Compyl
Sponsored by:
The Conversation Starts in....
Days
Hours
Minutes
Seconds

Evidence Collection Is Not GRC Engineering

Who’s on this one

Ryan Schoeller — Director, Security GRC, Treasure AI, where he runs the security governance, risk and compliance program for an enterprise customer data platform. His argument: GRC engineering is a full-breadth discipline — the way a security operations engineer covers detections, response and integration rather than just log pipelines — and the real gap isn’t collecting the evidence, it’s what happens after.

Stas Bojoukha — Founder & CEO, Compyl. 20+ years as a CISO across financial services, real estate, and energy.

Daniel Tangney — Host, GRC Radio.

Who should be in the room

  • GRC and compliance managers — you have the evidence pipeline, or you want one. This is about what to build next and who owns what comes out of it.
  • CISOs and security leaders — if you are hiring or scoping a GRC engineer, this is the job description you should be writing.
  • Security and platform engineers embedded in or adjacent to GRC — the people being asked to “automate compliance” and wondering where the job actually ends.

Run of show

Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.

  • Where “GRC engineering = evidence pipelines” came from — and everything it leaves out.
  • The SecOps analogy — what a security operations engineer actually covers, and what the GRC equivalent looks like when you are not a Fortune 100 with an army of specialists.
  • The programmable surface — TPRM lifecycle, customer questionnaires and trust center, access governance, executive reporting: automating the whole lifecycle, not just the pull.
  • Computable risk — moving risk quantification from narrative to something you can calculate and defend.
  • After the evidence is collected — the vulnerability-management lesson: a flagged critical isn’t a fixed one, and collected evidence isn’t a closed control. Ownership, workflows and cross-team relationships, or it’s just data sitting in a platform.
  • What to build first — a practical starting point for a team of one.
  • Live Q&A — open floor.
When
November 5, 2026
Time
2:00 pm –
2:45 pm
Evidence Collection Is Not GRC Engineering — GRC Radio live webinar with Stas Bojoukha and Ryan Schoeller, November 5, 2026

We will cover:

  • Why evidence collection became the poster child for GRC engineering — and why it is the smallest part of the job
  • The SecOps analogy: what one GRC engineer has to cover when you are not a Fortune 100 with an army of specialists
  • Treating the GRC platform as a programmable surface — TPRM lifecycle, questionnaire and trust-center workflows, access governance, executive reporting
  • Making risk quantification computable instead of narrative-only
  • The vulnerability-management lesson: a flagged critical isn’t a fixed one, and collected evidence isn’t a closed control
  • Engineered workflows, clear ownership and cross-team relationships — where the engineering discipline actually goes

"(Required)" indicates required fields

Name(Required)
Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies