The Paramify Podcast
The Paramify Podcast is a practical, occasionally chaotic show about GRC, risk management, and staying audit-ready without losing your mind. It’s part talking security strategy, and part group therapy.
We talk with cybersecurity and GRC leaders, including CISOs, auditors, founders, and security engineers, about FedRAMP and FedRAMP 20x, SOC 2, CMMC, NIST RMF, the shift toward continuous evidence, and everything in between.
Learn about what we do at Paramify here: www.paramify.com
Episodes

Jul 27, 2026
Jul 27, 2026
1 hr 12 min
CMMC just hit pause again, and this time it might actually lead somewhere better. In this episode, Kenny and Isaac sit down with AJ Yawn, founder of the GRC Engineering Club, bestselling author of GRC Engineering for AWS, and GRC Engineering leader at Rippling, for a deep dive into CMMC's Phase 2 suspension, why FedRAMP 20x is a preview of where all compliance is headed, and what "GRC engineering" actually means in practice.
We cover AJ's path from Army captain to GRC (by way of Coalfire and PwC), why screenshot-based compliance is dead on arrival, the "painkiller, not vitamin" mindset that separates real value from busywork, and why treating your GRC program like a product instead of a once-a-year fire drill is the only way forward. We also get into risk-first thinking, the Kubernetes admission controller example that never showed up in an audit, and why this might be the best time in a decade to build a career in GRC.
Isaac Teuscher (Paramify's FDE Lead) joins for the science edition to get into the technical weeds.
Links:AJ Yawn on LinkedIn: https://www.linkedin.com/in/ajyawn/GRC Engineering Club: https://www.grcengclub.comRippling: https://www.rippling.comParamify: https://www.paramify.comKenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott/Isaac Teuscher on LinkedIn: https://www.linkedin.com/in/isaacteuscher/
Chapters: 0:00 CMMC disruption is an opportunity1:34 Welcome + intro to AJ Yawn2:20 AJ's background: Army to GRC3:08 Getting into Coalfire in the early days5:06 The moment AJ knew there had to be a better way6:41 How the GRC space has shifted over 10 years8:33 Why curiosity matters more than obligation9:39 AJ's book and the GRC Engineering Club origin10:24 Do old GRC skills still matter?10:52 The horses-to-cars analogy11:42 Why AJ wrote the book12:31 How the GRC Engineering Club grew to 1,000+ members13:24 "Make the bet" on technical skills14:03 AJ's early PWC story15:47 Painkillers vs. vitamins16:35 The career flip: GRC goes programmatic17:58 Being a painkiller, not a vitamin19:06 Launching the Certified GRC Engineer Auditor cert19:44 Both sides of the table have to benefit20:00 CMMC's assessor shortage problem21:13 FedRAMP 20x and the C3PAO readiness gap21:34 Going back to first principles: risk and data23:19 The "dark arts" of CMMC documentation24:39 Pete's "ship it out to sea" SSP analogy26:34 The CMMC/20x meme and the 60-day disruption28:33 Why now is the time for GRC people to step up30:38 "Make compliance suck less"31:00 How compliance burden limits federal innovation32:39 Disruption is good: conflict produces progress33:19 The status page analogy for FedRAMP 20x35:07 GRC engineering = software engineering principles36:56 Why GRC salaries are rising37:44 SOC 2 vs. FedRAMP: where's the real value-add?39:03 Cutting the garbage, keeping deterministic telemetry39:44 GRC touches everything in the business41:39 The risk register as a living, breathing thing42:11 Why "R" is the most important letter in GRC43:00 The nirvana state: proactive risk signals44:39 GRC as a business enabler45:04 The Kubernetes admission controller example47:21 Start small: building a risk-aware culture48:37 FedRAMP 20x lets you tell your security story49:23 Life in the old screenshot-based world50:23 Assume breach: the new security mindset51:53 Chaos engineering for risk management53:35 Operational failure = design failure54:08 The problem with shared responsibility (CECs)55:04 Breaches from misconfigurations and third-party access55:38 AI makes everything connected and automatable57:38 The best time to be in GRC1:00:04 Domain expertise takes time, no shortcuts1:02:38 Hard work is the only secret1:05:31 Now's the time to level up your career1:06:01 What AJ's software engineer brothers are saying about AI1:07:31 Orchestration layers: where GRC is headed1:09:47 Where to find the GRC Engineering Club1:11:39 Wrap up

Jul 20, 2026
Jul 20, 2026
50 min
"If the community wins, America's going to win. If America wins, the world is going to win."
That's Tyler Sweatt's mindset as CEO of Second Front.
Tyler's a West Point grad and Army vet who's spent his career at the intersection of defense and tech. He's been with Second Front for six years, and in that time its Game Warden platform has powered around a hundred ISVs, from legacy primes to brand-new startups, getting mission-critical software authorized and deployed to government networks in a fraction of the usual time. Tyler joined Kenny and Mike on the Paramify Podcast to talk about it.
Key moments from the podcast:
→ Why old FedRAMP® is dead, and why that's a good thing
→ Why entrepreneurial naivety is actually an asset in defense tech
→ Why Second Front bets on self-hosted models over frontier labs for mission-critical software
→ Why more competitors in this space makes everyone better
→ His take on building a company right now, when the frontier labs get all the attention
Learn more:Tyler Sweatt (Second Front CEO): https://www.linkedin.com/in/tylersweatt/Kenny Scott (Paramify Founder & CEO): https://www.linkedin.com/in/kenny-g-scott/Mike Schreiner (Paramify): https://www.linkedin.com/in/mikecschreiner/Second Front Systems: https://www.secondfront.comParamify: https://www.paramify.com
Chapters:0:00 Teaser: the best time in history to build a company1:20 Welcome Tyler Sweatt from Second Front2:04 What Second Front does and how Tyler got there3:45 Lessons (and dark humor) from his military service4:34 Why America struggles to think in long-term horizons6:33 TikTok, algorithms, and a generational divide7:09 The broken incentives behind national security spending8:19 Why program managers aren't rewarded for efficiency10:11 Congress, sound bites, and who ends up in office11:17 The rise of digital natives in national security12:00 Regulatory capture vs. building an open ecosystem13:54 Giving credit to the FedRAMP office15:00 The friction of selling into the Department of War16:05 AO stovepipes and the reciprocity problem18:00 Private capital turning defense tech into a real industry18:35 The "defense tech cohort" and cutting your teeth at Palantir19:07 Why having real competitors makes Second Front better20:05 Entrepreneurial naivety as an asset21:01 Why old FedRAMP is dead23:06 Continuous ATO politics in the Department of War24:43 CMMC, and why it's overdue for an overhaul25:01 The Department's inflection point with private industry28:16 AI access, geopolitics, and a wild few months30:17 AI as a tailwind (or headwind) for mission software32:17 The risk of hard-coding dependency on one frontier model33:35 Why Second Front bet on Cohere over the big labs35:38 What's the same and different from his Calypso AI days39:01 AI hype vs. reality, and managing expectations41:05 Why competition forces incumbents to get better43:25 Paramify's early days and building trust the hard way44:41 Living through industry-wide change45:18 Building a company when frontier labs get all the attention46:21 Why this is the best time in history to build47:17 Why resisting change is a losing bet49:27 How to learn more about Second Front

Jun 29, 2026
Jun 29, 2026
38 min
Justin Scott didn't set out to build a security program. But after Vasion's customers started asking hard questions about cloud security, he ended up leading the company through ISO 27001, SOC 2, FedRAMP Moderate, and all the way to FedRAMP High, with IL6 on the horizon. He breaks down what actually worked, what didn't, and why automation is non-negotiable.
Learn more about Vasion at https://vasion.comLearn more about Justin Scott: https://www.linkedin.com/in/jusscott/
Learn more about Paramify at https://www.paramify.comLearn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/Learn more about Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/
Chapters:0:00 Intro1:06 Meet Justin Scott and Vasion2:24 How Justin Got Into Security4:29 Going from On-Prem to SaaS7:24 Owning the Full Security Program at Vasion10:26 Starting with ISO 27001 Before FedRAMP13:00 The Challenge of Finding a Sponsor16:20 Choosing Stack Armor as a Partner19:06 Why a Technical Program Manager is Non-Negotiable19:44 Printer Security and Why It's a Blind Spot23:00 How Vasion's Capabilities Map to Compliance Frameworks25:00 AI, ISO 42001, and What Vasion Is Building27:36 The Role of Simplicity in Building a Security Program29:31 Why Automation Is the Only Way to Keep Up31:39 FedRAMP 20X: Takes and Tradeoffs36:51 FedRAMP High as a Growth Lever38:27 Justin's Advice for Anyone Starting a FedRAMP Journey39:52 Outro

