Artwork

Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta

57:19
 
공유
 

Manage episode 516808592 series 3644937
Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.

He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.


5 Key Takeaways

  • Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are.
  • Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works.
  • Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits.
  • Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.
  • Define the Right Role: The best GRC teams act as a sparring partner --challenging, supportive, and focused on outcomes.

What You’ll Learn

  • How to rebuild trust with engineering after “audit fatigue”
  • Practical ways to convert control requirements into product language
  • How to design evidence from logs, pipelines, and tickets you already have
  • When to push, when to partner, and how to escalate with credibility
  • Communicating risk trade-offs without killing roadmap velocity

Connect With Our Guest:
Tristan Ingold | Security GRC Program Manager | Meta

This podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

Watch more episodes

Rate, review, and share if you enjoyed the show!

Subscribe to Security & GRC Decoded wherever you get your podcasts:

  continue reading

24 에피소드

Artwork
icon공유
 
Manage episode 516808592 series 3644937
Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.

He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.


5 Key Takeaways

  • Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are.
  • Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works.
  • Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits.
  • Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.
  • Define the Right Role: The best GRC teams act as a sparring partner --challenging, supportive, and focused on outcomes.

What You’ll Learn

  • How to rebuild trust with engineering after “audit fatigue”
  • Practical ways to convert control requirements into product language
  • How to design evidence from logs, pipelines, and tickets you already have
  • When to push, when to partner, and how to escalate with credibility
  • Communicating risk trade-offs without killing roadmap velocity

Connect With Our Guest:
Tristan Ingold | Security GRC Program Manager | Meta

This podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

Watch more episodes

Rate, review, and share if you enjoyed the show!

Subscribe to Security & GRC Decoded wherever you get your podcasts:

  continue reading

24 에피소드

所有剧集

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생