GRC ENGINEER
THE GRC GRAPH
$ archive
$ persona
SUBSCRIBE
CRT-01
LEGEND
theme · click to unfold
release
cited / match
+
−
⌂
$
THEMES
15
· RELEASES
74
·
LIVE
The GRC Graph: every release by concept cluster
GRC ENGINEERING (34)
⚙️ Everyone Says Get Technical. Nobody Says At What.
⚙️ Threatify Your GRC Workflows: Keep the Steps, Swap the Questions
⚙️ Your GRC Program Has No Garbage Collector. So It Leaks.
⚙️ A Lot Of GRC Work Is Performative. So Was Security, Once Upon a Time.
⚙️ Not Every Control Belongs in the ICU: A GRC Engineering Guide to Control Triage
⚙️ You Spent a Year Learning to Use AI for GRC. The Real Skill Is Assessing It.
❤️ I just started at Lovable. 5 things I've been thinking about as I'm onboarding.
⚙️ Meet The GRC Companion: Your GRC Engineering AI Learning Buddy
⚙️ GRC as Git: A Mental Model for your Whole Programme
⚙️ What If Compliance Was Just a Query on Data You Already Collect?
⚙️ GRC Teams Are Getting More Capable Than Ever But The Shape Looks Different.
⚙️ Your GRC Program Serves the Audit. The Best GRC Engineering Programs Don't.
💬 Build vs. Buy: We Did Both. Here's What We Learned (RSAC 2026 Talk Summary)
⚙️ Your Certification Covers 100%. Your Auditor Checked 0.07%.
📝 State of GRC 2026 Report: Spreadsheets are still #1
⚙️ How to Stop Making Risk Management a Compliance Control
🏴☠️ Building the GRC Engineering Trust Infrastructure: Introducing Corsair
⚙️ GRC plays PvE when everyone else in Security plays PvP
⚙️ Compliance-as-Cope: How GRC Engineering Automated the Wrong Thing
⚙️ The 3 Types of Automation in GRC Engineering (pick the right one)
⚙️ Engineer Your GRC Process Before You Automate It
🎁 GRC Engineer 2025 Wrapped (+ Shape What's Next)
🎴 GRC Engineering Collector Cards: Chief Information Security Officer
⚙️ What Engineers Know That GRC Professionals Don't
🎴 GRC Engineering Collector Cards: Software Engineer
⚙️ What GRC Engineering Is Actually Grateful For Across People, Process, and Technology
🎴 GRC Engineering Collector Cards: Security Engineer
⚙️ Are You Building for Auditors or Attackers? The GRC Engineering Shift
⚙️ You Still Work in GRC: What GRC Engineering Is, and What It Isn't
⚙️ The GRC Engineering Implementation Framework That Works for Enterprises (no more DIY failures)
⚙️ GRC Engineer vs. GRC Engineering. Which one you need? Maybe both?
⚙️ The GRC Engineering Maturity Model v1.0
⚙️ Unlocking the Hidden Value in Your Current GRC Platform
⚙️ The Technical Foundations Every GRC Professional Needs
GRC ARCHITECTURE (19)
⚙️ The Compliance Leverage Ladder: Your GRC Roadmap Is Pulling the Weakest Levers
⚙️ GRC Finally Has Too Much Context. Most Teams Will Waste It...
⚙️ A Lot Of GRC Work Is Performative. So Was Security, Once Upon a Time.
⚙️ Not Every Control Belongs in the ICU: A GRC Engineering Guide to Control Triage
⚙️ GRC as Git: A Mental Model for your Whole Programme
⚙️ Your First GRC Lead Left. Their Instincts Are Still Running Your Program.
⚙️ What If Compliance Was Just a Query on Data You Already Collect?
⚙️ Your GRC Program Serves the Audit. The Best GRC Engineering Programs Don't.
