<?xml version="1.0" encoding="UTF-8"?><!-- generator="podbean/5.5" -->
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
     xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"
     xmlns:spotify="http://www.spotify.com/ns/rss"
     xmlns:podcast="https://podcastindex.org/namespace/1.0"
    xmlns:media="http://search.yahoo.com/mrss/">

<channel>
    <title>The Paramify Podcast</title>
    <atom:link href="https://feed.podbean.com/Paramify/feed.xml" rel="self" type="application/rss+xml"/>
    <link>https://Paramify.podbean.com</link>
    <description><![CDATA[<p><span>The Paramify Podcast is a practical, occasionally chaotic show about GRC, risk management, and staying audit-ready without losing your mind. It’s part talking security strategy, and part group therapy. </span></p>
<p><span></span></p>
<p><span>We talk with cybersecurity and GRC leaders, including CISOs, auditors, founders, and security engineers, about FedRAMP and FedRAMP 20x, SOC 2, CMMC, NIST RMF, the shift toward continuous evidence, and everything in between. </span></p>
<p><span></span></p>
<p><span>Learn about what we do at P</span><span>aramify here: www.paramify.com</span></p>]]></description>
    <pubDate>Tue, 26 May 2026 11:00:00 -0600</pubDate>
    <generator>https://podbean.com/?v=5.5</generator>
    <language>en</language>
    <spotify:countryOfOrigin>us</spotify:countryOfOrigin>
    <copyright>Copyright 2023 All rights reserved.</copyright>
    <category>Business:Entrepreneurship</category>
    <ttl>1440</ttl>
    <itunes:type>episodic</itunes:type>
          <itunes:summary></itunes:summary>
        <itunes:author>Paramify</itunes:author>
	<itunes:category text="Business">
		<itunes:category text="Entrepreneurship" />
	</itunes:category>
    <itunes:owner>
        <itunes:name>Paramify</itunes:name>
            </itunes:owner>
    	<itunes:block>No</itunes:block>
	<itunes:explicit>false</itunes:explicit>
	<itunes:new-feed-url>https://feed.podbean.com/Paramify/feed.xml</itunes:new-feed-url>
    <itunes:image href="https://pbcdn1.podbean.com/imglogo/image-logo/16727912/Copy_of_Branding_Board_Mood_Board_Template_300_x_300_px_b32pz.png" />
    <image>
        <url>https://pbcdn1.podbean.com/imglogo/image-logo/16727912/Copy_of_Branding_Board_Mood_Board_Template_300_x_300_px_b32pz.png</url>
        <title>The Paramify Podcast</title>
        <link>https://Paramify.podbean.com</link>
        <width>144</width>
        <height>144</height>
    </image>
    <item>
        <title>FedRAMP 20x, CMMC, and the Future of GRC with Matt Bruggeman</title>
        <itunes:title>FedRAMP 20x, CMMC, and the Future of GRC with Matt Bruggeman</itunes:title>
        <link>https://Paramify.podbean.com/e/fedramp-20x-cmmc-and-the-future-of-grc-with-matt-bruggeman/</link>
                    <comments>https://Paramify.podbean.com/e/fedramp-20x-cmmc-and-the-future-of-grc-with-matt-bruggeman/#comments</comments>        <pubDate>Tue, 26 May 2026 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/9b84e31f-1393-3836-98d3-59089f4e9e4f</guid>
                                    <description><![CDATA[<p>"For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman</p>
<p>Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂 </p>
<p>In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC.</p>
<p>Chapters:
00:00 The State of CMMC in 2026
01:00 Intro and Meet Matt Bruggeman
02:52 Matt's Unconventional Path to GRC
06:11 About A-LIGN and the Ascend Platform
08:14 CMMC Today: What's Working and What Needs to Change
09:19 Phase 1 vs Phase 2 and the November 10th Deadline
11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan?
15:46 FedRAMP 20X: Hype vs Reality
19:01 Why FedRAMP Was Broken from the Start
23:28 How to Think About Rev 5 vs 20X for Your Business
27:52 FedRAMP Equivalency Explained
31:36 The Technical Reality of a CMMC Assessment
35:27 Compliance Doesn't Have to Be Boring
37:30 How to Get Into the GRC Space
40:19 Where to Find Matt and A-LIGN</p>
<p>Connect with our guest:</p>
<p>Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/</p>
<p>A-LIGN: https://www.a-lign.com
A-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/</p>
<p>Paramify:
Website: https://www.paramify.com
LinkedIn: https://www.linkedin.com/company/80788473/</p>
<p>Hosts:
Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/
Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>"For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman</p>
<p>Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂 </p>
<p>In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC.</p>
<p>Chapters:<br>
00:00 The State of CMMC in 2026<br>
01:00 Intro and Meet Matt Bruggeman<br>
02:52 Matt's Unconventional Path to GRC<br>
06:11 About A-LIGN and the Ascend Platform<br>
08:14 CMMC Today: What's Working and What Needs to Change<br>
09:19 Phase 1 vs Phase 2 and the November 10th Deadline<br>
11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan?<br>
15:46 FedRAMP 20X: Hype vs Reality<br>
19:01 Why FedRAMP Was Broken from the Start<br>
23:28 How to Think About Rev 5 vs 20X for Your Business<br>
27:52 FedRAMP Equivalency Explained<br>
31:36 The Technical Reality of a CMMC Assessment<br>
35:27 Compliance Doesn't Have to Be Boring<br>
37:30 How to Get Into the GRC Space<br>
40:19 Where to Find Matt and A-LIGN</p>
<p>Connect with our guest:</p>
<p>Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/</p>
<p>A-LIGN: https://www.a-lign.com<br>
A-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/</p>
<p>Paramify:<br>
Website: https://www.paramify.com<br>
LinkedIn: https://www.linkedin.com/company/80788473/</p>
<p>Hosts:<br>
Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/<br>
Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vqpiqnmczrf9n36h/Matt_Bruggeman_Full_Podcast9ydad.mp3" length="40383266" type="audio/mpeg"/>
        <itunes:summary><![CDATA["For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman
Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂 
In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC.
