The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

From Compliance to SBOMs: Josh Bressers’ Take on Security

Security & GRC Decoded · 2025-05-01 · 1h 6m

0:00--:--

Topics in this episode

CybersecurityOpen sourcesecurityJosh BressersSBOM

Episode notes

In this episode, Raj Krishnamurthy sits down with Josh Bressers , VP of Security at Anchore and longtime leader in the open source security space. With decades of experience, Josh brings a candid and compelling perspective on everything from the chaos of early cybersecurity days to the nuanced challenges of SBOMs and compliance in today’s world. Josh reflects on how he entered the security world before there were formal certifications or programs, how community and curiosity fuel innovation in open source, and why the relationships you build are often the most valuable asset in your career. He also dives into exciting new work with the SBOM Everywhere Working Group and shares how GenAI is helping categorize the sprawling ecosystem of SBOM tools. Key Takeaways : GRC teams often overburden themselves with audits. Embracing a product manager mindset helps GRC teams drive security initiatives. Technical knowledge empowers GRC professionals to enhance security programs. Changing perceptions of GRC within organizations is crucial for success. Proactive strategies can elevate GRC’s role and reputation. Integrating privacy into GRC frameworks strengthens compliance efforts.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Formal methods with Hillel WayneThe Pragmatic Engineer · on Open source95 / 100
  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on Cybersecurity89 / 100
  • Mastercard CEO: AI Shopping Agents, Machine-to-Machine Payments, and the New Infrastructure of CommerceMotley Fool Hidden Gems Investing · on Cybersecurity88 / 100
  • The Content Management System Landscape with Matt GarrepyRunAs Radio · on security80 / 100
  • Edge AI Security: Why Secure-by-Design Engineering MattersEmbedded Insiders · on security79 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on Cybersecurity79 / 100

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →