The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

Scaling GRC Without the Chaos: How to Build Programs That Don’t Break ft Tom Scuderi, Senior Manager of Security & GRC @ LTK

Security & GRC Decoded · 2025-12-16 · 56 min

0:00--:--

Topics in this episode

grcRaj KrishnamurthySecurity and GRC DecodedTom ScuderiLTK

Episode notes

In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Tom Scuderi , Senior Manager of Security & GRC at LTK and a veteran practitioner who has spent his career building governance functions at QTS, Tableau, Salesforce, and LTK. Tom shares how to scale GRC in high-growth environments by designing processes that resemble engineering workflows, reducing friction with stakeholders, and shifting from reactive audits to continuous visibility. He breaks down why curated visibility beats blanket access, why SOC 2 should sharpen - not dilute - your security program, and how to anchor leadership decisions with meaningful risk data. Key Takeaways GRC only scales when its processes mirror how engineering teams already work. SOC 2 should enhance your security program rather than becoming a superficial checkbox exercise. Curated visibility reduces friction and improves cross-functional trust. Clarity in ownership is the backbone of a scalable GRC function. Continuous, context-driven evidence cuts audit fatigue and sharpens the entire program. What You’ll Learn How Tom built and matured GRC programs across four different companies.

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →