Explore every episode of the podcast The GRC Engineering Club's AntiCheckBox Podcast
Dive into the complete episode list for The GRC Engineering Club's AntiCheckBox Podcast. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
Rows per page:
50
1–9 of 9
Title
Pub. Date
Duration
Ten Years In GRC Without A Single Certification | Guest: Pradeep Reddy
13 Sep 2026
00:36:00
Pradeep Reddy went ten years into his career before he pursued a single certification. Twelve years in now, he has spent the last four mentoring people trying to break into GRC and security, and this episode is the closest thing we have published to an operating manual for that, on both sides of the call.
His path was not a straight line. STEM, then commerce, then a master's in finance, then IT audit at KPMG almost by accident, third line of defense to second line, and eventually into information security risk management. Nobody along the way told him he needed a lead auditor cert or a CISA to have a career, and one of his early mentors gave him a piece of advice about credentials and careers that he still repeats.
His position on learning is that it counts in any form. A podcast, a YouTube playlist, an article, somebody's LinkedIn timeline, a breach report you read closely enough to understand the root cause.
What makes this one useful is that he has actually built a process. There is an intake step before the first call ever happens. There is documentation, because he ran it as a loose series of calls for a year and it did not work.
There is a hiring calendar most people ignore. And there is a hard line on what a mentor can and cannot promise you, which is where we pushed him hardest.
KEY TAKEAWAYS
Why he asks for a set of answers in writing before the first mentoring call, and what those answers tell him.
The thing that makes him tell somebody they are not ready yet. It is not skill level.
Why he stopped running mentorship as a string of calls after a year of it not working, and what he replaced it with.
The hiring calendar. Why January and February are slow, why March is the real deadline, and how far ahead of it you need to start.
Using the NIST NICE framework to mentor. Start from the role somebody wants, work backward to the skills that role actually requires, and stop re-teaching the basics they already have.
His pitch to employers: alongside the performance manager who evaluates you, put somebody whose only job is guidance, and the difference between advice from 30,000 feet and advice from 1,000 feet.
How to spot a mentorship program that is working you. He is generous about it. We were less generous.
What he says to anybody who asks him for a job guarantee, which is shorter and blunter than you would expect from him.
Why he corrects people who say cybersecurity when they mean
information security, and why that distinction matters on day one.
What he actually gets out of mentoring. His answer is about a generational shift and it is not the answer most people give.
ISO 42001 will not make your AI safer | Guest: James Kavanagh
10 Sep 2026
00:47:08
James Kavanagh led the program that earned Amazon Web Services the first ISO 42001 certification of any global cloud provider. Then he sat down with us and said it plainly: you can implement that standard end to end and still not move the safety or the security of the systems you actually operate.
Adding more standards does not fix it either.
That is not a cheap shot at ISO. It is a shot at what he calls static governance, the belief that you can hold a system still, check it once a year, and call the result assurance. James spent 25 years across Microsoft and Amazon in engineering, security and regulatory roles, including the AWS team whose job was to understand every law and regulation on earth, translate it backward into engineering, and get the engineers to answer back in assurance language.
Before any of that he was a chemical engineer designing plants and running operators through simulated disasters, which turns out to be the whole point.
His argument is that an AI system is not just complicated. It is complex, it has emergent behavior, and it is unbounded, and we are standing inside the box we keep trying to draw around it. He calls the alternative adaptive governance, and he says it works at ten people and at Amazon scale.
We pushed on the part that matters to this audience. If the standard is not the answer, what is. If your engineers are never going to read the impact assessment, what were we producing it for. And where exactly did cyber learn its lessons, given that the things we already knew keep getting relearned every five years.
KEY TAKEAWAYS
Adaptive governance, defined without the buzzwords: build governance that changes at the same rate as the system you are governing.
Complicated, complex, unbounded. Why the third one is what actually breaks the annual audit model.
Technical problems versus adaptive problems. An adaptive leadership frame you can use with your team on Monday.
The behavioral model that scales down to a ten person shop: encourage, coach, sanction, and why the default response to bad behavior should be that you designed the system wrong.
Three tiers of compliance behavior. Checkbox compliance, high integrity compliance, and a third tier that is worse than both.
Why engineers never read the 50 page impact assessment, and what breaks when the management system and the engineering never meet.
What actually made cyber more secure, and why it was not FedRAMP and it was not more prescriptive requirements.
The engineering design rule every safety discipline treats as rule zero, and where AI at global scale is currently violating it.
Straight career talk. AI governance is not a niche, it is not easy money, and right now the field has no experts.
Will GRC Engineering Get Absorbed Into Cloud Security? | Guest: Damien Burks
06 Sep 2026
00:49:52
Damien Burks has been in tech for nineteen years, started programming at sixteen, and came onto a GRC show to argue that GRC engineering is going to get absorbed into cloud security engineering. Not the other way around.
He is a senior cloud security engineer and the founder of the DevSec Blueprint. His case is that cloud security engineers are already being quietly rebranded as GRC engineers, because the old model was never going to hold. You write a policy, you enforce it through more writing, and nobody builds the thing that makes the policy true. The enforcement work is moving left toward the engineers and the SREs, where it can actually be codified against NIST, FedRAMP or whatever framework you answer to. His prediction is that GRC engineering has its DevSecOps moment. It bubbles, it blows up, it gets a category, and then it is just the new normal.
KEY TAKEAWAYS
Why GRC engineering ends up as a subset of cloud security engineering, and what he sees in the tooling that convinced him
The thing he is genuinely worried about: scope creep in the cloud security generalist role, and why it lands hardest on people trying to get their first job
Which cloud cert to chase depends on sector and geography. Azure for public sector, because government is a Microsoft shop. AWS if you are in North America. Google Cloud has taken over elsewhere
Where GRC and DevSecOps actually overlap in practice, including a concrete example of failing a non-compliant build before it ever reaches AWS
The four phases of the DevSec Blueprint, and why phase one is not technical at all
Why he built the whole thing as documentation instead of video, and what that has to do with your first week on the job
The career strategy phase he is shipping, and who it matters most for
And the line that stopped the episode. Job security is a myth, which we have all heard before. It was the second half of that sentence that got us.
He Watched a Man Get Ejected 200 Feet Into the Air. Then He Chose GRC | Guest: Christopher Warner
30 Aug 2026
00:48:14
Chris Warner spent ten years in the Air Force doing electronic warfare. His first night on the flight line, he watched a man get shot out of an ejection seat 200 feet into the air. That was the moment policies and procedures stopped being paperwork to him and became life and death measurements.
Three decades later he has run the bases across all sixteen critical infrastructure sectors. One of the largest SCADA systems in the world at a Department of Energy remote sensing lab. Five years as an asset owner in natural gas. NERC CIP rollout from the consulting side. Then gaming, and now OT, IT, and AI architecture.
Lauren Alex-Igwe guest hosts and pushes on the question most of us in GRC never have to answer: what do you do when the risk register ends in someone not making it home?
KEY TAKEAWAYS
Policies are life and death measurements. Chris traces his whole GRC career to two incidents: the ejection seat, and the pipeline rupture in Bellingham, Washington that burned through a neighborhood when the SCADA system missed a pressure drop.
Seventy-one percent of US critical infrastructure is owned and operated by private entities. Private entities have to turn a profit. Security is competing against margin, permanently.
The highest-need targets are the lowest-resourced ones. Four IT people covering twenty towns across four counties, with nation-state actors already prepositioned and using them as a proving ground.
Remediation funding exists if you know where to look. Several states tie money to NIST CSF alignment. Florida was among the first.
Chris will not say IT/OT convergence. OSI layers do not map cleanly to Purdue or ISA-95. He calls it alignment, and the distinction changes how you scope a program.
The first move is not framework selection. It is a box of donuts and a real relationship with the field guys. If you cannot break the wall down inside your own organization, you are not ready to pick a control set.
AI will hurt before it helps. Organizations are deploying and rolling back, deploying and rolling back, and nobody is validating that the rollback actually happened. Know what you have before you plug in something new.
Citizens have a lever most of us forget. Every state has a Public Utilities Commission with public meetings and boards, and the EPA keeps records on boil water alerts.
Credentials are not the differentiator. Some of the best operators Chris has worked with never opened a book.
The Auditor won't care that AI Pulled It | Guest: Alan Luk
23 Aug 2026
00:28:40
Alan Luk has been on both sides of the audit table, and he came on the AntiCheckbox Podcast with a take that runs against the current mood in GRC. Not everything should get AI'd. And the things that should are about to run headfirst into an audit profession that has not moved yet.
