
Here's What to Expect
Learn how security, GRC, and engineering leaders reduce risk, free engineers, and close deals faster.
The modern tech stack is exploding in complexity — and so are the challenges of keeping it compliant, secure, and resilient. While CISOs juggle frameworks, engineers are buried in evidence requests, and GRC teams are stuck translating between the two.
For the first time, CISOs and Heads of Engineering will share how they’re breaking the compliance–engineering deadlock and redesigning the stack so GRC, security, and engineering finally operate as one.
In this session, we’ll explore:
- Where the compliance–engineering divide really shows up, and why it’s so hard to close
- How to map today’s stack — from infra to SaaS — against risks, controls, and automation opportunities
- Practical ways to cut manual evidence work and unblock engineering velocity
- New patterns for collaboration between CISOs, GRC leaders, and engineering teams
- What an integrated, automated risk stack looks like in practice
Here's What to Expect
Learn how security, GRC, and engineering leaders reduce risk, free engineers, and close deals faster.
The modern tech stack is exploding in complexity — and so are the challenges of keeping it compliant, secure, and resilient. While CISOs juggle frameworks, engineers are buried in evidence requests, and GRC teams are stuck translating between the two.
For the first time, CISOs and Heads of Engineering will share how they’re breaking the compliance–engineering deadlock and redesigning the stack so GRC, security, and engineering finally operate as one.
In this session, we’ll explore:
- Where the compliance–engineering divide really shows up, and why it’s so hard to close
- How to map today’s stack — from infra to SaaS — against risks, controls, and automation opportunities
- Practical ways to cut manual evidence work and unblock engineering velocity
- New patterns for collaboration between CISOs, GRC leaders, and engineering teams
- What an integrated, automated risk stack looks like in practice
Frequently Asked Questions
Panelists

Nicholas Muy serves as Chief Information Security Officer at Scrut Automation, where he leads enterprise security and compliance strategy. With a strong foundation in cloud security architecture and operational risk, he is also an active investor and advisor to early-stage cybersecurity startups, driving the future of modern GRC.

Alpha Diallo leads security at Plaid and brings more than a decade of experience building and scaling security programs across multiple industries, including Aerospace & Defense, SaaS, and cyber insurance. He has held key positions at Boeing, Smartsheet, and Resilience, where his work focused on product security, cloud security, and risk management. Alpha draws on this broad industry background to drive effective security practices in complex environments.

Siyavash G. Nia is Chief Information Security Officer at ShyftLabs, where he oversees security, privacy, and compliance initiatives to enable trusted and resilient technology. With a career spanning software engineering, cybersecurity, and cloud architecture, he has co-founded InsightHx and held senior roles including CTO and VP of Products. Siyavash also guided the FDA approval of AI-enabled medical technologies and continues to publish research in AI and security.

Avaneesh Vyas is the Engineering Director at Scrut Automation, leading the design of secure, scalable platforms for modern InfoSec compliance. He began his career at RSA and Siemens, gaining deep expertise in networking and cybersecurity that shaped his approach to resilient software design. With experience across network diagnostics and forensics, he now blends technical acumen with a passion for mentoring teams to build secure, cloud-native systems.
Ready to see what security-first GRC really looks like?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.



