
Hosted by Raj Krishnamurthy
How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy.
37 episodes · publishes fortnightly · latest 2026-06-25 · ~60 min/episode
Rank
#23
Substance
88.2
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#23 of 6183
Substance
Top 1%
outscores 100% of the index
Security & GRC Decoded ranks #23 on The B2B Podcast Index with a substance score of 88.2 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Jasmine Kaur is a genuinely strong practitioner guest: 20+ years in cybersecurity, hands-on GRC leadership at major scale (Google, SAP, CoreWeave), currently building GRC strategy at an AI hyperscaler during a critical inflection point. She speaks from real operational constraints, not theoretical positions. Her credibility is reinforced by specific war stories and the complexity of her current role.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers substantial, non-obvious insights about GRC transformation in AI infrastructure, particularly the tension between ephemeral systems and traditional audit models. Jasmine articulates concrete problems (GPU return cycles, evidence staleness, ephemeral infrastructure) and proposes novel frameworks (GRC as infrastructure, signals/thresholds, agentic GRC). However, some segments include repetitive explanation and softer advice toward the end that dilutes density.
“by the time our audit readiness dance completed, the GPUs were already returned to the pool. The identity was already revoked. and the new network paths, the storage, et cetera, will be reconfigured”
“When I say GRC is part of the infrastructure, I mean your control set, your compliance guardrails are embedded in the infrastructure itself. It runs all the time. It scales automatically.”
The framing of GRC as fundamentally broken for AI infrastructure is relatively fresh and contrarian to mainstream GRC thinking. The specific assertion that audit models assume systems will 'pause long enough' for sampling, and the proposal that GRC must become infrastructure-embedded rather than application-layer are genuinely counterintuitive. However, continuous controls monitoring and 'shift-left' concepts are established patterns, limiting novelty somewhat.
“audits assume the system will pause long enough for it to be able to sample or pull an evidence, right? But the AI systems don't. And it's not only because there is a misconfiguration, it's because they are short-lived by design.”
“the traditional way of managing audit will not work for us”
Jasmine Kaur is a genuinely strong practitioner guest: 20+ years in cybersecurity, hands-on GRC leadership at major scale (Google, SAP, CoreWeave), currently building GRC strategy at an AI hyperscaler during a critical inflection point. She speaks from real operational constraints, not theoretical positions. Her credibility is reinforced by specific war stories and the complexity of her current role.
“Jasmine has 20 plus years in cybersecurity managing security operations teams, GRC. She has worked for some fantastic companies like SAP, Google, and now she's at CoreWeave.”
“the way it what it means to us right so as a GRC practitioner I would also like to tell you Raj working for AI hyperscaler what does it mean right it means that the traditional GRC models will not work for us”
Jasmine provides the GPU-return-cycle audit story as concrete evidence of the core problem, and references specific techniques (policy-as-code, controls-as-code, signals/thresholds). She names CoreWeave, Google, SAP, and mentions frameworks like CCM. However, she lacks dollar figures, timelines, quantified impact metrics, or details on actual implementations at CoreWeave. The agentic GRC discussion is conceptual without concrete use cases or prototypes demonstrated.
“At Coreweave, we were to audit our product, which is an AI cloud product. Now, for us to be able to scope that particular audit, we had AI training workloads running on the GPU-backed infrastructure.”
“policy as a code, control as a code, or embedding GRC part of the infrastructure itself”
Raj demonstrates strong interviewing: he asks clarifying follow-ups (model vs. ML model distinction), challenges assumptions (SIEM vs. infrastructure-embedded approach), and pushes on the auditor relationship. However, he occasionally accepts claims without deep pushback (e.g., on the feasibility of agentic GRC adoption, or how leadership actually funds this). Some questions are soft or generic (women in leadership), and there's an awkward audio issue mid-conversation. The host does synthesize well and summarize key points.
“Are you saying that the GRC team should take an active role in threat modeling?”
“how is this different than traditionally log shipping into a central SIM like Splunk or LogRhythm”
First period on the Index - history builds from here.
10 scored on substance · 37 tracked in total.
The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC
2026-06-25 · 38 min
Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath
2026-06-02 · 54 min
From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave
2026-05-05 · 54 min
The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis
2026-04-21 · 55 min
GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife
2026-04-07 · 1h 8m
Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security & GRC @ Yahoo
2026-03-24 · 60 min
The 3 Year GRC Reckoning: Customer Trust, Real-Time Assurance, and the Future of Risk ft Bryan Culp, Senior Director of Customer Trust @ Box
2026-03-10 · 1h 6m
When GRC Stops Watching and Starts Working ft Ryan Schoeller, Director of Security & GRC @ Treasure Data
2026-02-24 · 57 min
Does GRC Belongs Outside Security? The Case for an Independent Second Line ft Charles Nwatu - GRC Engineering Leader
2026-02-10 · 1h 1m
GRC Is an Engineering Discipline. Not a Checklist. ft Akhila Chitiprolu, Head of Security & GRC @ Sierra
2026-01-27 · 55 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/security-grc-decoded" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/security-grc-decoded/badge.svg" alt="Ranked #3 on The B2B Podcast Index" width="360" height="136" />
</a>Track Security & GRC Decoded's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.