Jun 26, 2026
Jun 26, 2026
47 min
Monthly vulnerability scans and POA&M spreadsheets aren't going to cut it anymore. Kenny and Isaac break down FedRAMP NTC-0014 and CISA BOD 26-04, the two mandates reshaping how cloud service providers approach vulnerability management, and what CSPs need to do before the December 7, 2026 deadline hits.
They cover why AI has fundamentally changed the threat landscape, how tools like Wiz are helping teams understand attack paths instead of just CVE lists, and what the FedRAMP VDR/VER standard actually requires in practice. Plus, why showing red in your trust center might be the best thing you can do for agency confidence.If you're a CSP still running manual scans and hoping for the best, this one's for you.
Resources mentioned:
- FedRAMP NTC-0014 (VDR/VER Mandate): https://www.fedramp.gov/notices/0014/- FedRAMP VDR Technical Docs: https://www.fedramp.gov/docs/20x/vulnerability-detection-and-response/- CISA BOD 26-04 Implementation Guidance: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog- CISA SSVC Decision Tree Methodology: https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc- FedRAMP NTC-0013 (Rev 5 Sunset): https://www.fedramp.gov/notices/0013/- FedRAMP Marketplace: https://marketplace.fedramp.gov/
Learn more about Paramify: https://www.paramify.com/
Chapters:0:00 - Transparency in Trust Centers: Why Agencies Want to See Red0:13 - Episode Intro & FedRAMP NTC-0014 Explained3:24 - CISA BOD 26-04 and the December 7, 2026 Deadline5:46 - Why the Old FedRAMP Approach Is Broken9:01 - How AI Changed the Vulnerability Landscape11:35 - DARPA's AI Cyber Challenge at DEF CON13:12 - Risk-Based Vulnerability Prioritization: The FedRAMP VDR Response15:15 - Smart Architecture as a Security Foundation20:14 - The FedRAMP VDR Standard: Scanning Requirements21:27 - SSVC Decision Tree: Triage Methodology22:14 - What "Internet Reachable" Actually Means24:07 - Likely Exploitable: The CISA KEV List26:58 - Agency Impact and the Pain Scale28:25 - Pain Level Timelines by FedRAMP Class31:00 - Ditching the POA&M Spreadsheet Mindset32:10 - What to Stop Doing in the Old Model34:17 - Boundary Diagrams vs. Terraform Truth36:24 - Why Transparency Wins with Agency Customers41:08 - Trust Centers Done Right: The OpenAI Status Page Example43:06 - What Large Orgs Getting Ahead Are Doing45:06 - Incident Response and Vulnerability Management: Blurring Lines46:55 - Outro

May 26, 2026
May 26, 2026
42 min
"For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman
Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂
In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC.
Chapters:00:00 The State of CMMC in 202601:00 Intro and Meet Matt Bruggeman02:52 Matt's Unconventional Path to GRC06:11 About A-LIGN and the Ascend Platform08:14 CMMC Today: What's Working and What Needs to Change09:19 Phase 1 vs Phase 2 and the November 10th Deadline11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan?15:46 FedRAMP 20X: Hype vs Reality19:01 Why FedRAMP Was Broken from the Start23:28 How to Think About Rev 5 vs 20X for Your Business27:52 FedRAMP Equivalency Explained31:36 The Technical Reality of a CMMC Assessment35:27 Compliance Doesn't Have to Be Boring37:30 How to Get Into the GRC Space40:19 Where to Find Matt and A-LIGN
Connect with our guest:
Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/
A-LIGN: https://www.a-lign.comA-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/
Paramify:Website: https://www.paramify.comLinkedIn: https://www.linkedin.com/company/80788473/
Hosts:Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/

May 18, 2026
May 18, 2026
55 min
Is legacy compliance actually dead?
In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence.
We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation?
Connect with BladeStack:LinkedIn: bladestack.ioBhanu Jagasia: linkedin.com/in/bhanujagasiaVincent Tham: linkedin.com/in/vincentthamWebsite: bladestack.io
Connect with Paramify:LinkedIn: linkedin.com/company/paramifyKenny Scott: linkedin.com/in/kenny-g-scottMike Schreiner: linkedin.com/in/mikecschreinerWebsite: paramify.com
0:00 Intro & Evidence Automation1:27 Welcome to the Paramify Podcast3:00 How Bladestack Got Started6:29 Evidence Automation & the "Dark Matter" of Data12:31 Why Expertise Still Matters in FedRAMP14:37 Bladestack's Tech-First Approach to Compliance18:40 AI Hype vs Reality in FedRAMP22:52 Understanding What LLMs Actually Are26:34 The Problem with Legacy SSPs28:06 Why FedRAMP 20X Changes Everything36:40 The Legacy FedRAMP Process Was Broken40:32 How Bladestack Leverages AI Internally43:19 Branding in an AI-Commoditized World46:31 AI's Impact on the Threat Landscape49:53 The Future of Compliance54:00 Where to Find Bladestack

May 12, 2026
May 12, 2026
1 hr 6 min
"Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy
Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop.
He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was.
His job interview at TRM Labs? They made him build an AI agent.
And yes, this is the first Paramify Podcast Isaac is on.
We got into:
→ Why now is the best time to learn something new
→ Why 85% of a good GRC agent is deterministic code, not AI
→ How to actually build agents (dog food your own stuff, stop one-shotting)
→ Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x
→ Why domain expertise is what separates good AI output from great AI output
FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf
Learn more about Ethan Troy:https://www.linkedin.com/in/ethantroy/?skipRedirect=true
Learn more about TRM Labs: https://www.trmlabs.com/
Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Isaac Teuscher: https://www.linkedin.com/in/isaacteuscher/
Learn more about Paramify:https://www.paramify.com/
Chapters:
00:58 - Introductions & GRC Engineering
02:12 - From Nursing to Cybersecurity
05:18 - The Problem with Legacy GRC Tools
12:13 - FedRAMP 2.0: The End of SSPs?
16:48 - The FedRAMP Marketplace Metaphor
24:38 - Outcome-Based vs. Hourly Consulting
31:51 - Automating Evidence Collection
37:16 - AI & Real-Time Incident Response
45:10 - Secure Configuration Guides
52:43 - Building an AI-First Culture
58:51 - Principles for AI Agents in GRC
01:05:03 - The 85/15 Rule for AI Logic

Mar 2, 2026
Mar 2, 2026
55 min
In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption.
Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down.
They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper.
Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai.
Links:Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoffKenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scottDTEX.ai: https://www.dtex.ai/Paramify: https://www.paramify.com/
In this episode, you’ll hear:- Why usable security is better security- How secure AI can help small teams move faster- Why trust centers are becoming more important- How accessibility gaps can create real security risk- Why servant leadership matters in cybersecurity- Why FedRAMP 20x is shifting the focus back to risk
Chapters:0:00 Secure AI, lean teams, and why the right tools matter1:12 Intro to Justin Merhoff2:08 How Justin got started in cybersecurity8:31 Army stories, leadership, and early security lessons16:06 Moving from the military into corporate security19:17 Why security should enable the business20:45 The future of trust centers25:20 Secure AI, small teams, and reducing compliance burnout29:32 Why FedRAMP 20x is a needed change36:31 Cyber leadership, adaptability, and how people break into security44:13 Why accessibility is a cybersecurity issue51:18 What Justin was doing at the time and how Rhymetec helps clients54:35 Outro
This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.

Feb 17, 2026
Feb 17, 2026
28 min
Today's episode is An Apropos of Nothing.
This episode is optional, you can skip it if you want, but it's a pretty honest glimpse into what hanging out with us is actually like.

Feb 2, 2026
Feb 2, 2026
54 min
“There’s a 5% chance of a $5 million loss. Is it exactly right? No. But it’s way better than saying medium, because medium means nothing.”
Kenny sits down with Rob Black, Founder and CEO of Fractional CISO, to break down how to translate cyber risk into language executives actually act on: probability, dollars, tradeoffs, and clear acceptance instead of vague labels that disappear into a slide deck.
We also get into the “magic genie” myth of GRC tools, what vCISO looked like back in 2017, and the origin story behind Rob’s legendary wig videos.
Key takeaways:• How to quantify risk without pretending it’s perfectly precise• Why “high/medium/low” breaks the conversation with leadership• Where humans are still required (even with great tools)
Learn more about Rob Black here: https://www.linkedin.com/in/blackrob/
Learn more about FractionalCISO:https://fractionalciso.com/
Learn more about Kenny:https://www.linkedin.com/in/kenny-g-scott/
Learn more about Paramify:https://www.paramify.com/







