CMMC just hit pause again, and this time it might actually lead somewhere better. In this episode, Kenny and Isaac sit down with AJ Yawn, founder of the GRC Engineering Club, bestselling author of GRC Engineering for AWS, and GRC Engineering leader at Rippling, for a deep dive into CMMC's Phase 2 suspension, why FedRAMP 20x is a preview of where all compliance is headed, and what "GRC engineering" actually means in practice.
We cover AJ's path from Army captain to GRC (by way of Coalfire and PwC), why screenshot-based compliance is dead on arrival, the "painkiller, not vitamin" mindset that separates real value from busywork, and why treating your GRC program like a product instead of a once-a-year fire drill is the only way forward. We also get into risk-first thinking, the Kubernetes admission controller example that never showed up in an audit, and why this might be the best time in a decade to build a career in GRC.
Isaac Teuscher (Paramify's FDE Lead) joins for the science edition to get into the technical weeds.
AJ Yawn on LinkedIn: https://www.linkedin.com/in/ajyawn/
GRC Engineering Club: https://www.grcengclub.com
Rippling: https://www.rippling.com
Paramify: https://www.paramify.com
Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott/
Isaac Teuscher on LinkedIn: https://www.linkedin.com/in/isaacteuscher/
0:00 CMMC disruption is an opportunity
1:34 Welcome + intro to AJ Yawn
2:20 AJ's background: Army to GRC
3:08 Getting into Coalfire in the early days
5:06 The moment AJ knew there had to be a better way
6:41 How the GRC space has shifted over 10 years
8:33 Why curiosity matters more than obligation
9:39 AJ's book and the GRC Engineering Club origin
10:24 Do old GRC skills still matter?
10:52 The horses-to-cars analogy
11:42 Why AJ wrote the book
12:31 How the GRC Engineering Club grew to 1,000+ members
13:24 "Make the bet" on technical skills
14:03 AJ's early PWC story
15:47 Painkillers vs. vitamins
16:35 The career flip: GRC goes programmatic
17:58 Being a painkiller, not a vitamin
19:06 Launching the Certified GRC Engineer Auditor cert
19:44 Both sides of the table have to benefit
20:00 CMMC's assessor shortage problem
21:13 FedRAMP 20x and the C3PAO readiness gap
21:34 Going back to first principles: risk and data
23:19 The "dark arts" of CMMC documentation
24:39 Pete's "ship it out to sea" SSP analogy
26:34 The CMMC/20x meme and the 60-day disruption
28:33 Why now is the time for GRC people to step up
30:38 "Make compliance suck less"
31:00 How compliance burden limits federal innovation
32:39 Disruption is good: conflict produces progress
33:19 The status page analogy for FedRAMP 20x
35:07 GRC engineering = software engineering principles
36:56 Why GRC salaries are rising
37:44 SOC 2 vs. FedRAMP: where's the real value-add?
39:03 Cutting the garbage, keeping deterministic telemetry
39:44 GRC touches everything in the business
41:39 The risk register as a living, breathing thing
42:11 Why "R" is the most important letter in GRC
43:00 The nirvana state: proactive risk signals
44:39 GRC as a business enabler
45:04 The Kubernetes admission controller example
47:21 Start small: building a risk-aware culture
48:37 FedRAMP 20x lets you tell your security story
49:23 Life in the old screenshot-based world
50:23 Assume breach: the new security mindset
51:53 Chaos engineering for risk management
53:35 Operational failure = design failure
54:08 The problem with shared responsibility (CECs)
55:04 Breaches from misconfigurations and third-party access
55:38 AI makes everything connected and automatable
57:38 The best time to be in GRC
1:00:04 Domain expertise takes time, no shortcuts
1:02:38 Hard work is the only secret
1:05:31 Now's the time to level up your career
1:06:01 What AJ's software engineer brothers are saying about AI
1:07:31 Orchestration layers: where GRC is headed
1:09:47 Where to find the GRC Engineering Club