The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

Can Compliance Be Cool? Harness's Andrew Spangler Thinks So

Security & GRC Decoded · 2025-05-15 · 55 min

0:00--:--

Topics in this episode

Risk managementGenAI SecurityCompliance EngineeringAutomation GRCSBOMs

Episode notes

In this episode of Security and GRC Decoded , Raj Krishnamurthy sits down with Andrew Spangler , Director of Security and GRC at Harness , to explore how compliance engineering can go far beyond checkboxes - and actually drive innovation. Andrew shares his journey from building the compliance engineering function at Datadog to scaling automation and visibility across the SDLC at Harness. He dives into how using internal platforms for security workflows (aka “drinking your own champagne”) can unlock time savings and risk reduction, especially in areas like vulnerability management and secure software delivery. Key Takeaways: How compliance automation builds credibility and supports innovation. Lessons from building compliance engineering at Datadog. Harnessing the power of SBOMs and supply chain security. Practical uses of generative AI and ChatGPT for GRC workflows. The future of democratized threat modeling. Advice for new grads entering security and GRC. Podcast recommendations that go beyond the security bubble.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Corporate Finance Explained | When Bitcoin Hits The Balance SheetFinPod · on Risk management80 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on Risk management79 / 100
  • The Financial Stakes of Risk Management in a Self-Insured CaptiveThe Canary Report: Safety & Risk Management · on Risk management77 / 100
  • How Vertical SaaS Solves the Compliance Trap in ConstructionVertical SaaS with Fexingo · on Risk management
  • How Jamie Dimon Built a Fortress Balance Sheet at JPMorganThe CEO Diary with Fexingo · on Risk management

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →