The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

RGC, Not GRC: Why Risk Comes First ft Ricky Waldron

Security & GRC Decoded · 2025-06-26 · 1h 19m

0:00--:--

Topics in this episode

Risk managementcompliancesecuritygrcGovernance Risk Compliance

Episode notes

What if compliance wasn't just about passing audits - but about building trust from the ground up? In this powerful episode of Security & GRC Decoded , Raj sits down with Ricky Waldron , Director of Security Audit & GRC at Navan , whose GRC experience spans tech giants like Microsoft , Disney , Oracle , and Smartsheet . Ricky shares how GRC is evolving into a strategic business partner, why automation and technical fluency are no longer optional, and what it takes to make compliance an engine of trust, not a blocker. From FedRAMP horror stories to generative AI workflows, this conversation dives deep into the future of governance, risk, and compliance - and why it's time for GRC teams to start thinking like engineers. 5 Key Takeaways Compliance = Security (If Done Right): Internal compliance based on risk and business needs often leads to stronger security outcomes than external certifications alone. Stop Policing, Start Partnering: GRC shouldn’t just point out problems - it should offer solutions and collaborate with teams to reduce risk. Quantify Risk to Speak Leadership’s Language: Turn technical risk into business impact using frameworks like FAIR to get buy-in and budget.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Content Management System Landscape with Matt GarrepyRunAs Radio · on security80 / 100
  • The Financial Stakes of Risk Management in a Self-Insured CaptiveThe Canary Report: Safety & Risk Management · on Risk management77 / 100
  • Corporate Finance Explained | Interest Rate Risk ManagementFinPod · on Risk management75 / 100
  • From Demo to Production- Building Enterprise AI Agents That Actually Work with Microsoft Copilot Studio with Elliot Margot [MVP]M365.FM · on compliance
  • Cybersecurity Awesomeness Podcast - Episode 168Cybersecurity Awesomeness Podcast · on security
  • How Jamie Dimon Built a Fortress Balance Sheet at JPMorganThe CEO Diary with Fexingo · on Risk management

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →