
Security & GRC Decoded · 2025-06-26 · 1h 19m
What if compliance wasn't just about passing audits - but about building trust from the ground up? In this powerful episode of Security & GRC Decoded , Raj sits down with Ricky Waldron , Director of Security Audit & GRC at Navan , whose GRC experience spans tech giants like Microsoft , Disney , Oracle , and Smartsheet . Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine of trust, not a blocker. From FedRAMP horror stories to generative AI workflows, this conversation dives deep into the future of governance, risk, and compliance - and why it's time for GRC teams to start thinking like engineers. 5 Key Takeaways Compliance = Security (If Done Right): Internal compliance based on risk and business needs often leads to stronger security outcomes than external certifications alone. Stop Policing, Start Partnering: GRC shouldn’t just point out problems - it should offer solutions and collaborate with teams to reduce risk. Quantify Risk to Speak Leadership’s Language: Turn technical risk into business impact using frameworks like FAIR to get buy-in and budget.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.