Escaping the RMF Trap, Validating AI Vendors, & The Curiosity Hack | Guest: Lee

Escaping the RMF Trap, Validating AI Vendors, & The Curiosity Hack | Guest: Lee

Source: YouTube · GRC Engineering Club · published Jul 14, 2026 · 48:12

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This interview with Lee Heheart explores the critical need for technical depth in Governance, Risk, and Compliance (GRC) to bridge the gap between bureaucratic checkboxes and actual security operations, while also addressing the realistic limitations of AI in cybersecurity. 0:47

Key Takeaways:
• GRC professionals must move beyond "checkbox compliance" to understand the engineering intent behind controls 1:05
• Leadership gaps widen when non-technical directors prioritize financial metrics over technical realities 7:43
• Technical staff should develop business acumen to effectively challenge poor vendor claims 37:14
• AI cannot replace the creativity and contextual understanding of human offensive security testers 25:50
• Those entering GRC should learn Linux and understand practical framework implementation 15:30

Lee emphasizes that staying relevant requires continuous curiosity and willingness to challenge the status quo. He advises professionals to leverage communities and ask difficult questions to build confidence and drive meaningful security improvements.

Sources:

  • 0:47 Introduction to technical GRC
  • 1:05 Checkbox compliance critique
  • 7:43 Non-technical leadership gaps
  • 15:30 Linux skills for GRC
  • 25:50 AI limitations in security
  • 37:14 Business acumen for tech staff

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome friends to another what I feel is going to be scintillating discussion here on the anti-checkbox podcast. I'm joined as always by the ineimitable Amanda Heheart. Amanda, >> appreciate it. Yeah, Lee, happy to uh to dive in today and learn more about you and your experiences. >> Let us know. Lee, let us know who you are, what brought you here, and then let's dive in. >> Yeah. So my background spans a lot of different areas from military I did some air force things military got out did some things for financial institutions and DoD contracting of course so that's where I'm currently at. So, I find an interest in GRC because of the uh well, it's not really a new wave. I I would say, but more so the push to get more people into the ideal of being more technical and hands-on with the GRC…