Who’s on this one
Ryan Schoeller — Director, Security GRC, Treasure AI, where he runs the security governance, risk and compliance program for an enterprise customer data platform. His argument: GRC engineering is a full-breadth discipline — the way a security operations engineer covers detections, response and integration rather than just log pipelines — and the real gap isn’t collecting the evidence, it’s what happens after.
Stas Bojoukha — Founder & CEO, Compyl. 20+ years as a CISO across financial services, real estate, and energy.
Daniel Tangney — Host, GRC Radio.
Who should be in the room
- GRC and compliance managers — you have the evidence pipeline, or you want one. This is about what to build next and who owns what comes out of it.
- CISOs and security leaders — if you are hiring or scoping a GRC engineer, this is the job description you should be writing.
- Security and platform engineers embedded in or adjacent to GRC — the people being asked to “automate compliance” and wondering where the job actually ends.
Run of show
Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.
- Where “GRC engineering = evidence pipelines” came from — and everything it leaves out.
- The SecOps analogy — what a security operations engineer actually covers, and what the GRC equivalent looks like when you are not a Fortune 100 with an army of specialists.
- The programmable surface — TPRM lifecycle, customer questionnaires and trust center, access governance, executive reporting: automating the whole lifecycle, not just the pull.
- Computable risk — moving risk quantification from narrative to something you can calculate and defend.
- After the evidence is collected — the vulnerability-management lesson: a flagged critical isn’t a fixed one, and collected evidence isn’t a closed control. Ownership, workflows and cross-team relationships, or it’s just data sitting in a platform.
- What to build first — a practical starting point for a team of one.
- Live Q&A — open floor.
