Rethinking SOC 2 & GRC | Ctrl-Alt-Secure S4E16 ft. Emma Lawler & AJ Yawn episode artwork

EPISODE · May 19, 2026 · 42 MIN

Rethinking SOC 2 & GRC | Ctrl-Alt-Secure S4E16 ft. Emma Lawler & AJ Yawn

from Ctrl - Alt - Secure Podcast · host Red Sentry CEO Valentina Flores

In this episode of Ctrl-Alt-Secure, Valentina Flores, CEO of Red Sentry, sits down with Emma Lawler and AJ Yawn from Rippling to explore the evolving world of Governance, Risk, and Compliance (GRC) and why modern organizations need to rethink how they approach SOC 2 audits, security evidence, and compliance operations.Emma and AJ share insights into how companies can move away from manual, checkbox-driven compliance processes and toward engineering-driven security programs powered by automation, transparency, and first-party data. Rather than treating GRC as a once-a-year project, the conversation focuses on building systems that continuously improve security posture while reducing friction between companies, auditors, and operational teams.The discussion dives into why automation should not be confused with reduced rigor, the importance of maintaining auditor independence, and how organizations can shift compliance “to the left” by embedding security into operational workflows instead of treating it as a final hurdle.Valentina, Emma, and AJ also explore the cultural side of compliance, including why findings should be viewed as actionable signals for improvement rather than blame, and how organizations can design systems where compliance efforts compound over time instead of restarting from scratch every audit cycle.Key topics covered:• Why SOC 2 is more than a compliance checkbox• Engineering compliance instead of documenting compliance• The role of automation and first-party data in modern GRC• Why auditor independence still matters• Shifting security and compliance earlier into operational workflows• Treating GRC as a continuous product instead of a yearly project• Building scalable systems that reduce long-term audit fatigue• Turning security findings into opportunities for improvementWho should listen:This episode is ideal for security leaders, compliance professionals, auditors, startup founders, IT teams, and anyone looking to build more sustainable and scalable security and compliance programs.About Ctrl-Alt-SecureCtrl-Alt-Secure is brought to you by Red Sentry, a human-led, tech-powered penetration testing firm helping companies identify and fix vulnerabilities before attackers can exploit them.🔗 Learn more about Red Sentry: https://redsentry.com/🔗 Learn more about Rippling: https://www.rippling.com/Find more about Red Sentry. 

Episode metadata supplied by the publisher feed · Published May 19, 2026

Embed this episode

In this episode of Ctrl-Alt-Secure, Valentina Flores, CEO of Red Sentry, sits down with Emma Lawler and AJ Yawn from Rippling to explore the evolving world of Governance, Risk, and Compliance (GRC) and why modern organizations need to rethink how they approach SOC 2 audits, security evidence, and compliance operations. Emma and AJ share insights into how companies can move away from manual, checkbox-driven compliance processes and toward engineering-driven security programs powered by automat...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Rethinking SOC 2 & GRC | Ctrl-Alt-Secure S4E16 ft. Emma Lawler & AJ Yawn

0:00 42:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Ctrl - Alt - Secure Podcast?

This episode is 42 minutes long.

When was this Ctrl - Alt - Secure Podcast episode published?

This episode was published on May 19, 2026.

Can I download this Ctrl - Alt - Secure Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!