Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab episode artwork

EPISODE · Mar 6, 2025 · 52 MIN

Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab

from Security & GRC Decoded · host Raj Krishnamurthy

In this episode of Security & GRC Decoded, host Raj Krishnamurthy (CEO of ComplianceCow) sits down with Ayoub Fandi, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of GRC through an engineering lens. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing real-time data, automation, and developer-friendly processes is the key to building stronger security and compliance programs. He also reveals his controversial perspective on external certifications—explaining why they can sometimes feel overrated—and makes the case for continuous, risk-based assurance that truly reflects an organization’s security posture. If you’ve ever felt the “cognitive dissonance” of outdated compliance controls in a modern engineering world, this conversation is a must-listen. Key Takeaways ✅ Bridging the Gap with Engineering: How GRC teams can embed themselves into developers’ workflows (e.g., JIRA, pull requests) to gain more accurate data and achieve real-time compliance insights. ✅ Continuous vs. Annual Audits: The advantages of leveraging APIs and automation to monitor control effectiveness in near real-time, instead of relying on point-in-time evidence. ✅ Rethinking External Certifications: Why these certifications can be a misleading representation of true security and how GRC professionals can ensure audits deliver real value. ✅ Building a Modern GRC Program: Practical tips on designing policies and controls that align with fast-paced, cloud-native environments—minus the “waterfall mentality.” Tune in to hear why GRC must evolve alongside today’s DevOps-driven world, and how you can unlock greater efficiency, credibility, and trust by adopting an engineering-first approach to governance, risk, and compliance. 🎙️ Security & GRC Decoded is brought to you by ComplianceCow. Make sure to rate and review the show to let us know you're enjoying the content! Subscribe now for expert insights from industry leaders shaping the future of security & compliance. Learn More About How ComplianceCow Can Help Your GRC Team Today! 🎙️ Follow Ayoub Fandi: Stay connected with Carlos’s insights and experiences by following him on LinkedIn:

Episode metadata supplied by the publisher feed · Published Mar 6, 2025

Embed this episode

In this episode of Security & GRC Decoded, host Raj Krishnamurthy (CEO of ComplianceCow) sits down with Ayoub Fandi, a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of GRC through an engineering lens. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing real-time data, automation, and developer-friendly p...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Engineering Better Relationships: Why We Should Shift GRC Left w/ Ayoub Fandi @ Gitlab

0:00 52:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security & GRC Decoded?

This episode is 52 minutes long.

When was this Security & GRC Decoded episode published?

This episode was published on March 6, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Security & GRC Decoded episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!