Chapters:00:00 The State of CMMC in 202601:00 Intro and Meet Matt Bruggeman02:52 Matt's Unconventional Path to GRC06:11 About A-LIGN and the Ascend Platform08:14 CMMC Today: What's Working and What Needs to Change09:19 Phase 1 vs Phase 2 and the November 10th Deadline11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan?15:46 FedRAMP 20X: Hype vs Reality19:01 Why FedRAMP Was Broken from the Start23:28 How to Think About Rev 5 vs 20X for Your Business27:52 FedRAMP Equivalency Explained31:36 The Technical Reality of a CMMC Assessment35:27 Compliance Doesn't Have to Be Boring37:30 How to Get Into the GRC Space40:19 Where to Find Matt and A-LIGN
Connect with our guest:
Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/
A-LIGN: https://www.a-lign.comA-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/
Paramify:Website: https://www.paramify.comLinkedIn: https://www.linkedin.com/company/80788473/
Hosts:Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2523</itunes:duration>
                <itunes:episode>58</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>AI, FedRAMP and the "Dark Matter" of Data with Bhanu Jagasia and Vincent Tham</title>
        <itunes:title>AI, FedRAMP and the "Dark Matter" of Data with Bhanu Jagasia and Vincent Tham</itunes:title>
        <link>https://Paramify.podbean.com/e/ai-fedramp-and-the-dark-matter-of-data-with-bhanu-jagasia-and-vincent-tham/</link>
                    <comments>https://Paramify.podbean.com/e/ai-fedramp-and-the-dark-matter-of-data-with-bhanu-jagasia-and-vincent-tham/#comments</comments>        <pubDate>Mon, 18 May 2026 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d497d00a-b785-36aa-a445-96a4efdb366a</guid>
                                    <description><![CDATA[<p>Is legacy compliance actually dead? </p>
<p>In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence.</p>
<p>We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation?</p>
<p>Connect with BladeStack:
LinkedIn: bladestack.io
Bhanu Jagasia: linkedin.com/in/bhanujagasia
Vincent Tham: linkedin.com/in/vincenttham
Website: bladestack.io</p>
<p>
Connect with Paramify:
LinkedIn: linkedin.com/company/paramify
Kenny Scott: linkedin.com/in/kenny-g-scott
Mike Schreiner: linkedin.com/in/mikecschreiner
Website: paramify.com</p>
<p>
0:00 Intro &amp; Evidence Automation
1:27 Welcome to the Paramify Podcast
3:00 How Bladestack Got Started
6:29 Evidence Automation &amp; the "Dark Matter" of Data
12:31 Why Expertise Still Matters in FedRAMP
14:37 Bladestack's Tech-First Approach to Compliance
18:40 AI Hype vs Reality in FedRAMP
22:52 Understanding What LLMs Actually Are
26:34 The Problem with Legacy SSPs
28:06 Why FedRAMP 20X Changes Everything
36:40 The Legacy FedRAMP Process Was Broken
40:32 How Bladestack Leverages AI Internally
43:19 Branding in an AI-Commoditized World
46:31 AI's Impact on the Threat Landscape
49:53 The Future of Compliance
54:00 Where to Find Bladestack</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Is legacy compliance actually dead? </p>
<p>In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence.</p>
<p>We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation?</p>
<p>Connect with BladeStack:<br>
LinkedIn: bladestack.io<br>
Bhanu Jagasia: linkedin.com/in/bhanujagasia<br>
Vincent Tham: linkedin.com/in/vincenttham<br>
Website: bladestack.io</p>
<p><br>
Connect with Paramify:<br>
LinkedIn: linkedin.com/company/paramify<br>
Kenny Scott: linkedin.com/in/kenny-g-scott<br>
Mike Schreiner: linkedin.com/in/mikecschreiner<br>
Website: paramify.com</p>
<p><br>
0:00 Intro &amp; Evidence Automation<br>
1:27 Welcome to the Paramify Podcast<br>
3:00 How Bladestack Got Started<br>
6:29 Evidence Automation &amp; the "Dark Matter" of Data<br>
12:31 Why Expertise Still Matters in FedRAMP<br>
14:37 Bladestack's Tech-First Approach to Compliance<br>
18:40 AI Hype vs Reality in FedRAMP<br>
22:52 Understanding What LLMs Actually Are<br>
26:34 The Problem with Legacy SSPs<br>
28:06 Why FedRAMP 20X Changes Everything<br>
36:40 The Legacy FedRAMP Process Was Broken<br>
40:32 How Bladestack Leverages AI Internally<br>
43:19 Branding in an AI-Commoditized World<br>
46:31 AI's Impact on the Threat Landscape<br>
49:53 The Future of Compliance<br>
54:00 Where to Find Bladestack</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rk5xrtnu5a5ykip6/BladeStack_Podcast_Audio8pkk1.mp3" length="53352121" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Is legacy compliance actually dead? 
In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence.
We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation?
Connect with BladeStack:LinkedIn: bladestack.ioBhanu Jagasia: linkedin.com/in/bhanujagasiaVincent Tham: linkedin.com/in/vincentthamWebsite: bladestack.io
Connect with Paramify:LinkedIn: linkedin.com/company/paramifyKenny Scott: linkedin.com/in/kenny-g-scottMike Schreiner: linkedin.com/in/mikecschreinerWebsite: paramify.com
0:00 Intro &amp; Evidence Automation1:27 Welcome to the Paramify Podcast3:00 How Bladestack Got Started6:29 Evidence Automation &amp; the "Dark Matter" of Data12:31 Why Expertise Still Matters in FedRAMP14:37 Bladestack's Tech-First Approach to Compliance18:40 AI Hype vs Reality in FedRAMP22:52 Understanding What LLMs Actually Are26:34 The Problem with Legacy SSPs28:06 Why FedRAMP 20X Changes Everything36:40 The Legacy FedRAMP Process Was Broken40:32 How Bladestack Leverages AI Internally43:19 Branding in an AI-Commoditized World46:31 AI's Impact on the Threat Landscape49:53 The Future of Compliance54:00 Where to Find Bladestack]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3334</itunes:duration>
                <itunes:episode>57</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>GRC Engineering, FedRAMP 20x, and AI with Ethan Troy</title>
        <itunes:title>GRC Engineering, FedRAMP 20x, and AI with Ethan Troy</itunes:title>
        <link>https://Paramify.podbean.com/e/grc-engineering-fedramp-20x-and-ai-with-ethan-troy/</link>
                    <comments>https://Paramify.podbean.com/e/grc-engineering-fedramp-20x-and-ai-with-ethan-troy/#comments</comments>        <pubDate>Tue, 12 May 2026 10:59:59 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/eb61c7b8-a927-384c-b25b-815bc3ad6835</guid>
                                    <description><![CDATA[<p>"Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy</p>
<p>Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop.</p>
<p>He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was.</p>
<p>His job interview at TRM Labs? They made him build an AI agent.</p>
<p>And yes, this is the first Paramify Podcast Isaac is on.</p>
<p>We got into:</p>
<p>→ Why now is the best time to learn something new </p>
<p>→ Why 85% of a good GRC agent is deterministic code, not AI </p>
<p>→ How to actually build agents (dog food your own stuff, stop one-shotting) </p>
<p>→ Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x </p>
<p>→ Why domain expertise is what separates good AI output from great AI output</p>
<p>
FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf</p>
<p>Learn more about Ethan Troy:
https://www.linkedin.com/in/ethantroy/?skipRedirect=true</p>
<p>Learn more about TRM Labs: 
https://www.trmlabs.com/</p>
<p>Learn more about Kenny Scott: 
https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Isaac Teuscher: 
https://www.linkedin.com/in/isaacteuscher/</p>
<p>Learn more about Paramify:
https://www.paramify.com/</p>
<p>Chapters:</p>
<p>00:58 - Introductions &amp; GRC Engineering</p>
<p>02:12 - From Nursing to Cybersecurity</p>
<p>05:18 - The Problem with Legacy GRC Tools</p>
<p>12:13 - FedRAMP 2.0: The End of SSPs?</p>
<p>16:48 - The FedRAMP Marketplace Metaphor</p>
<p>24:38 - Outcome-Based vs. Hourly Consulting</p>
<p>31:51 - Automating Evidence Collection</p>
<p>37:16 - AI &amp; Real-Time Incident Response</p>
<p>45:10 - Secure Configuration Guides</p>
<p>52:43 - Building an AI-First Culture</p>
<p>58:51 - Principles for AI Agents in GRC</p>
<p>01:05:03 - The 85/15 Rule for AI Logic</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>"Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy</p>
<p>Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop.</p>
<p>He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was.</p>
<p>His job interview at TRM Labs? They made him build an AI agent.</p>
<p>And yes, this is the first Paramify Podcast Isaac is on.</p>
<p>We got into:</p>
<p>→ Why now is the best time to learn something new </p>
<p>→ Why 85% of a good GRC agent is deterministic code, not AI </p>
<p>→ How to actually build agents (dog food your own stuff, stop one-shotting) </p>
<p>→ Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x </p>
<p>→ Why domain expertise is what separates good AI output from great AI output</p>
<p><br>
FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf</p>
<p>Learn more about Ethan Troy:<br>
https://www.linkedin.com/in/ethantroy/?skipRedirect=true</p>
<p>Learn more about TRM Labs: <br>
https://www.trmlabs.com/</p>
<p>Learn more about Kenny Scott: <br>
https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Isaac Teuscher: <br>
https://www.linkedin.com/in/isaacteuscher/</p>
<p>Learn more about Paramify:<br>
https://www.paramify.com/</p>
<p>Chapters:</p>
<p>00:58 - Introductions &amp; GRC Engineering</p>
<p>02:12 - From Nursing to Cybersecurity</p>
<p>05:18 - The Problem with Legacy GRC Tools</p>
<p>12:13 - FedRAMP 2.0: The End of SSPs?</p>
<p>16:48 - The FedRAMP Marketplace Metaphor</p>
<p>24:38 - Outcome-Based vs. Hourly Consulting</p>
<p>31:51 - Automating Evidence Collection</p>
<p>37:16 - AI &amp; Real-Time Incident Response</p>
<p>45:10 - Secure Configuration Guides</p>
<p>52:43 - Building an AI-First Culture</p>
<p>58:51 - Principles for AI Agents in GRC</p>
<p>01:05:03 - The 85/15 Rule for AI Logic</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fbnk489xh3pt5as9/Ethan_Troy_Full_Podcast95262.mp3" length="64079880" type="audio/mpeg"/>
        <itunes:summary><![CDATA["Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy
Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop.
He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was.
His job interview at TRM Labs? They made him build an AI agent.
And yes, this is the first Paramify Podcast Isaac is on.
We got into:
→ Why now is the best time to learn something new 
→ Why 85% of a good GRC agent is deterministic code, not AI 
→ How to actually build agents (dog food your own stuff, stop one-shotting) 
→ Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x 
→ Why domain expertise is what separates good AI output from great AI output
FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf
Learn more about Ethan Troy:https://www.linkedin.com/in/ethantroy/?skipRedirect=true
Learn more about TRM Labs: https://www.trmlabs.com/
Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Isaac Teuscher: https://www.linkedin.com/in/isaacteuscher/
Learn more about Paramify:https://www.paramify.com/
Chapters:
00:58 - Introductions &amp; GRC Engineering
02:12 - From Nursing to Cybersecurity
05:18 - The Problem with Legacy GRC Tools
12:13 - FedRAMP 2.0: The End of SSPs?
16:48 - The FedRAMP Marketplace Metaphor
24:38 - Outcome-Based vs. Hourly Consulting
31:51 - Automating Evidence Collection
37:16 - AI &amp; Real-Time Incident Response
45:10 - Secure Configuration Guides
52:43 - Building an AI-First Culture
58:51 - Principles for AI Agents in GRC
01:05:03 - The 85/15 Rule for AI Logic]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4004</itunes:duration>
                <itunes:episode>56</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity</title>
        <itunes:title>Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity</itunes:title>
        <link>https://Paramify.podbean.com/e/justin-merhoff-on-fedramp-20x-secure-ai-trust-centers-and-modern-cybersecurity/</link>
                    <comments>https://Paramify.podbean.com/e/justin-merhoff-on-fedramp-20x-secure-ai-trust-centers-and-modern-cybersecurity/#comments</comments>        <pubDate>Mon, 02 Mar 2026 14:03:05 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/62b6b4ee-e7e1-32cb-8254-bae251d00ca4</guid>
                                    <description><![CDATA[<p>In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption.</p>
<p>Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down.</p>
<p>They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper.</p>
<p>Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai.</p>
<p>Links:
Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoff
Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott
DTEX.ai: https://www.dtex.ai/
Paramify: https://www.paramify.com/</p>
<p>In this episode, you’ll hear:
- Why usable security is better security
- How secure AI can help small teams move faster
- Why trust centers are becoming more important
- How accessibility gaps can create real security risk
- Why servant leadership matters in cybersecurity
- Why FedRAMP 20x is shifting the focus back to risk</p>
<p>Chapters:
0:00 Secure AI, lean teams, and why the right tools matter
1:12 Intro to Justin Merhoff
2:08 How Justin got started in cybersecurity
8:31 Army stories, leadership, and early security lessons
16:06 Moving from the military into corporate security
19:17 Why security should enable the business
20:45 The future of trust centers
25:20 Secure AI, small teams, and reducing compliance burnout
29:32 Why FedRAMP 20x is a needed change
36:31 Cyber leadership, adaptability, and how people break into security
44:13 Why accessibility is a cybersecurity issue
51:18 What Justin was doing at the time and how Rhymetec helps clients
54:35 Outro</p>
<p>This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption.</p>
<p>Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down.</p>
<p>They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper.</p>
<p>Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai.</p>
<p>Links:<br>
Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoff<br>
Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott<br>
DTEX.ai: https://www.dtex.ai/<br>
Paramify: https://www.paramify.com/</p>
<p>In this episode, you’ll hear:<br>
- Why usable security is better security<br>
- How secure AI can help small teams move faster<br>
- Why trust centers are becoming more important<br>
- How accessibility gaps can create real security risk<br>
- Why servant leadership matters in cybersecurity<br>
- Why FedRAMP 20x is shifting the focus back to risk</p>
<p>Chapters:<br>
0:00 Secure AI, lean teams, and why the right tools matter<br>
1:12 Intro to Justin Merhoff<br>
2:08 How Justin got started in cybersecurity<br>
8:31 Army stories, leadership, and early security lessons<br>
16:06 Moving from the military into corporate security<br>
19:17 Why security should enable the business<br>
20:45 The future of trust centers<br>
25:20 Secure AI, small teams, and reducing compliance burnout<br>
29:32 Why FedRAMP 20x is a needed change<br>
36:31 Cyber leadership, adaptability, and how people break into security<br>
44:13 Why accessibility is a cybersecurity issue<br>
51:18 What Justin was doing at the time and how Rhymetec helps clients<br>
54:35 Outro</p>
<p>This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/agpx6kz8qpj25vb8/Justin_Merhoff_Full_Podcastbousk.mp3" length="53041996" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption.
Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down.
They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper.
Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai.
Links:Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoffKenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scottDTEX.ai: https://www.dtex.ai/Paramify: https://www.paramify.com/
In this episode, you’ll hear:- Why usable security is better security- How secure AI can help small teams move faster- Why trust centers are becoming more important- How accessibility gaps can create real security risk- Why servant leadership matters in cybersecurity- Why FedRAMP 20x is shifting the focus back to risk
Chapters:0:00 Secure AI, lean teams, and why the right tools matter1:12 Intro to Justin Merhoff2:08 How Justin got started in cybersecurity8:31 Army stories, leadership, and early security lessons16:06 Moving from the military into corporate security19:17 Why security should enable the business20:45 The future of trust centers25:20 Secure AI, small teams, and reducing compliance burnout29:32 Why FedRAMP 20x is a needed change36:31 Cyber leadership, adaptability, and how people break into security44:13 Why accessibility is a cybersecurity issue51:18 What Justin was doing at the time and how Rhymetec helps clients54:35 Outro
This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3315</itunes:duration>
                <itunes:episode>55</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>An Apropos of Nothing</title>
        <itunes:title>An Apropos of Nothing</itunes:title>
        <link>https://Paramify.podbean.com/e/an-apropos-of-nothing/</link>
                    <comments>https://Paramify.podbean.com/e/an-apropos-of-nothing/#comments</comments>        <pubDate>Tue, 17 Feb 2026 14:38:21 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/730bc6be-9f7d-3e90-8c6c-1fcf512dab9f</guid>
                                    <description><![CDATA[<p>Today's episode is An Apropos of Nothing.</p>
<p>This episode is optional, you can skip it if you want, but it's a pretty honest glimpse into what hanging out with us is actually like.</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today's episode is An Apropos of Nothing.</p>
<p>This episode is optional, you can skip it if you want, but it's a pretty honest glimpse into what hanging out with us is actually like.</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4cjprdtdy89nbahk/An_Apropos_of_Nothing_Audio9kb9a.mp3" length="27114316" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today's episode is An Apropos of Nothing.
This episode is optional, you can skip it if you want, but it's a pretty honest glimpse into what hanging out with us is actually like.
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1694</itunes:duration>
                <itunes:episode>54</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Making Risk Make Sense with Rob Black</title>
        <itunes:title>Making Risk Make Sense with Rob Black</itunes:title>
        <link>https://Paramify.podbean.com/e/making-risk-make-sense-with-rob-black/</link>
                    <comments>https://Paramify.podbean.com/e/making-risk-make-sense-with-rob-black/#comments</comments>        <pubDate>Mon, 02 Feb 2026 12:48:55 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/89db56b1-0282-38ab-85c0-9ebe787371b4</guid>
                                    <description><![CDATA[<p>“There’s a 5% chance of a $5 million loss. Is it exactly right? No. But it’s way better than saying medium, because medium means nothing.”</p>
<p>Kenny sits down with Rob Black, Founder and CEO of Fractional CISO, to break down how to translate cyber risk into language executives actually act on: probability, dollars, tradeoffs, and clear acceptance instead of vague labels that disappear into a slide deck.</p>
<p>We also get into the “magic genie” myth of GRC tools, what vCISO looked like back in 2017, and the origin story behind Rob’s legendary wig videos.</p>
<p>Key takeaways:
• How to quantify risk without pretending it’s perfectly precise
• Why “high/medium/low” breaks the conversation with leadership
• Where humans are still required (even with great tools)</p>
<p>Learn more about Rob Black here: 
https://www.linkedin.com/in/blackrob/</p>
<p>Learn more about FractionalCISO:
https://fractionalciso.com/</p>
<p>Learn more about Kenny:
https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify:
https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>“There’s a 5% chance of a $5 million loss. Is it exactly right? No. But it’s way better than saying medium, because medium means nothing.”</p>
<p>Kenny sits down with Rob Black, Founder and CEO of Fractional CISO, to break down how to translate cyber risk into language executives actually act on: probability, dollars, tradeoffs, and clear acceptance instead of vague labels that disappear into a slide deck.</p>
<p>We also get into the “magic genie” myth of GRC tools, what vCISO looked like back in 2017, and the origin story behind Rob’s legendary wig videos.</p>
<p>Key takeaways:<br>
• How to quantify risk without pretending it’s perfectly precise<br>
• Why “high/medium/low” breaks the conversation with leadership<br>
• Where humans are still required (even with great tools)</p>
<p>Learn more about Rob Black here: <br>
https://www.linkedin.com/in/blackrob/</p>
<p>Learn more about FractionalCISO:<br>
https://fractionalciso.com/</p>
<p>Learn more about Kenny:<br>
https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify:<br>
https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/24yiubrnfpr3i5me/Rob_Black_Full_Podcast7cdqi.mp3" length="52076092" type="audio/mpeg"/>
        <itunes:summary><![CDATA[“There’s a 5% chance of a $5 million loss. Is it exactly right? No. But it’s way better than saying medium, because medium means nothing.”
