
Escaping the Big 4 Audit Trap & Building Open Source GRC | Guest: AJ Dehn
Source: YouTube · GRC Engineering Club · published May 13, 2026 · 40:33
AJ Dean discusses his career transition from traditional IT audit to GRC engineering, emphasizing the importance of technical depth and continuous learning in the field 0:36.
Key Takeaways:
• AJ Dean began his career at KPMG performing IT audits, including SOC 2 and financial statement audit IT portions 0:43.
• He highlights the need for GRC professionals to understand underlying technical controls rather than just checking boxes 1:12.
• The discussion covers the evolution of GRC engineering, noting a shift towards more automated and integrated security practices 2:05.
• Dean advises newcomers to focus on building foundational knowledge in both security frameworks and technical implementation 2:45.
GRC engineering requires a blend of regulatory knowledge and technical proficiency to effectively manage risk.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Welcome friends to another hopefully I feel it will be scintillating time with the GRC engineering podcast joined by I think it's it's it's exciting to see when the GRC engineering's OG AJ says wait a second you got to talk to this AJ. I'm stoked to get into it and with somebody who has much time in the game. So please AJ without further ado let the people know who you are and how you got here. >> Yeah, no thanks so much for having me. Um yes, I'm AJ Dean not to be confused with AJ Yawn but I'm based out of Minneapolis, Minnesota and I started my career excuse me out of college at KPMG was doing a lot of IT audits, SOC 2s, and then the like IT audit portion of financial statement audits. Really enjoyed my time there was there for about four years but I knew I didn't want to be an external …