
Security & GRC Decoded · 2025-12-16 · 56 min
In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Tom Scuderi , Senior Manager of Security & GRC at LTK and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen - not dilute - your security program, and how to anchor leadership decisions with meaningful risk data. Key Takeaways GRC only scales when its processes mirror how engineering teams already work. SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise. Curated visibility reduces friction and improves cross-functional trust. Clarity in ownership is the backbone of a scalable GRC function. Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program. What You’ll Learn How Tom built and matured GRC programs across four different companies.