Kenny sits down with Rob Black, Founder and CEO of Fractional CISO, to break down how to translate cyber risk into language executives actually act on: probability, dollars, tradeoffs, and clear acceptance instead of vague labels that disappear into a slide deck.
We also get into the “magic genie” myth of GRC tools, what vCISO looked like back in 2017, and the origin story behind Rob’s legendary wig videos.
Key takeaways:• How to quantify risk without pretending it’s perfectly precise• Why “high/medium/low” breaks the conversation with leadership• Where humans are still required (even with great tools)
Learn more about Rob Black here: https://www.linkedin.com/in/blackrob/
Learn more about FractionalCISO:https://fractionalciso.com/
Learn more about Kenny:https://www.linkedin.com/in/kenny-g-scott/
Learn more about Paramify:https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3254</itunes:duration>
                <itunes:episode>53</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>From Film to FedRAMP with Justin Rende</title>
        <itunes:title>From Film to FedRAMP with Justin Rende</itunes:title>
        <link>https://Paramify.podbean.com/e/from-film-to-fedramp-with-justin-rende/</link>
                    <comments>https://Paramify.podbean.com/e/from-film-to-fedramp-with-justin-rende/#comments</comments>        <pubDate>Tue, 20 Jan 2026 14:09:47 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/9f2d735f-d20c-30d8-8794-fd3eff285efe</guid>
                                    <description><![CDATA[<p>Federal compliance is having a moment. FedRAMP, FedRAMP 20x, CMMC, the whole alphabet soup is going mainstream, fast.</p>
<p>In this episode of The Paramify Podcast, we sit down with Justin Rende, Founder and CEO of Rhymetec, to talk about what’s actually changing, what’s still painfully hard, and why “compliance automation” only works if you stay obsessed with real risk.</p>
<p>Justin also shares his origin story (tech ➝ film festivals ➝ tech), how Rhymetec grew from early penetration tests into full vCISO and compliance programs, and the most New York lead gen strategy ever: biking around the city delivering Google Homes and handwritten notes to prospects.</p>
<p>If you’ve ever been promised an “easy button” for SOC 2, ISO, or FedRAMP, this one’s for you.</p>
<p>In this episode:</p>
<p>Why federal compliance is exploding (and why it’s not slowing down)</p>
<p>FedRAMP 20x and the pace of government innovation (yes, really)</p>
<p>The risk of “checkbox compliance” in a world of automation</p>
<p>How to set expectations with customers when security is never just one toggle</p>
<p>Bootstrapping, building recurring revenue, and staying flexible</p>
<p>Customer experience as the real differentiator (care scales better than you think)</p>
<p>Where to find Justin and Rhymetec:
https://rhymetec.com
  / justin-rende  </p>
<p>Learn more about Paramify: 
Paramify website: https://www.paramify.com/
Mike Schreiner (LinkedIn):   / mikecschreiner  
Kenny Scott (LinkedIn):   / kenny-g-scott  </p>
<p>Chapters</p>
<p>0:00 Federal compliance is exploding (and getting mainstream)
0:30 Welcome to The Paramify Podcast + Justin Rende intro
1:34 Justin’s origin story: tech ➝ film ➝ tech
2:53 Starting Rhymetec with pentesting (and betting on SaaS early)
4:25 Tribeca and Doha: running VIP experiences and meeting “heroes”
5:33 The real lesson from film: make the customer have a good time
7:01 Mess-ups happen, recovery is the job
8:15 “Don’t meet your heroes” (Rudy story)
9:24 Leaving film, chasing stability, spotting outdated consulting
10:43 Bootstrapping vs taking investment and why flexibility wins
13:53 From big pentest checks to recurring revenue and vCISO programs
15:24 Employee experience: quality of life, culture, and remote done right
18:10 SOC 2 and ISO automation: the pros, the cons, and the risk gap
20:25 The “easy button” myth (MFA is never just one button)
21:38 Sales overpromising, complexity, and doing right by the customer
25:36 Biking NYC: Google Homes, handwritten notes, and standing out
27:13 “Magic” in packaging, Alchemy, and why it works
31:28 Why Rhymetec leaned into federal compliance
32:24 SOC 2 race to the bottom vs doing it the right way
39:15 What’s improving in federal compliance (and what still hurts)
40:11 FedRAMP 20x innovation and building in public
42:52 FedRAMP scale, CMMC scale, and why it’s all accelerating
44:29 Legacy environments and why DoD adoption takes longer
46:24 Where to find Rhymetec + closing thoughts</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Federal compliance is having a moment. FedRAMP, FedRAMP 20x, CMMC, the whole alphabet soup is going mainstream, fast.</p>
<p>In this episode of The Paramify Podcast, we sit down with Justin Rende, Founder and CEO of Rhymetec, to talk about what’s actually changing, what’s still painfully hard, and why “compliance automation” only works if you stay obsessed with real risk.</p>
<p>Justin also shares his origin story (tech ➝ film festivals ➝ tech), how Rhymetec grew from early penetration tests into full vCISO and compliance programs, and the most New York lead gen strategy ever: biking around the city delivering Google Homes and handwritten notes to prospects.</p>
<p>If you’ve ever been promised an “easy button” for SOC 2, ISO, or FedRAMP, this one’s for you.</p>
<p>In this episode:</p>
<p>Why federal compliance is exploding (and why it’s not slowing down)</p>
<p>FedRAMP 20x and the pace of government innovation (yes, really)</p>
<p>The risk of “checkbox compliance” in a world of automation</p>
<p>How to set expectations with customers when security is never just one toggle</p>
<p>Bootstrapping, building recurring revenue, and staying flexible</p>
<p>Customer experience as the real differentiator (care scales better than you think)</p>
<p>Where to find Justin and Rhymetec:<br>
https://rhymetec.com<br>
  / justin-rende  </p>
<p>Learn more about Paramify: <br>
Paramify website: https://www.paramify.com/<br>
Mike Schreiner (LinkedIn):   / mikecschreiner  <br>
Kenny Scott (LinkedIn):   / kenny-g-scott  </p>
<p>Chapters</p>
<p>0:00 Federal compliance is exploding (and getting mainstream)<br>
0:30 Welcome to The Paramify Podcast + Justin Rende intro<br>
1:34 Justin’s origin story: tech ➝ film ➝ tech<br>
2:53 Starting Rhymetec with pentesting (and betting on SaaS early)<br>
4:25 Tribeca and Doha: running VIP experiences and meeting “heroes”<br>
5:33 The real lesson from film: make the customer have a good time<br>
7:01 Mess-ups happen, recovery is the job<br>
8:15 “Don’t meet your heroes” (Rudy story)<br>
9:24 Leaving film, chasing stability, spotting outdated consulting<br>
10:43 Bootstrapping vs taking investment and why flexibility wins<br>
13:53 From big pentest checks to recurring revenue and vCISO programs<br>
15:24 Employee experience: quality of life, culture, and remote done right<br>
18:10 SOC 2 and ISO automation: the pros, the cons, and the risk gap<br>
20:25 The “easy button” myth (MFA is never just one button)<br>
21:38 Sales overpromising, complexity, and doing right by the customer<br>
25:36 Biking NYC: Google Homes, handwritten notes, and standing out<br>
27:13 “Magic” in packaging, Alchemy, and why it works<br>
31:28 Why Rhymetec leaned into federal compliance<br>
32:24 SOC 2 race to the bottom vs doing it the right way<br>
39:15 What’s improving in federal compliance (and what still hurts)<br>
40:11 FedRAMP 20x innovation and building in public<br>
42:52 FedRAMP scale, CMMC scale, and why it’s all accelerating<br>
44:29 Legacy environments and why DoD adoption takes longer<br>
46:24 Where to find Rhymetec + closing thoughts</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/978mduycsg65aspy/Justin_Rende_Full_Podcast_au088.mp3" length="45226159" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Federal compliance is having a moment. FedRAMP, FedRAMP 20x, CMMC, the whole alphabet soup is going mainstream, fast.