📝 State of GRC 2026 Report: Spreadsheets are still #1
⚙️ How to Stop Making Risk Management a Compliance Control
⚙️ Compliance-as-Cope: How GRC Engineering Automated the Wrong Thing
⚙️ The Framework Mapping Trap: When Documentation Precedes Reality
⚙️ Engineer Your GRC Process Before You Automate It
⚙️ The Three Lines of Defence, a systems-thinking approach
⚙️ Why DIY GRC Automation Breaks at Enterprise Scale
⚙️ GRC Team Topologies: When to Centralise, Distribute, or Build Platform Models
⚙️ Building a Central Data Layer: The Foundation of Modern Enterprise GRC
⚙️ From Silos to Systems: GRC Architecture
⚙️ From Silos to Systems: GRC Architecture
COMPLIANCE (15)
⚙️ The Compliance Leverage Ladder: Your GRC Roadmap Is Pulling the Weakest Levers
⚙️ Threatify Your GRC Workflows: Keep the Steps, Swap the Questions
⚙️ Your GRC Program Has No Garbage Collector. So It Leaks.
⚙️ Not Every Control Belongs in the ICU: A GRC Engineering Guide to Control Triage
⚙️ What If Compliance Was Just a Query on Data You Already Collect?
⚙️ Your GRC Program Serves the Audit. The Best GRC Engineering Programs Don't.
⚙️ Your Certification Covers 100%. Your Auditor Checked 0.07%.
⚙️ GRC plays PvE when everyone else in Security plays PvP
⚙️ The Framework Mapping Trap: When Documentation Precedes Reality
⚙️ The 3 Types of Automation in GRC Engineering (pick the right one)
⚙️ The Zillow Effect in GRC: When Platforms Perform Control Testing
⚙️ Automating Quarterly Access Reviews: GRC Engineering in practice
⚙️ Why the Policy-as-Code revolution didn't happen (and what can we do?)
⚙️ Designing Controls Where Compliance is an Afterthought
⚙️ Control Orchestration: The Missing Link in Enterprise Compliance Programs
SYSTEMS THINKING (15)
⚙️ The Compliance Leverage Ladder: Your GRC Roadmap Is Pulling the Weakest Levers
⚙️ Everyone Says Get Technical. Nobody Says At What.
⚙️ Threatify Your GRC Workflows: Keep the Steps, Swap the Questions
⚙️ GRC Finally Has Too Much Context. Most Teams Will Waste It...
⚙️ Your GRC Program Has No Garbage Collector. So It Leaks.
⚙️ A Lot Of GRC Work Is Performative. So Was Security, Once Upon a Time.
⚙️ You Spent a Year Learning to Use AI for GRC. The Real Skill Is Assessing It.
⚙️ Meet The GRC Companion: Your GRC Engineering AI Learning Buddy
⚙️ Your First GRC Lead Left. Their Instincts Are Still Running Your Program.
⚙️ GRC Teams Are Getting More Capable Than Ever But The Shape Looks Different.
💬 Build vs. Buy: We Did Both. Here's What We Learned (RSAC 2026 Talk Summary)
⚙️ The Framework Mapping Trap: When Documentation Precedes Reality
⚙️ What Engineers Know That GRC Professionals Don't
⚙️ What GRC Engineering Is Actually Grateful For Across People, Process, and Technology
⚙️ Signal vs. Noise: The Mental Model That Transforms GRC Effectiveness
GRC AS A PRODUCT (11)
⚙️ Everyone Says Get Technical. Nobody Says At What.
❤️ I just started at Lovable. 5 things I've been thinking about as I'm onboarding.
💬 Build vs. Buy: We Did Both. Here's What We Learned (RSAC 2026 Talk Summary)
🏴☠️ Building the GRC Engineering Trust Infrastructure: Introducing Corsair
⚙️ GRC plays PvE when everyone else in Security plays PvP
🤖 3 Basic Things Killing Your AI Usage for GRC
⚙️ What Engineers Know That GRC Professionals Don't
🎴 GRC Engineering Collector Cards: Product Manager
⚙️ Becoming a GRC Product Manager: The Evolution Beyond Compliance TPM
⚙️ Where GRC is a Product: Breaking the Project Mindset
👟 Your GRC Program Needs a Product Manager, Not Another ex-Auditor
STAKEHOLDER MANAGEMENT (11)
⚙️ Your First GRC Lead Left. Their Instincts Are Still Running Your Program.
