
Security & GRC Decoded · 2025-08-05 · 1h 13m
Jiphun Satapathy has built and scaled security organizations at AWS , Snowflake , and now Medallia . In this episode, he joins our host Raj to explore the evolving role of CISOs as strategic business leaders . They discuss the importance of treating security as a service organization , how to handle vendor noise , and why insider risk is often overlooked . You’ll hear practical advice for security and GRC leaders working in AI-first , high-growth environments - and how to maintain trust across engineering, compliance, and executive teams . Key Takeaways Security as a Service Function : Security should empower - not block - the business. Jiphun shares how his team supports product, engineering, and sales. Vendor Engagement Matters : CISOs who ignore vendors miss out on innovation. But filtering the noise is key. Insider Risk is Real : Not rogue employees, but everyday developer behavior is a top source of risk. Modern GRC Requires Technical Fluency : Especially in AI-first companies, GRC teams must understand the tech stack to stay relevant. Earn Trust Through Action: Metrics matter, but culture and execution are what build credibility with boards, customers, and engineers.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.