The line most teams are not drawing: there is AI you use to learn and experiment, and there is AI you use to build something the business will actually rely on in an audit. Alan sets loose guardrails for his team specifically so nobody burns weeks on something that was never going to survive a control test.
We also got into Delve, why the blast radius is everybody and not just one vendor, and the uncomfortable check on our own movement. If our answer to every problem is "AI all the things," we are not anti-checkbox anymore. We just built a new checkbox with better branding.
KEY TAKEAWAYS
Separate exploring from producing. Playing with a tool to upskill is not the same as shipping an evidence pipeline the business depends on. Say which one you are doing before you start.
Augment the learning, do not replace it. If you have churned out the same deliverable ten times and your actual knowledge never got deeper, all you got better at was writing prompts. You are still accountable for the output.
Know the questions before your auditor asks them. How deterministic is it. How reproducible. How repeatable. How consistent. How complete and accurate. You cannot spin up an agent to go pull evidence when you cannot say what source system it pulled from.
Control owners are doing this too. AI is showing up inside control design and operating effectiveness, not just evidence collection. That gets assessed on its own terms, and the standard depends on how much certainty that control actually needs.
The burden of proof is on us. Auditors are not going to wake up and announce a new model of assurance.
The Big Four will not move first. Smaller firms are more willing to work with teams heading this direction, and the big firms will feel it when clients walk. But there is a floor, and the race to the cheapest possible SOC 2 is a big part of how we got here.
If it leaves the department, it represents the department. That applies to whatever your agent just generated too.
Alan is one of the few people posting from inside the work rather than above it. This one earned the reputation.
20 Years In Finance. Zero Right Answers. Hired Anyway | Guest: Sunil Karir
16 Aug 2026
00:57:04
Sunil Karir spent 20 years as an accountant before he ever touched cybersecurity. He got laid off, spoke to a couple of friends, took a handful of entry level courses, and then applied to ten jobs a day, every day, for about four months. When he finally landed an interview at an MSP, he got every single technical question wrong. TLS, the handshake, all the layers, all of it. The hiring manager asked him straight up why he should take him on. Sunil said "why not." He got the job.
That is where this one opens, and it does not let up. We get into the part of a career pivot that nobody posts about: the nights and days learning Fortinet and Juniper on the job while your colleagues carry you, raising your hand for the ISO 27001 re-cert nobody else wanted, and figuring out that the audit brain you built over two decades in finance was the asset the whole time.
We also spend real time on where he and I overlap outside the work. Immigrant parents, the family shop, four in the morning, on time is late, and the question every one of us got handed back with a 70 percent test score: what happened to the other 30. Then the harder part, which is figuring out what to keep from all that and what to leave behind when you are the parent now.
If you are trying to break in, or you are already in GRC and wondering why the screenshots feel hollow, this one is for you.
Key Takeaways
Attitude gets you in the door. It does not keep you in the room. Sunil's take is that talent gets you so far and then the only thing left is outworking the people around you.
The pivot is not a hack. Ten applications a day, every day, at every level, including the ones you have no business applying to. Four months of that before the LinkedIn message that changed everything.
The move that redirected his whole career was volunteering for a compliance project nobody else wanted. He ran an ISO 27001 recert between himself and Google, and found the discipline he actually belonged in.
Certs still carry bargaining power because they give an employer a little reassurance when they cannot evaluate you technically. But do the work before the cert, not instead of it.
Thirty people in his training cohort. Two got jobs in cyber. That gap is not talent.
His closing advice: go learn privacy. GDPR is still the global reference point, it gets you into contract conversations, and it is the substrate underneath most of what is happening in AI governance right now.
Checkbox Compliance Is Better Than Nothing | AI Gov From The Trenches w/ Chris van der Heijden
08 Aug 2026
00:55:40
Our guest builds AI governance for a living and he told us that checkbox compliance is better than nothing. On this show. We let it ride, because the context changes the whole argument.
Chris van der Heijden is not talking about a Fortune 500 with a compliance function. He is talking about the three to ten person startups shipping the AI features the rest of us are about to buy. Every governance guide in existence is written for enterprises, or at minimum for mildly mature companies. The teams actually generating the risk have none of that, and most of them believe they need a full compliance team before they can even start.