In this episode of The Paramify Podcast, we sit down with Justin Rende, Founder and CEO of Rhymetec, to talk about what’s actually changing, what’s still painfully hard, and why “compliance automation” only works if you stay obsessed with real risk.
Justin also shares his origin story (tech ➝ film festivals ➝ tech), how Rhymetec grew from early penetration tests into full vCISO and compliance programs, and the most New York lead gen strategy ever: biking around the city delivering Google Homes and handwritten notes to prospects.
If you’ve ever been promised an “easy button” for SOC 2, ISO, or FedRAMP, this one’s for you.
In this episode:
Why federal compliance is exploding (and why it’s not slowing down)
FedRAMP 20x and the pace of government innovation (yes, really)
The risk of “checkbox compliance” in a world of automation
How to set expectations with customers when security is never just one toggle
Bootstrapping, building recurring revenue, and staying flexible
Customer experience as the real differentiator (care scales better than you think)
Where to find Justin and Rhymetec:https://rhymetec.com  / justin-rende  
Learn more about Paramify: Paramify website: https://www.paramify.com/Mike Schreiner (LinkedIn):   / mikecschreiner  Kenny Scott (LinkedIn):   / kenny-g-scott  
Chapters
0:00 Federal compliance is exploding (and getting mainstream)0:30 Welcome to The Paramify Podcast + Justin Rende intro1:34 Justin’s origin story: tech ➝ film ➝ tech2:53 Starting Rhymetec with pentesting (and betting on SaaS early)4:25 Tribeca and Doha: running VIP experiences and meeting “heroes”5:33 The real lesson from film: make the customer have a good time7:01 Mess-ups happen, recovery is the job8:15 “Don’t meet your heroes” (Rudy story)9:24 Leaving film, chasing stability, spotting outdated consulting10:43 Bootstrapping vs taking investment and why flexibility wins13:53 From big pentest checks to recurring revenue and vCISO programs15:24 Employee experience: quality of life, culture, and remote done right18:10 SOC 2 and ISO automation: the pros, the cons, and the risk gap20:25 The “easy button” myth (MFA is never just one button)21:38 Sales overpromising, complexity, and doing right by the customer25:36 Biking NYC: Google Homes, handwritten notes, and standing out27:13 “Magic” in packaging, Alchemy, and why it works31:28 Why Rhymetec leaned into federal compliance32:24 SOC 2 race to the bottom vs doing it the right way39:15 What’s improving in federal compliance (and what still hurts)40:11 FedRAMP 20x innovation and building in public42:52 FedRAMP scale, CMMC scale, and why it’s all accelerating44:29 Legacy environments and why DoD adoption takes longer46:24 Where to find Rhymetec + closing thoughts]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2826</itunes:duration>
                <itunes:episode>52</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>GRC Lasagna with Ayoub Fandi</title>
        <itunes:title>GRC Lasagna with Ayoub Fandi</itunes:title>
        <link>https://Paramify.podbean.com/e/grc-lasagna-with-ayoub-fandi/</link>
                    <comments>https://Paramify.podbean.com/e/grc-lasagna-with-ayoub-fandi/#comments</comments>        <pubDate>Mon, 05 Jan 2026 12:29:46 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/c4eabe96-1db9-3472-bf63-d8ca56eff335</guid>
                                    <description><![CDATA[<p>“There’s this misconception in the marketplace that you need to be a coder to do GRC Engineering. You don’t. I don’t want people to be bogged down in scripting. I want them to be systems thinkers focusing on architecture and orchestration.”</p>
<p>Kenny and Mike sit down with the GOATed pioneer of GRC Engineering, Ayoub Fandi. In case you’ve been living under a rock, Ayoub is the Security Assurance Automation Team Lead at GitLab and the Founder of GRC Engineer.</p>
<p>This episode covers Ayoub’s wild pivot from middle school English teacher to sending 500 cold LinkedIn DMs to break into security. We dive into his first trip to Utah (discovery of "sugarcane fillets" and life-changing butter cake), why APIs are the “landlines” of the past, and how he sparked the movement behind the GRC Engineering Manifesto to give practitioners their own “Phoenix Project” moment for compliance.</p>
<p>Key Takeaways:
* Systems Over Scripts: GRC Engineering isn't about being a "coder." It’s about systems thinking and moving away from the "crawl space" of manual scripting.
* The "Cell Phone" Moment: Why GRC is skipping the "landline" era of APIs and jumping straight to agentic workflows with MCP (Model Context Protocol).
* FedRAMP® 20x: How Key Security Indicators (KSIs) move the burden of proof from 4,000-page narratives to 80%+ automated validation.
* The 7-Minute Threat: AI-powered adversaries can pop a machine in 7 minutes. If your compliance isn't "threat-driven," it's irrelevant.</p>
<p>Learn more about Ayoub:
Gitlab: https://about.gitlab.com/ 
GRC Engineer: https://grcengineer.com/
GRC Engineer Podcast: https://www.youtube.com/channel/UC8cvmIXoEEBs0dryLh2p2cA
Ayoub's LinkedIn: https://www.linkedin.com/in/ayoubfandi/</p>
<p>Learn more about Paramify:
Website: https://www.paramify.com/
Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/
Mike's LinkedIn: https://www.linkedin.com/in/mikecschreiner/</p>
<p>Chapters</p>
<p>00:00 Intro — Utah, butter cake, and Ayoub's first time in the U.S.