⚙️ GRC Teams Are Getting More Capable Than Ever But The Shape Looks Different.
🎴 GRC Engineering Collector Cards: Chief Information Security Officer
🎴 GRC Engineering Collector Cards: Software Engineer
⚙️ What GRC Engineering Is Actually Grateful For Across People, Process, and Technology
🎴 GRC Engineering Collector Cards: Security Engineer
🎴 GRC Engineering Collector Cards: Product Manager
⚙️ GRC Engineering isn't running parallel to security, it's running behind it
⚙️ Selling GRC Engineering: From Vision to Executive Buy-In
⚙️ The Human API: Building Interfaces Between GRC and Engineering Teams
⚙️ From Obstacles to Allies: Winning Over Key GRC Stakeholders
AI IN GRC (10)
⚙️ GRC Finally Has Too Much Context. Most Teams Will Waste It...
⚙️ You Spent a Year Learning to Use AI for GRC. The Real Skill Is Assessing It.
❤️ I just started at Lovable. 5 things I've been thinking about as I'm onboarding.
⚙️ Meet The GRC Companion: Your GRC Engineering AI Learning Buddy
⚙️ GRC Teams Are Getting More Capable Than Ever But The Shape Looks Different.
⚙️ Your Certification Covers 100%. Your Auditor Checked 0.07%.
⚙️ Engineer Your GRC Process Before You Automate It
🤖 3 Basic Things Killing Your AI Usage for GRC
⚙️ GRC's AI Dilemma: Strong Workflow, Dumb AI vs Dumb Workflow, Strong AI
⚙️ Vibe Coding for GRC Engineering: A Practitioner's Guide
PODCAST (6)
🔎 Rebuilding GRC from Scratch at Docker w/ Emre & Chad
🎙️ The GRC Engineering Blueprint for the Public Sector w/ Dr. Ibrahim Waziri Jr.
🎙️ Why Cyber Risk Quantification is the mindset shift your GRC program needs w/ Tony Martin-Vegue
🎙️ Beyond The API: GRC Engineering in the Real World w/ Ange Ferrari
👷🏻♂️ Is GRC Engineering the next DevSecOps?
🤖 AI Agents as the next GRC Frontier
RISK MANAGEMENT (5)
⚙️ How to Stop Making Risk Management a Compliance Control
⚙️ Compliance-as-Cope: How GRC Engineering Automated the Wrong Thing
⚙️ Are You Building for Auditors or Attackers? The GRC Engineering Shift
⚙️ The GRC Graduation: From Compliance Theatre to Risk-Driven Insights
⚙️ Risk Registers Reimagined: From Static Inventories to Action Engines
GRC COLLECTOR CARDS (4)
🎴 GRC Engineering Collector Cards: Chief Information Security Officer
🎴 GRC Engineering Collector Cards: Software Engineer
🎴 GRC Engineering Collector Cards: Security Engineer
🎴 GRC Engineering Collector Cards: Product Manager
DEEP-DIVE (3)
📝 State of GRC 2026 Report: Spreadsheets are still #1
🔎 Rebuilding GRC from Scratch at Docker w/ Emre & Chad
🔎 Deep-Dive on Coveo's GRC Program w/ Pierre-Paul Ferland
GOVERNANCE (2)
⚙️ GRC as Git: A Mental Model for your Whole Programme
⚙️ Git-Based Policy Management: The Version-Controlled Future of Governance
CORSAIR (1)
🏴☠️ Building the GRC Engineering Trust Infrastructure: Introducing Corsair
GRC MARKET PULSE (1)
📊 GRC Market Pulse April/May 2025 Part 1: Anecdotes $55M Series B, The Full Deep-Dive Analysis
VENDOR ROUNDTABLE (1)
🎙️ GRC Automation Vendors Roundtable