Artwork

Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Why Security And GRC Teams Must Act Like Service Teams ft Jiphun Satapathy from Medallia

1:13:21
 
공유
 

Manage episode 496381820 series 3644937
Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Jiphun Satapathy has built and scaled security organizations at AWS, Snowflake, and now Medallia. In this episode, he joins our host Raj to explore the evolving role of CISOs as strategic business leaders. They discuss the importance of treating security as a service organization, how to handle vendor noise, and why insider risk is often overlooked. You’ll hear practical advice for security and GRC leaders working in AI-first, high-growth environments—and how to maintain trust across engineering, compliance, and executive teams.


Key Takeaways

  • Security as a Service Function: Security should empower—not block—the business. Jiphun shares how his team supports product, engineering, and sales.
  • Vendor Engagement Matters: CISOs who ignore vendors miss out on innovation. But filtering the noise is key.
  • Insider Risk is Real: Not rogue employees, but everyday developer behavior is a top source of risk.
  • Modern GRC Requires Technical Fluency: Especially in AI-first companies, GRC teams must understand the tech stack to stay relevant.
  • Earn Trust Through Action: Metrics matter, but culture and execution are what build credibility with boards, customers, and engineers.

What You’ll Learn

  • How to build a risk-based security roadmap that keeps pace with rapid development
  • The role of security in shaping culture across a global org
  • How startups can engage CISOs without falling into FUD tactics

This episode is brought to you by ComplianceCow — the smarter way to automate compliance and monitor controls.

-- Learn more at compliancecow.com
-- Connect with Jiphun on Linkedin:
linkedin.com/in/jiphunsatapathy

🎧 Rate, review, and share if you enjoyed the show!
🎙 Subscribe to
Security & GRC Decoded wherever you get your podcasts:

Spotify and Apple Podcasts

(Approximate) Timestamps:

  • [00:01:48] Jiphun challenges CISO aversion to vendor engagement
  • [00:03:25] Filtering vendors based on prioritized security needs
  • [00:06:24] Empowering teams with bottom-up decision-making
  • [00:08:15] Driving culture change and making security a productivity enabler
  • [00:11:33] MFA example showing how to improve both security and UX
  • [00:15:25] Treating internal stakeholders as customers
  • [00:21:02] Measuring risk with frameworks and metrics
  • [00:30:22] Using automation to align security cadence with CI/CD pipelines
  • [00:32:47] Insider risk and why it belongs on board slides
  • [00:42:33] Empowering devs by reducing vulnerability noise
  • [00:51:22] Why healthy paranoia is essential in AI adoption
  • [00:56:51] Why GRC teams must be technical in AI-first environments
  • [01:03:15] Advice to security startups: stop with the FUD
  • [01:07:02] Coping strategies for CISO stress and burnout
  • [01:09:60] Books and mentors that shaped Jiphun’s leadership journey

  continue reading

24 에피소드

Artwork
icon공유
 
Manage episode 496381820 series 3644937
Raj Krishnamurthy에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Raj Krishnamurthy 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Jiphun Satapathy has built and scaled security organizations at AWS, Snowflake, and now Medallia. In this episode, he joins our host Raj to explore the evolving role of CISOs as strategic business leaders. They discuss the importance of treating security as a service organization, how to handle vendor noise, and why insider risk is often overlooked. You’ll hear practical advice for security and GRC leaders working in AI-first, high-growth environments—and how to maintain trust across engineering, compliance, and executive teams.


Key Takeaways

  • Security as a Service Function: Security should empower—not block—the business. Jiphun shares how his team supports product, engineering, and sales.
  • Vendor Engagement Matters: CISOs who ignore vendors miss out on innovation. But filtering the noise is key.
  • Insider Risk is Real: Not rogue employees, but everyday developer behavior is a top source of risk.
  • Modern GRC Requires Technical Fluency: Especially in AI-first companies, GRC teams must understand the tech stack to stay relevant.
  • Earn Trust Through Action: Metrics matter, but culture and execution are what build credibility with boards, customers, and engineers.

What You’ll Learn

  • How to build a risk-based security roadmap that keeps pace with rapid development
  • The role of security in shaping culture across a global org
  • How startups can engage CISOs without falling into FUD tactics

This episode is brought to you by ComplianceCow — the smarter way to automate compliance and monitor controls.

-- Learn more at compliancecow.com
-- Connect with Jiphun on Linkedin:
linkedin.com/in/jiphunsatapathy

🎧 Rate, review, and share if you enjoyed the show!
🎙 Subscribe to
Security & GRC Decoded wherever you get your podcasts:

Spotify and Apple Podcasts

(Approximate) Timestamps:

  • [00:01:48] Jiphun challenges CISO aversion to vendor engagement
  • [00:03:25] Filtering vendors based on prioritized security needs
  • [00:06:24] Empowering teams with bottom-up decision-making
  • [00:08:15] Driving culture change and making security a productivity enabler
  • [00:11:33] MFA example showing how to improve both security and UX
  • [00:15:25] Treating internal stakeholders as customers
  • [00:21:02] Measuring risk with frameworks and metrics
  • [00:30:22] Using automation to align security cadence with CI/CD pipelines
  • [00:32:47] Insider risk and why it belongs on board slides
  • [00:42:33] Empowering devs by reducing vulnerability noise
  • [00:51:22] Why healthy paranoia is essential in AI adoption
  • [00:56:51] Why GRC teams must be technical in AI-first environments
  • [01:03:15] Advice to security startups: stop with the FUD
  • [01:07:02] Coping strategies for CISO stress and burnout
  • [01:09:60] Books and mentors that shaped Jiphun’s leadership journey

  continue reading

24 에피소드

모든 에피소드

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생