In this episode of **Security & GRC Decoded**, Raj Krishnamurthy sits down with James Tabron, Director of GRC Engineering at **Aquia**, for a conversation almost nobody in this space is qualified to have: what GRC looks like from *inside* an engineering org.
James spent two decades in IT before building GRC programs at SendGrid, Twilio, and Snapdocs — and then did something almost no GRC practitioner ever does. He crossed the aisle. A VP of engineering hired him into the engineering organization to build DevSecOps, and within a couple of years James was a Director of Software Engineering running five teams, 33 people, and the operations behind roughly 9 figures in revenue. Today he runs GRC engineering at Aquia, building continuous authority to operate (cATO) programs in the federal space.
That combination gives him an unusually blunt read on why GRC keeps producing theater. His answer isn't that practitioners are lazy — it's that the incentives are working exactly as designed. Companies are rewarded for getting a SOC 2 as fast and cheaply as possible, and the market has quietly demonstrated that breaches rarely cost you customers. Compare that to federal, where an authority to operate means a third-party assessor, an authorizing official, a 500-page system security plan, and anywhere from 150 to 700+ NIST 800-53 controls, and the picture of which environment produces more real security gets uncomfortable fast.
The conversation also covers continuous controls monitoring in a cATO model, why GRC teams have never touched DORA metrics, what agentic AI actually automates in an audit cycle, why James thinks incumbent GRC tools have three to five years to justify their price tag, and the skill he believes every aspiring GRC engineer is currently sleeping on: data engineering.
**Key Takeaways**:
- GRC theater is an incentive problem, not a competence problem — the SaaS market rewards the fastest, cheapest attestation, and breaches rarely produce churn.
- Federal ATO environments produce less theater because accountability is enforced before a system ever reaches production, not after an incident.
- In a continuous ATO model, every control family should have an evidence pipeline — not just the handful of controls that are easy to monitor.
- Agentic workflows are a natural fit for audit prep, and offloading that tactical work is what finally makes experienced GRC professionals strategically valuable.
- The next differentiating skill for GRC engineers is data engineering — specifically the "T" in ETL.
**What You'll Learn**:
- Why a product VP with no security mandate chose to hire a GRC leader into engineering
- How to translate compliance requirements into the tools and rituals engineers already use
- What continuous monitoring actually requires versus what most programs settle for
- Why traditional GRC has never measured DORA metrics — and whether it should
- Where the build-vs-buy line really sits for GRC tooling, and who gets to cross it
- Why technical acumen should come before framework knowledge in a GRC career
This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.
**Learn more**: https://www.compliancecow.com
**Watch more episodes**: https://www.compliancecow.com/podcast
**Connect With Our Guest**: James Tabron | Director, GRC Engineering | Aquia
**LinkedIn**: https://www.linkedin.com/in/jamestabron/
James is also VP of the GRC Engineering Club — a community for practitioners building in this space.
**Rate, review, and share** if you enjoyed the show!
**Subscribe** to Security & GRC Decoded wherever you get your podcasts:
**Spotify**: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr
**Apple Podcasts**: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450