02:00 How Ayoub got into GRC (500 cold DMs and ISO cramming)
09:00 Struggling to commit to GRC — until Adobe's program changed everything
13:00 What GRC Engineering actually means
15:00 Why evidence collection is plumbing, not strategy
20:00 Why AI won’t kill GRC — it’ll force it to grow up
25:00 Architecting assurance: the new role of GRC
30:00 Why APIs are losing ground to agentic protocols like MCP
35:00 Landlines vs. Cell Phones: How automation skipped a generation
38:00 Platformization, assurance, and the SaaS vendor dilemma
43:00 Can platforms fix SOC 2 quality?
48:00 Sticker fatigue and the case for continuous assurance
52:00 Why threat-driven compliance is the only way forward
56:00 Advice for early-career GRC professionals in an AI-native world</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>“There’s this misconception in the marketplace that you need to be a coder to do GRC Engineering. You don’t. I don’t want people to be bogged down in scripting. I want them to be systems thinkers focusing on architecture and orchestration.”</p>
<p>Kenny and Mike sit down with the GOATed pioneer of GRC Engineering, Ayoub Fandi. In case you’ve been living under a rock, Ayoub is the Security Assurance Automation Team Lead at GitLab and the Founder of GRC Engineer.</p>
<p>This episode covers Ayoub’s wild pivot from middle school English teacher to sending 500 cold LinkedIn DMs to break into security. We dive into his first trip to Utah (discovery of "sugarcane fillets" and life-changing butter cake), why APIs are the “landlines” of the past, and how he sparked the movement behind the GRC Engineering Manifesto to give practitioners their own “Phoenix Project” moment for compliance.</p>
<p>Key Takeaways:<br>
* Systems Over Scripts: GRC Engineering isn't about being a "coder." It’s about systems thinking and moving away from the "crawl space" of manual scripting.<br>
* The "Cell Phone" Moment: Why GRC is skipping the "landline" era of APIs and jumping straight to agentic workflows with MCP (Model Context Protocol).<br>
* FedRAMP® 20x: How Key Security Indicators (KSIs) move the burden of proof from 4,000-page narratives to 80%+ automated validation.<br>
* The 7-Minute Threat: AI-powered adversaries can pop a machine in 7 minutes. If your compliance isn't "threat-driven," it's irrelevant.</p>
<p>Learn more about Ayoub:<br>
Gitlab: https://about.gitlab.com/ <br>
GRC Engineer: https://grcengineer.com/<br>
GRC Engineer Podcast: https://www.youtube.com/channel/UC8cvmIXoEEBs0dryLh2p2cA<br>
Ayoub's LinkedIn: https://www.linkedin.com/in/ayoubfandi/</p>
<p>Learn more about Paramify:<br>
Website: https://www.paramify.com/<br>
Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/<br>
Mike's LinkedIn: https://www.linkedin.com/in/mikecschreiner/</p>
<p>Chapters</p>
<p>00:00 Intro — Utah, butter cake, and Ayoub's first time in the U.S.<br>
02:00 How Ayoub got into GRC (500 cold DMs and ISO cramming)<br>
09:00 Struggling to commit to GRC — until Adobe's program changed everything<br>
13:00 What GRC Engineering actually means<br>
15:00 Why evidence collection is plumbing, not strategy<br>
20:00 Why AI won’t kill GRC — it’ll force it to grow up<br>
25:00 Architecting assurance: the new role of GRC<br>
30:00 Why APIs are losing ground to agentic protocols like MCP<br>
35:00 Landlines vs. Cell Phones: How automation skipped a generation<br>
38:00 Platformization, assurance, and the SaaS vendor dilemma<br>
43:00 Can platforms fix SOC 2 quality?<br>
48:00 Sticker fatigue and the case for continuous assurance<br>
52:00 Why threat-driven compliance is the only way forward<br>
56:00 Advice for early-career GRC professionals in an AI-native world</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/344w39ysx5nqfi2d/Ayoub_Fandi_Full_Podcastb73rm.mp3" length="81942201" type="audio/mpeg"/>
        <itunes:summary><![CDATA[“There’s this misconception in the marketplace that you need to be a coder to do GRC Engineering. You don’t. I don’t want people to be bogged down in scripting. I want them to be systems thinkers focusing on architecture and orchestration.”
Kenny and Mike sit down with the GOATed pioneer of GRC Engineering, Ayoub Fandi. In case you’ve been living under a rock, Ayoub is the Security Assurance Automation Team Lead at GitLab and the Founder of GRC Engineer.
This episode covers Ayoub’s wild pivot from middle school English teacher to sending 500 cold LinkedIn DMs to break into security. We dive into his first trip to Utah (discovery of "sugarcane fillets" and life-changing butter cake), why APIs are the “landlines” of the past, and how he sparked the movement behind the GRC Engineering Manifesto to give practitioners their own “Phoenix Project” moment for compliance.
Key Takeaways:* Systems Over Scripts: GRC Engineering isn't about being a "coder." It’s about systems thinking and moving away from the "crawl space" of manual scripting.* The "Cell Phone" Moment: Why GRC is skipping the "landline" era of APIs and jumping straight to agentic workflows with MCP (Model Context Protocol).* FedRAMP® 20x: How Key Security Indicators (KSIs) move the burden of proof from 4,000-page narratives to 80%+ automated validation.* The 7-Minute Threat: AI-powered adversaries can pop a machine in 7 minutes. If your compliance isn't "threat-driven," it's irrelevant.
