
Security & GRC Decoded · 2025-10-30 · 57 min
How do you build real trust between GRC and engineering? In this episode of Security & GRC Decoded, host Raj Krishnamurthy welcomes Tristan Ingold , Security GRC Program Manager at Meta . Tristan shares how consulting shaped his approach, why “policing” doesn’t work, and how GRC earns influence by acting as a partner to engineering - not a blocker. He discusses the cultural friction between audit, security, and product teams, how to communicate in the language of engineering, and why the right role for GRC is a “sparring partner” that helps teams ship safer, faster. From reframing control objectives to focusing on evidence the business already produces, this conversation is a practical playbook for building credibility and velocity at the same time. 5 Key Takeaways Partnership Over Policing: GRC earns influence by modeling partnership behaviors and meeting teams where they are. Translate Controls to Engineering: Use product language and existing telemetry; design evidence around the way the system actually works. Make It Observable: Treat GRC like an observability layer - surface risk signals the business already emits.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.