano, as he partners with incredible security champions to challenge the GRC industry stereotype and outline security career and program strategies you can implement today.
Visit www.thegrcpodcast.com for more information

bookmark
Share icon

All episodes

Best episodes

Seasons

Top 10 The GRC Podcast Episodes

Goodpods has curated a list of the 10 best The GRC Podcast episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to The GRC Podcast for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite The GRC Podcast episode by adding your comments to the episode page.

The GRC Podcast - 2023 Retrospective - End of Year Highlights
play

12/30/23 • 39 min

Join us for a special year-end episode of the GRC podcast, where we revisit some of the most significant insights and dialogues from the past year. This episode is a compilation of valuable lessons and insights that have shaped our understanding of Governance, Risk, and Compliance (GRC) and provided practical solutions to common obstacles faced by GRC professionals.
In this episode:
- Dustin Bailey underscores the importance of understanding the 'why' behind our actions, which not only strengthens stakeholder relationships but also fosters a unified team effort.
- Steven Nguyen offers his unique insights and challenges us to be introspective about the value and necessity of the work we perform, viewing our services as products that provide business value and enjoyable user experience.
- Patrick Ayerte illuminates the importance of personal branding and visibility within the workplace. He shares practical advice on how to make sure your work doesn't go unnoticed, a critical aspect for career advancement.
- Jake Bernardes delves into privacy legislation, shedding light on its ethical implications and the importance of data protection, particularly for the next generation growing up in a digital age.
- Daniel Redding emphasizes the role of simplicity and practicality in risk management, showcasing how effective context framing and pointed dialogues can facilitate risk identification, assessment, and mitigation.
- Monica Smith discusses the importance of security transparency and the benefits of proactively communicating your organization's security culture and practices during the sales cycle.
- Leif Dreizler highlights the transformative power of community networking and how it can lead to new opportunities for professional advancement, team performance and community growth.
- Jeevan Singh breaks down walls between GRC and security engineering teams, stressing the importance of effective, consistent communication and team work.
- Ariel Shin explores the practical application of GRC frameworks, demonstrating the need for user-friendly and accessible GRC practices, products and services.
- The conversation concludes with Alex Bovee's insights on the growing need for scalable and automated identity and access management systems, particularly in an era where SaaS adoption is accelerating.
Whether you've followed us throughout the year or are tuning in for the first time, this episode offers valuable takeaways for GRC professionals at any career stage. Tune in to deepen your understanding of the principles that can guide you towards a successful and rewarding journey in the GRC world

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

In this conversation, Gina Gabriel shares inside information, tips and tricks for resume building that she accrued from over a decade of tech recruiting experience. Gina and I discuss the importance of resumes in career development and growth. We explore the resume review process, including what happens once job postings go live and resumes start coming in. We debunk common misconceptions about resumes and provide tips for making resumes memorable. We also discuss the value of referrals and networking in the job search process. Gina shares success stories of transforming resumes and offers insights into the storytelling aspect of resumes. Gina and I even conduct a live review of my actual resume, highlighting changes and recommendations. Gina provides information about her consulting services and offers free resources for resume improvement.

Unlock the secrets to transforming your job application from forgettable to formidable, as Gina and I share the tools you need to navigate the tumultuous waters of the job market. From uncovering the behind-the-scenes chaos of job postings to mastering the applicant tracking systems like Workday, our comprehensive chat is the beacon you've been seeking. Discover the potent combination of an impactful resume, the weight of employee referrals, and the nuanced art of tailoring your narrative to sail through the hiring process.

Step into the inner circle of application strategy, where we spill the insider details on making your resume resonate with recruiters and hiring managers alike. Through a live review of my actual resume, Gina and I show you firsthand how to stand out in the interview process by selling yourself as effectively as the slickest SaaS product. You'll learn how to format your resume to tell your professional story and how to wield your job titles like a seasoned marketer, ensuring your skills and experience capture the spotlight.

Concluding our journey, we explore the treasure trove of free resources that can elevate your job application toolkit to new heights, and Gina extends an open invitation to anyone seeking tailored advice for career advancement. Whether you're a fresh-faced job seeker or a seasoned professional, my conversation with Gina arms you with the strategies to not just land the interview, but to ace it and confidently step into your next career chapter. Join us, and let's turn the page together on your professional success story.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode
The GRC Podcast - Say the Taboo: Vendor Risk Management is Bullsh*t
play

04/19/24 • 6 min

In today's episode we take a candid look at the efficacy of vendor risk management programs in the face of breaches. This time, we're reflecting on a conversation that pushed me out of my comfort zone and made me question the very fundamentals of vendor risk management. The startling realization that the well-trodden path of best practices might not hold all the answers spurred a much-needed debate on whether it's time to disrupt the status quo and embrace a more proactive stance in managing vendor risks.
We're challenging conventional wisdom, by evaluating the October 2023 breach of Okta despite the collective efforts of nearly 20,000 customers' vendor risk management programs. The episode takes you through a journey of introspection and industry critique, examining how traditional defensive strategies might not be enough and why a shift in perspective is crucial. We don't just outline the problems; we also explore what it means to safeguard against the inevitable issues and the importance of leading with the taboo in conversations that could redefine industry standards.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Get ready for a dynamic conversation with our expert guest, Jake Bernardes, as we delve into the often ambiguous territory of privacy legislation. Ever considered how data collection could impact you or the younger generation? We deep-dive into this pressing topic, examining how businesses are collecting data, and the significant impact it may have on all of us. We highlight how the changing nature of data and its accessibility emphasize the vital role of privacy laws in our evolving digital landscape.
Join us as we traverse the labyrinth of privacy laws across different countries and uncover the complexities businesses navigate to avoid certain regulations. We discuss the implications of the Patriot Act in the U.S., and the hurdles faced in passing privacy laws due to lobbying and the influence of large corporations. Jake offers enlightening perspectives on protecting ourselves from not just the collection but also potential misuse of our data.
Lastly, we venture into the realm of AI and the implications it brings for personal data privacy. We consider the risks AI poses, the need for robust privacy programs, and the importance of understanding new AI security standards. What would a global privacy framework look like and how can businesses demonstrate compliance? Our conversation concludes by emphasizing the urgency for an international approach to privacy, and the necessity of businesses to build trust with consumers in this new age of data privacy. This conversation is one you won't want to miss!

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Ready to reframe your perspective on team management? Join us as we chat with Patrick Ayertey, Business Security Lead at Twilio, who shares his journey from being an individual contributor (IC), to a manager. Patrick's unique philosophy of leadership, deeply rooted in empathy and recognizing individual personalities within a team, might just inspire you to rethink your own approach.
Our conversation with Patrick is not just about leadership; it's a deep dive into the essence of human connection in a professional setting. Drawing upon his cultural background from Ghana and his experience as a music director, Patrick seamlessly blends these diverse perspectives into his management style. We unpack the importance of transparency and trust in manager-employee relationships and how understanding business dynamics can bolster career growth. Patrick also shares some interesting strategies he uses to build relationships within his team.
Finally, we explore Patrick's progressive strategies for working cross-functionally with high-level executives and in tailoring requirements to the business context. Patrick emphasizes the need to understand the 'why' behind regulations and requirements. We conclude the episode with a fascinating look into Patrick's personal projects, like teaching cloud engineering and creating music as an expression. This engaging conversation with Patrick ultimately challenges leaders to focus more on people than outcomes for team success.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Get ready to redefine your understanding of GRC and security with our esteemed guest Steven Nguyen, Business Information Security Officer of Data Applications at Twilio. Promising to enlighten you with a fresh perspective, we delve into the complexities of vendor risk management and security sales enablement, all in the light of business improvement. Stephen brings his expertise to the table, discussing the importance of agility and competitive positioning, as well as how to balance operational agility with reasonable security assurance.
This conversation takes a deep dive into the practicalities of executing GRC and security risk management within a small team. We touch upon the merits of adopting a cross-functional approach and the need for redundancy within skillsets, punctuated by Stephen’s insightful take on the matter. We also unravel the art of crafting quality questions for security questionnaires, which serves as a valuable tool to assess a vendor's maturity and calculate risk.
Not one to shy away from challenging topics, we navigate through the intricacies of security collateral and vendor risk management programs. Steven and I exchange views on the delicate issue of setting boundaries with customers running scans against our systems, and the legal complexities that contracts, DPAs, and security addendums bring to the table. We wrap up our discussion by emphasizing the importance of 'shifting left' in the sales process, and the need for standardization and transparency in GRC. This episode promises to be a rich source of knowledge for anyone keen on understanding the dynamics of GRC and security risk management.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Join us for an insightful exploration of Security & GRC hiring with Tom Alcock from Code Red Partners. Tom illuminates their bespoke recruitment strategy, expertly aligning Security organizations with candidates who are not just technically proficient but also a cultural fit. We delve into the ever-changing world of Security & GRC employment, delivering actionable strategies for both industry novices and veterans. The conversation underscores the significance of perpetual learning and the power of networking in this rapidly evolving field.
Tom highlights the crucial role of community engagement in Security hiring, demonstrating how building a trusted network can open doors to extensive connections and opportunities. We discuss the pivotal moments when specialized firms like Code Red become invaluable, be it for large-scale recruitment drives or assembling foundational teams for emerging startups. This episode brims with insights for those contemplating the right time and approach to engage with recruitment experts who deeply understand the ins and outs of security organizations and the ever changing security landscape.
Wrapping up, we focus on Security & GRC career progression strategies. Tom provides pragmatic guidance on role transitions, from individual contributor to managerial positions, emphasizing the advantage of maintaining hands-on involvement in certain situations. We also venture into pathways leading to senior management and C-suite roles, sharing inspiring success stories and identifying the distinctive qualities of industry leaders. Tune in for a compelling discussion about forging a triumphant career in the dynamic world of Security & GRC.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

In this podcast episode, we unravel the intricate world of risk management, shedding light on its role in our everyday lives and its influence on GRC (Governance, Risk and Compliance). Daniel Redding guides listeners through a comprehensive understanding of risk management, exploring how to effectively navigate and control it. They break down the complex elements of risk, including the interplay of probability and severity, and introduce the often overlooked factors that can amplify risk. This discussion brings risk management back to basics, reinforcing the importance of investing effort proportionate to the potential return on investment.
The episode also focuses on determining the criticality of security incidents and how to prioritize responses effectively. Daniel emphasizes on transforming complex elements into manageable metrics, enabling listeners to compare and analyze effectively. Key factors such as system revenue, regulatory compliance requirements, data quantity, strategic priority, and availability are discussed. Daniel underscores the importance of identifying potential system hotspots to minimize future risk, fostering a proactive approach to risk management.
Finally, the episode arms listeners with effective communication strategies to present potential risks to executives in a clear and comprehensible manner. It underscores the importance of quantifying risk using a balanced blend of data and estimates. Daniel stresses the need for making specific, actionable recommendations and assigning responsibility for risk solutions. The ultimate goal is to demystify risk management, ensuring that organizations focus on what matters most and are clear in their methods of measuring and communicating risk. Tune in to this enlightening episode and start navigating the realm of risk management and GRC with increased confidence and expertise.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode
The GRC Podcast - Making GRC Your Career Superpower with Chris Honda
play

