The Paramify Podcast

The Paramify Podcast

The Paramify Podcast is a practical, occasionally chaotic show about GRC, risk management, and staying audit-ready without losing your mind. It’s part talking security strategy, and part group therapy. We talk with cybersecurity and GRC leaders, including CISOs, auditors, founders, and security engineers, about FedRAMP and FedRAMP 20x, SOC 2, CMMC, NIST RMF, the shift toward continuous evidence, and everything in between. Learn about what we do at Paramify here: www.paramify.com

Episodes

July 27, 2026 72 mins

CMMC just hit pause again, and this time it might actually lead somewhere better. In this episode, Kenny and Isaac sit down with AJ Yawn, founder of the GRC Engineering Club, bestselling author of GRC Engineering for AWS, and GRC Engineering leader at Rippling, for a deep dive into CMMC's Phase 2 suspension, why FedRAMP 20x is a preview of where all compliance is headed, and what "GRC engineering" actually means in practice.

We cov...

Listen
Watch
Mark as Played

"If the community wins, America's going to win. If America wins, the world is going to win."

That's Tyler Sweatt's mindset as CEO of Second Front.

Tyler's a West Point grad and Army vet who's spent his career at the intersection of defense and tech. He's been with Second Front for six years, and in that time its Game Warden platform has powered around a hundred ISVs, from legacy primes to brand-new startups, getting mission-critica...

Listen
Watch
Mark as Played

Justin Scott didn't set out to build a security program. But after Vasion's customers started asking hard questions about cloud security, he ended up leading the company through ISO 27001, SOC 2, FedRAMP Moderate, and all the way to FedRAMP High, with IL6 on the horizon. He breaks down what actually worked, what didn't, and why automation is non-negotiable.

Learn more about Vasion at https://vasion.com Learn more about Justin Scott...

Listen
Watch
Mark as Played

Monthly vulnerability scans and POA&M spreadsheets aren't going to cut it anymore. Kenny and Isaac break down FedRAMP NTC-0014 and CISA BOD 26-04, the two mandates reshaping how cloud service providers approach vulnerability management, and what CSPs need to do before the December 7, 2026 deadline hits.

They cover why AI has fundamentally changed the threat landscape, how tools like Wiz are helping teams understand attack paths...

Listen
Watch
Mark as Played

"For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman

Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was...

Listen
Watch
Mark as Played

Is legacy compliance actually dead? 

In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence.

We also dive deep into the AI hype: Will knowledge work...

Listen
Watch
Mark as Played

"Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy

Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop.

He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the...

Listen
Watch
Mark as Played

In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption.

Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersec...

Listen
Watch
Mark as Played
February 17, 2026 28 mins

Today's episode is An Apropos of Nothing.

This episode is optional, you can skip it if you want, but it's a pretty honest glimpse into what hanging out with us is actually like.

Listen
Watch
Mark as Played
February 2, 2026 54 mins

“There’s a 5% chance of a $5 million loss. Is it exactly right? No. But it’s way better than saying medium, because medium means nothing.”

Kenny sits down with Rob Black, Founder and CEO of Fractional CISO, to break down how to translate cyber risk into language executives actually act on: probability, dollars, tradeoffs, and clear acceptance instead of vague labels that disappear into a slide deck.

We also ...

Listen
Watch
Mark as Played
January 20, 2026 47 mins

Federal compliance is having a moment. FedRAMP, FedRAMP 20x, CMMC, the whole alphabet soup is going mainstream, fast.

In this episode of The Paramify Podcast, we sit down with Justin Rende, Founder and CEO of Rhymetec, to talk about what’s actually changing, what’s still painfully hard, and why “compliance automation” only works if you stay obsessed with real risk.

Justin also shares his origin story (tech ➝...

Listen
Watch
Mark as Played
January 5, 2026 85 mins

“There’s this misconception in the marketplace that you need to be a coder to do GRC Engineering. You don’t. I don’t want people to be bogged down in scripting. I want them to be systems thinkers focusing on architecture and orchestration.”

Kenny and Mike sit down with the GOATed pioneer of GRC Engineering, Ayoub Fandi. In case you’ve been living under a rock, Ayoub is the Security Assurance Auto...

Listen
Watch
Mark as Played

Kenny and Mike sit down with Dixon Wright, Head of Delivery at Eden Data, for a grounded and insightful conversation on security, compliance, and building smarter systems.

They cover:

- Dixon’s journey from college football to leading security at Eden Data

- What it takes to actually deliver cybersecurity — not just sell it

- Why Eden Data joined the FedRAMP 20x pilot

- How compliance is evolving across commercial and f...

Listen
Watch
Mark as Played
December 8, 2025 52 mins

"The AI age we're in is going to force startups to compete in the higher upper echelon of risk assurance."

Jack Rumsey Head of GRC at Swimlane explains why startups will no longer have the luxury of maturing later and how the AI era is pushing even early-stage teams into enterprise-grade security.

This episode covers why assurance needs to evolve, how 20X can level the playing field, why automation is changing everything about how ...

Listen
Watch
Mark as Played

Security isn’t sexy. It’s laundry. You know you need to do it, but you’d rather have a tool do it for you.

Kenny Scott and Mike Schreiner from Paramify sit down with George Manuelian from RapidFort to talk about freeing the captives — the engineers buried in spreadsheets, patch tickets, and compliance chaos.

They cover:

Why security always seems at odds with progress

How automation can fix what boredom cre...

Listen
Watch
Mark as Played

FedRAMP as we know it is changing. In this episode, Mike and Kenny sit down with Mike “Waffle” Craig, founder and CEO of Vanaheim Security and longtime cloud and cybersecurity leader, to unpack what FedRAMP 20x means for agencies and vendors across FedCiv and DoD. We get into compliance philosophy, how to define your boundary the right way, why sponsorship strategies matter, and where scalability will make or break 20x.

...

Listen
Watch
Mark as Played

“Once you’re in Hotel FedRAMP, you can’t leave.”

Jason Oksenhendler, Cybersecurity Director of FedRAMP®/GovRAMP at Baker Tilly x Moss Adams, sits down with Kenny and Isaac to talk about FedRAMP’s past, how 20x is shaping the future, and why nobody ever really checks out of Hotel FedRAMP.

👉  Key Takeaways:

• FedRAMP 20x was a “hand grenade” for everyone’s roadmap, and it’s ...

Listen
Watch
Mark as Played

In this episode of the Paramify Podcast, Karen Laughton, EVP of Advisory at Coalfire, joins Kenny Scott (CEO of Paramify) and Mike Schreiner to unpack the future of government cybersecurity and compliance modernization. From the hard realities of FedRAMP 20X to lessons learned from the early days of FSMA and CMMC confusion, this conversation pulls no punches.

Karen shares how she broke into cybersecurity via HR (and a saltine-fuele...

Listen
Watch
Mark as Played

It’s not only about faster authorizations—it’s about unlocking the full potential of modern cloud for government.

FedRAMP 20X is how we get there.

In this exclusive roundtable, Pete Waterman (FedRAMP Director), Karen Laughton (EVP of Advisory, CoalFire), Rob Otten (Sr. Director, Risk & Compliance, Flock Safety), Kenny Scott (Founder & CEO, Paramify), and Mike Schreiner (COO, Paramify) break down:

- The mis...

Listen
Watch
Mark as Played

Today, we’re sitting down with StackArmor’s Martin Rieger — a FedRAMP veteran with over 300 engagements under his belt — for an unfiltered deep dive into the origin, evolution, and future of FedRAMP compliance.

We cover everything from the early days of DIACAP and gold images to today’s world of automation, OSCAL, and AI-powered documentation. Martin shares war stories, explains why so many companies f...

Listen
Watch
Mark as Played

Popular Podcasts

    In this intensely divided moment, one of the few things everyone still seems to agree on is Dolly Parton—but why? That simple question leads to a deeply personal, historical, and musical rethinking of one of America’s great icons. Join us for a 9-episode journey into the Dollyverse. Hosted by Jad Abumrad. Produced and reported by Shima Oliaee. Dolly Parton’s America is a production from OSM Audio and WNYC Studios.

    Stuff You Should Know

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Dateline NBC

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    Betrayal Weekly

    Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.

    The Joe Rogan Experience

    The official podcast of comedian Joe Rogan.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices