How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime episode artwork

EPISODE · Nov 13, 2025 · 56 MIN

How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime

from Security & GRC Decoded · host Raj Krishnamurthy

In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Mukund Sarma, Deputy CISO and Head of Product Security at Chime, to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass in aligning security, GRC, and DevOps for scale and sanity.5 Key TakeawaysGRC isn’t a blocker—it’s a mirror that keeps security honest and accountable.Strong security engineering automatically strengthens compliance outcomes.Friction between security and engineering fades when empathy drives collaboration.“Shift left” works best when paved paths and automation support developers.Practical controls and continuous validation create sustainable, scalable governance.What You’ll LearnHow to bridge silos between security, GRC, and engineering teams.Why automation and continuous control monitoring are the future of compliance.What “practical controls” really mean in modern DevSecOps environments.How empathy and communication transform security culture.Why compliance should follow great security engineering, not lead it.Real-world examples from Chime’s approach to product security.This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.comWatch more episodes: https://www.compliancecow.com/podcastConnect With Our Guest:Mukund Sarma | Deputy CISO and Head of Product Security | Chime Connect on LinkedIn: https://www.linkedin.com/in/sarmamukund/Rate, review, and share if you enjoyed the show!Subscribe to Security & GRC Decoded wherever you get your podcasts:Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqrApple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450?i=1000736617569

Episode metadata supplied by the publisher feed · Published Nov 13, 2025

Embed this episode

In this episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Mukund Sarma, Deputy CISO and Head of Product Security at Chime, to explore what happens when governance, risk, and compliance teams work with engineering instead of against it. Mukund shares real-world lessons from a decade in security, explaining how to balance shift-left initiatives, build paved paths that reduce friction, and make compliance a natural byproduct of great engineering. This is a masterclass ...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

How Pragmatic Controls Build Trust Between GRC, Security, and Engineering ft Mukund Sarma, Deputy CISO @ Chime

0:00 56:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security & GRC Decoded?

This episode is 56 minutes long.

When was this Security & GRC Decoded episode published?

This episode was published on November 13, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Security & GRC Decoded episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!