How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta episode artwork

EPISODE · Oct 30, 2025 · 57 MIN

How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta

from Security & GRC Decoded · host Raj Krishnamurthy

How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker.He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time.5 Key TakeawaysPartnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are.Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works.Make It Observable: Treat GRC like an observability layer -- surface risk signals the business already emits.Tell the Story, Not the Score: Dashboards support the narrative; they aren’t the narrative. Lead with context and trade-offs.Define the Right Role: The best GRC teams act as a sparring partner --challenging, supportive, and focused on outcomes.What You’ll LearnHow to rebuild trust with engineering after “audit fatigue”Practical ways to convert control requirements into product languageHow to design evidence from logs, pipelines, and tickets you already haveWhen to push, when to partner, and how to escalate with credibilityCommunicating risk trade-offs without killing roadmap velocityConnect With Our Guest:Tristan Ingold | Security GRC Program Manager | MetaThis podcast is brought to you by ComplianceCow - the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.Watch more episodesRate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts:SpotifyApple Podcasts

Episode metadata supplied by the publisher feed · Published Oct 30, 2025

Embed this episode

How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold, Security GRC Program Manager at Meta. Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering -- not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the r...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

How to Build Trust Between GRC and Engineering ft Tristan Ingold, Security GRC Program Manager at Meta

0:00 57:19

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security & GRC Decoded?

This episode is 57 minutes long.

When was this Security & GRC Decoded episode published?

This episode was published on October 30, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Security & GRC Decoded episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!