01/10/24 • 52 min

In this episode of the GRC Podcast, we sit down with Chris Honda, a seasoned Senior Security Analyst at Whistic, who walks us through the multifaceted world of Governance, Risk, and Compliance (GRC). With his unique journey into the world of Security, Chris sheds light on the transformative nature of cultivating GRC expertise and the value those skills can bring to the business and security landscapes.
GRC Unpacked: More Than Acronyms
Chris starts by demystifying GRC, breaking it down into its core components: Governance, Risk, and Compliance. He shares an accessible approach to explaining these concepts to non-experts, using relatable analogies like the Rosetta Stone, underscoring the importance of GRC as the lingua franca that bridges the gap between business operations and security imperatives.
The Human Element in InfoSec
Delving into the art of presenting at conferences, Chris emphasizes the need to bring one's personality into play. By humanizing InfoSec, he advocates for presentations that resonate on a personal level, which in turn fosters a more resilient and relatable security culture within organizations.
Career Trajectories in GRC
Reflecting on his own path, Chris discusses how asking the critical question "why" catalyzed his move from finance to security, highlighting the role of curiosity in driving career progression within GRC. He reassures listeners that a background in IT is not a prerequisite for a successful career in GRC, as the field welcomes diverse professional experiences.
Technical” Redefined
Chris challenges the misconception that one must be highly technical to succeed in security. He argues that problem-solving, communication, and understanding technology as a means to exceptional outcomes are just as crucial. This broader definition of 'technical' opens doors for GRC professionals to be recognized for their strategic and enabling contributions. (but also they should strive to have developer empathy and recognize stagnation in learning will significantly limit upward mobility, salary and future employability.)
The Convergence of Security and Privacy
Exploring the nuanced relationship between security and privacy, the discussion pivots to how these disciplines intersect within GRC frameworks. Chris provides insights into how evolving privacy laws create new opportunities for those passionate about privacy and compliance, demonstrating the dynamic nature of the GRC field.
The Specialist vs. Generalist Debate
Chris shares his experiences as a GRC generalist in a smaller company, weighing in on the benefits of wearing multiple hats against the deep focus of specialists in larger firms. He advocates for the value of generalist roles, highlighting their ability to manage a broad spectrum of GRC challenges and drive comprehensive security strategies.
Giving Back and Building Community
The episode wraps up with Chris reflecting on the importance of giving back to the GRC community. By volunteering and engaging in acts of kindness, professionals can cultivate a supportive network that not only fosters personal fulfillment but also strengthens the collective knowledge and resilience of the GRC industry.
Join us in this enriching discussion that promises to inspire both personal and professional growth, whether you're new to GRC or a veteran looking to reinvigorate your career with a fresh perspective.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Join us for a conversation with Leif Dreizler, a dynamic figure and avid organizer in the InfoSec industry. While Leif is a skilled practitioner, his roles as a seasoned conference organizer, insightful blogger, and engaging podcast host allow his influence to extend well beyond the traditional workspace. In this episode, he generously unpacks his extensive knowledge on brand building and community engagement, underscoring the crucial participation of everyone, from novices to seasoned experts.
Leif takes us through his unique journey, emphasizing that there isn’t a one-size-fits-all approach to career development in the industry. With a myriad of options available, professionals can carve out their own paths, selecting the avenues that align best with their individual needs and aspirations. He shares insights from his experience organizing prominent conferences, including AppSec California, BSides SF, and Loco Moco Sec, and reflects on how these endeavors have been instrumental in shaping his career.
The episode dives into the significance of community engagement and networking for security professionals. Leif shares personal anecdotes and highlights the importance of active participation in diverse community initiatives, ranging from public speaking and conference proposals to blogging and podcasting. He offers practical tips for maximizing efficiency in your work, sharing strategies for smart blogging and effective repurposing of content across talks, presentations, and podcast appearances.
However, Leif’s narrative isn’t solely about personal brand cultivation. It’s also a testament to the myriad ways individuals can contribute to and engage with the larger community. He outlines the tangible benefits of active involvement, such as network expansion and the discovery of new job opportunities, and prompts listeners to reflect on how they, too, can contribute to and glean valuable insights from the community.
Tune in to explore Leif’s story and consider how you might enhance your engagement with the security community, fostering both personal and professional growth.

For show notes, please visit The GRC Podcast website.
Sign up for our
Bi-Weekly Newsletter

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does The GRC Podcast have?

The GRC Podcast currently has 21 episodes available.

What topics does The GRC Podcast cover?

The podcast is about Security, Saas, Risk, Compliance, Podcasts, Technology, Business, B2B and Careers.

What is the most popular episode on The GRC Podcast?

The episode title 'Introduction to The GRC Podcast with Mark Graziano' is the most popular.

What is the average episode length on The GRC Podcast?

The average episode length on The GRC Podcast is 41 minutes.

How often are episodes of The GRC Podcast released?

Episodes of The GRC Podcast are typically released every 14 days.

When was the first episode of The GRC Podcast?

The first episode of The GRC Podcast was released on May 1, 2023.

Show more FAQ

Toggle view more icon

Comments