Security & GRC Decoded
Security & GRC Decoded
Podcast Description
How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC).
Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs.
Hosted by Raj Krishnamurthy.
It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates.
Security & GRC Decoded brings you:
+ Actionable strategies.
+ Expert insights.
+ Real-world stories to elevate your Security GRC programs.
Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches.
Subscribe now to unlock the tools and knowledge you need to succeed.
Podcast Insights
Content Themes
The podcast explores vital topics in security governance, risk management, and compliance, with episodes such as Engineering Better Relationships highlighting the engineering perspective in GRC and navigating AI Risks sharing crucial AI security insights, creating a comprehensive approach to modern security strategies

How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with James Huang, Head of GRC at Gong, to explore how Governance, Risk, and Compliance has evolved from a traditional audit function into a strategic engineering discipline.
Drawing on experience building GRC programs at Ernst & Young, Cisco, Salesforce, and Gong, James explains why modern GRC leaders must think beyond compliance checklists and focus instead on understanding risk, partnering with engineering, and building scalable security programs. The conversation covers common control frameworks, continuous controls monitoring, third-party risk, AI's impact on GRC, Mythos, automation, and why future GRC professionals need to become business translators rather than framework experts.
Key Takeaways:
- Modern GRC should focus on understanding and reducing risk—not simply satisfying compliance frameworks.
- A Common Controls Framework only succeeds when engineering and business teams understand the risks behind each control.
- Continuous controls monitoring should improve security posture, not just make audits easier.
- AI is transforming GRC by increasing both operational efficiency and third-party risk complexity.
- Successful GRC leaders act as translators between business, engineering, security, and compliance teams.
What You’ll Learn:
- Why compliance frameworks should always be interpreted through the lens of risk
- How to build scalable Common Control Frameworks across complex organizations
- What continuous controls monitoring should actually accomplish
- How AI is changing vendor risk management and security governance
- Why the future of GRC belongs to technically-minded business partners
This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
Watch more episodes: https://www.compliancecow.com/podcast
Connect With Our Guests:
James Huang | Head of GRC | Gong
Connect on LinkedIn: https://www.linkedin.com/in/james-k-huang/
Rate, review, and share if you enjoyed the show!
Subscribe to Security & GRC Decoded wherever you get your podcasts:
Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683
Apple Podcasts:
https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450

Disclaimer
This podcast’s information is provided for general reference and was obtained from publicly accessible sources. The Podcast Collaborative neither produces nor verifies the content, accuracy, or suitability of this podcast. Views and opinions belong solely to the podcast creators and guests.
For a complete disclaimer, please see our Full Disclaimer on the archive page. The Podcast Collaborative bears no responsibility for the podcast’s themes, language, or overall content. Listener discretion is advised. Read our Terms of Use and Privacy Policy for more details.