From Dashboards to Action: The Rise of Agentic GRC | Mar 19, 2026 | 🚀
Published on

Bridging the dev–security divide

In this episode of Risk Grustlers, Nicholas Muy, CISO at Scrut Automation, sits down with Siyavash G. Nia, CISO at ShyftLabs, to talk about what actually works for smaller teams that care about security but do not have an army of specialists: making vulnerabilities real for developers, using QA as a bridge instead of a shield, using GRC tools for shared visibility, and ignoring the AI noise until the fundamentals of secure code, infra, and data are in place.

Siyavash G. Nia
and
CISO, ShyftLabs
and
00:00 / 00:00

Listen on Your favourite platforms

Description

In this conversation, Nick and Siyavash look at application security from that blended lens of engineer, consultant, and CISO. They talk through how to teach developers what a vulnerability looks like in their own code, why a simple live exploit lands better than a slide deck, and how to avoid turning every security review into a blame game. The goal is fewer findings in every scan because the code is getting better, not because the reports are being ignored.

They also dig into how a GRC platform can do more than help with audits. When findings like public buckets or vulnerable packages are visible to project managers, they start driving fixes themselves instead of waiting for security to escalate.

Highlights from the episode

  • How small teams can cut vulnerability counts by teaching developers with real examples instead of hiring endless security roles.
  • How GRC-driven visibility lets project managers and engineers spot and own risks without waiting for a security escalation
  • Why revisiting core testing of infrastructure, code, and networks matters more than the latest AI scanner hype
“I always believed there is a huge gap where developers do not know security, and security engineers do not know development. The only way to close that gap is training and a better understanding of each other.”

- Siyavash G. Nia, CISO, ShyftLabs

About the Risk Grustlers Podcast

Risk Grustlers is a podcast for people working in security, risk, and governance who want sharper conversations than the usual industry soundbites. Each episode features CISOs, security leaders, and risk practitioners sharing how they think through the real operational challenges behind cybersecurity, compliance, AI governance, and enterprise risk.

Hosted by Aayush Ghosh Choudhury (CEO and Co-founder of Scrut Automation) and Nicholas Muy (CISO at Scrut Automation), this podcast series focuses on practical lessons, hard-earned perspectives, and the nuance that comes only from years spent in the security and compliance space.

Hosted By
Aayush Ghosh Choudhury
Co-Founder & CEO, Scrut Automation
Nicholas Muy
CISO, Scrut Automation
Subscribe to our newsletter
Get monthly updates and curated industry insights
Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Join the Unlimited

Get that doubles sales or startups is send a performance

Book a Demo

Share on

Join our community and be the first to know about updates!

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Related Resources

No items found.
No items found.
No items found.
No items found.
No items found.
No items found.
No items found.
No items found.
No items found.

Experience security-first GRC powered by Scrut Teammates.

Scrut Automation’s AI-powered platform helps you move fast, stay compliant, and build with confidence from day one.

Book a Demo
Book a Demo