
James Tabron
CISSP-certified Director of GRC Engineering at Aquia, specializing in SOC 2 compliance automation and AI agents for GRC; formerly led software engineering at Twilio.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
Aug 18, 2026
Security Theater Isn't a Skills Problem. It's an Incentive Problem. ft James Tabron, Director of GRC Engineering @ Aquia
5:57
6:08
7:04

James TabronGUEST
Yeah, so during my time at SendGrid, the way I ran the SOC 2 program was simple.

James TabronGUEST
very, um, soft skill heavy, right? Uh, people are the, um, understanding how to work with people, um, is really the engine, especially in a traditional GRC, um, model or environment, having the knowledge of the frameworks and risk management and cybersecurity principles is great, but none of that matters if you can't work effectively with people, build partnerships, build bridges, have a pragmatic approach that actually enables the business to make money and allows developers to move faster and the business to move faster and accelerate their revenue generation opportunities.

James TabronGUEST
And so, and kind of built a reputation as someone who, from a security standpoint, was very pragmatic, easy to deal with, opened the, removed the black box of security, made it more visible, built partnerships with different people.
7 MINS LATER
14:43
But what did he mean by GRC perspective in DevSecOps? What did he mean by that?
