Escaping the Big 4 Audit Trap & Building Open Source GRC | Guest: AJ Dehn

Escaping the Big 4 Audit Trap & Building Open Source GRC | Guest: AJ Dehn

Source: YouTube · GRC Engineering Club · published May 13, 2026 · 40:33

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

AJ Dean discusses his career transition from traditional IT audit to GRC engineering, emphasizing the importance of technical depth and continuous learning in the field 0:36.

Key Takeaways:
• AJ Dean began his career at KPMG performing IT audits, including SOC 2 and financial statement audit IT portions 0:43.
• He highlights the need for GRC professionals to understand underlying technical controls rather than just checking boxes 1:12.
• The discussion covers the evolution of GRC engineering, noting a shift towards more automated and integrated security practices 2:05.
• Dean advises newcomers to focus on building foundational knowledge in both security frameworks and technical implementation 2:45.

GRC engineering requires a blend of regulatory knowledge and technical proficiency to effectively manage risk.

Sources:

  • 0:36 Introduction and background at KPMG
  • 1:12 Importance of technical depth in GRC
  • 2:05 Evolution of GRC practices
  • 2:45 Advice for new GRC professionals

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome friends to another hopefully I feel it will be scintillating time with the GRC engineering podcast joined by I think it's it's it's exciting to see when the GRC engineering's OG AJ says wait a second you got to talk to this AJ. I'm stoked to get into it and with somebody who has much time in the game. So please AJ without further ado let the people know who you are and how you got here. >> Yeah, no thanks so much for having me. Um yes, I'm AJ Dean not to be confused with AJ Yawn but I'm based out of Minneapolis, Minnesota and I started my career excuse me out of college at KPMG was doing a lot of IT audits, SOC 2s, and then the like IT audit portion of financial statement audits. Really enjoyed my time there was there for about four years but I knew I didn't want to be an external …