Chris spent four years building a data clean room for sports sponsorship data. Encrypted computation on fan records, rights holders on one side, brands on the other. He exited earlier this year and now runs Vaiking AI, helping startups build governance that fits on a runway instead of a roadmap. His framework is called privacy by design from the trenches, and the tell that he actually lived it is that policy is the third pillar, not the first.
Worth noting, this was Chris's first podcast appearance ever. You would not know it.
Key Takeaways
Governance debt is worse than technical debt. Function creep pushes a use case into a higher risk bracket under the EU AI Act, and Chris's argument is that you cannot pay it down after the fact because the artifacts had to exist at the moment the decision was made.
The entry price is lower than founders think. A register, a few small policies, and real conversations about what gets recorded where. Chris built a full ISMS anyway, and the return was not the certificate. It was clearing enterprise due diligence questionnaires without the deal stalling.
Every party in the chain had an incentive not to care. Rights holders wanted sponsors, brands wanted conversions, fans wanted their team to win. Nobody was going to ask for data minimization, so the platform in the middle had to enforce it on all sides.
People Don't Scale: Tamelia Hutchinson on the 40 Year "Fad" of GRC Engineering
01 Aug 2026
00:41:21
We asked Tamelia Hutchinson whether GRC engineering is a fad or here to stay. She answered with a question of her own: what is your definition of GRC engineering? Everything after that was worth the price of admission.
Tamelia has spent about twenty years in security and compliance, accidentally at first and then on purpose. In this one she splits GRC engineering into its process side and its technical side, argues neither one is going anywhere, and lands on a phrase that is going to live in our head for a while: it has been a fad for forty years, so it is a fad in the geological sense.
We get into the thing nobody warns you about, which is that if you automate a bad process, you are just automating your demise. You get to the cliff faster. Tamelia walks through why software led transformation stalls when the people on the receiving end were never brought along, what she does when there is no internal proof of concept to point at, and the specific question she asks to get a stakeholder to imagine a different way of working instead of defending the current one.
She also breaks down how she actually learned to talk to leadership, which was not from a book. It was from sitting in rooms with people who were better at it than she was, listening for what connected, and then adapting it rather than copying it. Her line on that: copying someone else's delivery is like wearing somebody else's pants who says they are going to fit you.
And then there is the part we did not see coming. Leadership asked her how they would know the investment in compliance and security had paid off. Her answer was that they would know when they could let her go. When the maturity is high enough and the toil is reduced enough that her position is not needed. Her reasoning is the whole thesis of this show compressed into three words: people don't scale.
The GRC Engineering Club is a community of practitioners treating governance, risk, and compliance as an engineering discipline instead of a documentation ritual.
Subscribe for new episodes of the AntiCheckbox Podcast every week.
The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran from Locktivity
28 Jul 2026
00:47:33
"We have this weird model where it's like hand me a SOC 2 or answer a questionnaire, tell me everything's good, let's shake hands and move on. And then we forgot to enable 2FA..."
In this episode of the Anti Checkbox Podcast, O sits down with Rachel Curran to dismantle the current state of Third-Party Risk Management (TPRM). Rachel brings a brutally honest perspective to the industry, explaining why the traditional reliance on massive questionnaires and point-in-time compliance frameworks is nothing more than "security theater."
We discuss why small 10-to-12 person startups are being sold a false narrative that they need a SOC 2 or ISO certification just to do business. Instead, Rachel argues for a return to first principles: focusing on continuous monitoring of core security hygiene, like Multi-Factor Authentication (MFA), which can stop the vast majority of breaches. We also explore how a transparent, right-sized security program acts as a "trust marketplace" that can actually help companies close six-figure deals.
Key Takeaways:
Security Theater: Why passing around massive questionnaires and point-in-time SOC 2 reports completely fails to stop actual breaches.
The MFA Mandate: Why prioritizing basic hygiene like MFA and encryption is infinitely more valuable than completing 250-point compliance checklists.
Advice for Startups: Why tiny companies should avoid the trap of pursuing expensive SOC 2 certifications and instead invest in a few hours of expert consulting to nail down core business risks.
Selling with Security: How treating third-party risk as a competitive differentiator can get you budget, build trust, and help your company close major enterprise deals.