
Episode #62
CMMC Phase 2 Suspension, FedRAMP 20x, and the Future of GRC Engineering with AJ Yawn
CMMC just hit pause again, and this time it might actually lead somewhere better. In this episode, Kenny and Isaac sit down with AJ Yawn, founder of the GRC Engineering Club, bestselling author of GRC Engineering for AWS, and GRC Engineering leader at Rippling, for a deep dive into CMMC's Phase 2 suspension, why FedRAMP 20x is a preview of where all compliance is headed, and what "GRC engineering" actually means in practice. We cover AJ's path from Army captain to GRC (by way of Coalfire and PwC), why screenshot-based compliance is dead on arrival, the "painkiller, not vitamin" mindset that separates real value from busywork, and why treating your GRC program like a product instead of a once-a-year fire drill is the only way forward. We also get into risk-first thinking, the Kubernetes admission controller example that never showed up in an audit, and why this might be the best time in a decade to build a career in GRC. Isaac Teuscher (Paramify's FDE Lead) joins for the science edition to get into the technical weeds. Links: AJ Yawn on LinkedIn: https://www.linkedin.com/in/ajyawn/ GRC Engineering Club: https://www.grcengclub.com Rippling: https://www.rippling.com Paramify: https://www.paramify.com Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott/ Isaac Teuscher on LinkedIn: https://www.linkedin.com/in/isaacteuscher/ Chapters: 0:00 CMMC disruption is an opportunity 1:34 Welcome + intro to AJ Yawn 2:20 AJ's background: Army to GRC 3:08 Getting into Coalfire in the early days 5:06 The moment AJ knew there had to be a better way 6:41 How the GRC space has shifted over 10 years 8:33 Why curiosity matters more than obligation 9:39 AJ's book and the GRC Engineering Club origin 10:24 Do old GRC skills still matter? 10:52 The horses-to-cars analogy 11:42 Why AJ wrote the book 12:31 How the GRC Engineering Club grew to 1,000+ members 13:24 "Make the bet" on technical skills 14:03 AJ's early PWC story 15:47 Painkillers vs. vitamins 16:35 The career flip: GRC goes programmatic 17:58 Being a painkiller, not a vitamin 19:06 Launching the Certified GRC Engineer Auditor cert 19:44 Both sides of the table have to benefit 20:00 CMMC's assessor shortage problem 21:13 FedRAMP 20x and the C3PAO readiness gap 21:34 Going back to first principles: risk and data 23:19 The "dark arts" of CMMC documentation 24:39 Pete's "ship it out to sea" SSP analogy 26:34 The CMMC/20x meme and the 60-day disruption 28:33 Why now is the time for GRC people to step up 30:38 "Make compliance suck less" 31:00 How compliance burden limits federal innovation 32:39 Disruption is good: conflict produces progress 33:19 The status page analogy for FedRAMP 20x 35:07 GRC engineering = software engineering principles 36:56 Why GRC salaries are rising 37:44 SOC 2 vs. FedRAMP: where's the real value-add? 39:03 Cutting the garbage, keeping deterministic telemetry 39:44 GRC touches everything in the business 41:39 The risk register as a living, breathing thing 42:11 Why "R" is the most important letter in GRC 43:00 The nirvana state: proactive risk signals 44:39 GRC as a business enabler 45:04 The Kubernetes admission controller example 47:21 Start small: building a risk-aware culture 48:37 FedRAMP 20x lets you tell your security story 49:23 Life in the old screenshot-based world 50:23 Assume breach: the new security mindset 51:53 Chaos engineering for risk management 53:35 Operational failure = design failure 54:08 The problem with shared responsibility (CECs) 55:04 Breaches from misconfigurations and third-party access 55:38 AI makes everything connected and automatable 57:38 The best time to be in GRC 1:00:04 Domain expertise takes time, no shortcuts 1:02:38 Hard work is the only secret 1:05:31 Now's the time to level up your career 1:06:01 What AJ's software engineer brothers are saying about AI 1:07:31 Orchestration layers: where GRC is headed 1:09:47 Where to find the GRC Engineering Club 1:11:39 Wrap up

