Skip to main content
James Tabron

James Tabron

CISSP-certified Director of GRC Engineering at Aquia, specializing in SOC 2 compliance automation and AI agents for GRC; formerly led software engineering at Twilio.

Aug 18, 2026

5:54
What happened there? Explain to us the transition.
5:57
Yeah, so during my time at SendGrid, the way I ran the SOC 2 program was simple.
6:08
very, um, soft skill heavy, right? Uh, people are the, um, understanding how to work with people, um, is really the engine, especially in a traditional GRC, um, model or environment, having the knowledge of the frameworks and risk management and cybersecurity principles is great, but none of that matters if you can't work effectively with people, build partnerships, build bridges, have a pragmatic approach that actually enables the business to make money and allows developers to move faster and the business to move faster and accelerate their revenue generation opportunities.
6:52
So, I ran the program in a very mature fashion.
6:58
And in doing so, I built really strong relationships with engineering leaders.
7:04
And so, and kind of built a reputation as someone who, from a security standpoint, was very pragmatic, easy to deal with, opened the, removed the black box of security, made it more visible, built partnerships with different people.
7:21
different business functions across the organization.

7 MINS LATER

14:43
But what did he mean by GRC perspective in DevSecOps? What did he mean by that?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.