Learn more about Ayoub:Gitlab: https://about.gitlab.com/ GRC Engineer: https://grcengineer.com/GRC Engineer Podcast: https://www.youtube.com/channel/UC8cvmIXoEEBs0dryLh2p2cAAyoub's LinkedIn: https://www.linkedin.com/in/ayoubfandi/
Learn more about Paramify:Website: https://www.paramify.com/Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/Mike's LinkedIn: https://www.linkedin.com/in/mikecschreiner/
Chapters
00:00 Intro — Utah, butter cake, and Ayoub's first time in the U.S.02:00 How Ayoub got into GRC (500 cold DMs and ISO cramming)09:00 Struggling to commit to GRC — until Adobe's program changed everything13:00 What GRC Engineering actually means15:00 Why evidence collection is plumbing, not strategy20:00 Why AI won’t kill GRC — it’ll force it to grow up25:00 Architecting assurance: the new role of GRC30:00 Why APIs are losing ground to agentic protocols like MCP35:00 Landlines vs. Cell Phones: How automation skipped a generation38:00 Platformization, assurance, and the SaaS vendor dilemma43:00 Can platforms fix SOC 2 quality?48:00 Sticker fatigue and the case for continuous assurance52:00 Why threat-driven compliance is the only way forward56:00 Advice for early-career GRC professionals in an AI-native world]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>5121</itunes:duration>
                <itunes:episode>51</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>SOC 2, FedRAMP 20x, and the Future of Audits with Dixon Wright</title>
        <itunes:title>SOC 2, FedRAMP 20x, and the Future of Audits with Dixon Wright</itunes:title>
        <link>https://Paramify.podbean.com/e/soc-2-fedramp-20x-and-the-future-of-audits-with-dixon-wright/</link>
                    <comments>https://Paramify.podbean.com/e/soc-2-fedramp-20x-and-the-future-of-audits-with-dixon-wright/#comments</comments>        <pubDate>Tue, 16 Dec 2025 15:44:49 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/99cf7fb7-9fd4-35ff-b70f-3ff21e6b4cf0</guid>
                                    <description><![CDATA[<p>Kenny and Mike sit down with Dixon Wright, Head of Delivery at Eden Data, for a grounded and insightful conversation on security, compliance, and building smarter systems.</p>
<p>They cover:</p>
<p>- Dixon’s journey from college football to leading security at Eden Data</p>
<p>- What it takes to actually deliver cybersecurity — not just sell it</p>
<p>- Why Eden Data joined the FedRAMP 20x pilot</p>
<p>- How compliance is evolving across commercial and federal sectors</p>
<p>- Why trust, transparency, and execution matter more than buzzwords</p>
<p>It’s one of the most real conversations we’ve had about what delivery actually looks like in the compliance world.</p>
<p>Chapters
00:00 Intro: From field goals to FedRAMP
02:00 Dixon’s career in security consulting
05:00 What Eden Data does and who they serve
09:00 Joining the FedRAMP 20x pilot
14:00 Building credibility through execution
18:00 Security in practice vs. theory
23:00 Why delivery teams need flexibility
27:00 Shifts in federal and commercial compliance
32:00 Trust, tools, and transparent reporting
36:00 The future of cybersecurity delivery
41:00 Final thoughts</p>
<p>Learn more about Eden Data: 
https://www.edendata.com</p>
<p>Learn more about Dixon Wright:
  / dixon-wright-aab68321  </p>
<p>Learn more about Paramify: 
https://www.paramify.com/</p>
<p>Learn more about Kenny:
  / kenny-g-scott  
Learn more about Mike:
  / mikecschreiner  </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Kenny and Mike sit down with Dixon Wright, Head of Delivery at Eden Data, for a grounded and insightful conversation on security, compliance, and building smarter systems.</p>
<p>They cover:</p>
<p>- Dixon’s journey from college football to leading security at Eden Data</p>
<p>- What it takes to actually deliver cybersecurity — not just sell it</p>
<p>- Why Eden Data joined the FedRAMP 20x pilot</p>
<p>- How compliance is evolving across commercial and federal sectors</p>
<p>- Why trust, transparency, and execution matter more than buzzwords</p>
<p>It’s one of the most real conversations we’ve had about what delivery actually looks like in the compliance world.</p>
<p>Chapters<br>
00:00 Intro: From field goals to FedRAMP<br>
02:00 Dixon’s career in security consulting<br>
05:00 What Eden Data does and who they serve<br>
09:00 Joining the FedRAMP 20x pilot<br>
14:00 Building credibility through execution<br>
18:00 Security in practice vs. theory<br>
23:00 Why delivery teams need flexibility<br>
27:00 Shifts in federal and commercial compliance<br>
32:00 Trust, tools, and transparent reporting<br>
36:00 The future of cybersecurity delivery<br>
41:00 Final thoughts</p>
<p>Learn more about Eden Data: <br>
https://www.edendata.com</p>
<p>Learn more about Dixon Wright:<br>
  / dixon-wright-aab68321  </p>
<p>Learn more about Paramify: <br>
https://www.paramify.com/</p>
<p>Learn more about Kenny:<br>
  / kenny-g-scott  <br>
Learn more about Mike:<br>
  / mikecschreiner  </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x5tsmeimqsq2h2ut/Dixon_Wright_FULL_PODCAST97zr0.mp3" length="54800768" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Kenny and Mike sit down with Dixon Wright, Head of Delivery at Eden Data, for a grounded and insightful conversation on security, compliance, and building smarter systems.
They cover:
- Dixon’s journey from college football to leading security at Eden Data
- What it takes to actually deliver cybersecurity — not just sell it
- Why Eden Data joined the FedRAMP 20x pilot
- How compliance is evolving across commercial and federal sectors
- Why trust, transparency, and execution matter more than buzzwords
It’s one of the most real conversations we’ve had about what delivery actually looks like in the compliance world.
Chapters00:00 Intro: From field goals to FedRAMP02:00 Dixon’s career in security consulting05:00 What Eden Data does and who they serve09:00 Joining the FedRAMP 20x pilot14:00 Building credibility through execution18:00 Security in practice vs. theory23:00 Why delivery teams need flexibility27:00 Shifts in federal and commercial compliance32:00 Trust, tools, and transparent reporting36:00 The future of cybersecurity delivery41:00 Final thoughts
Learn more about Eden Data: https://www.edendata.com
Learn more about Dixon Wright:  / dixon-wright-aab68321  
Learn more about Paramify: https://www.paramify.com/
Learn more about Kenny:  / kenny-g-scott  Learn more about Mike:  / mikecschreiner  ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3425</itunes:duration>
                <itunes:episode>50</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Future of GRC with Jack Rumsey</title>
        <itunes:title>The Future of GRC with Jack Rumsey</itunes:title>
        <link>https://Paramify.podbean.com/e/the-future-of-grc-with-jack-rumsey/</link>
                    <comments>https://Paramify.podbean.com/e/the-future-of-grc-with-jack-rumsey/#comments</comments>        <pubDate>Mon, 08 Dec 2025 12:30:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d68db3da-a05e-3f00-927c-c6a1bb2cdf88</guid>
                                    <description><![CDATA[<p>"The AI age we're in is going to force startups to compete in the higher upper echelon of risk assurance."</p>
<p>Jack Rumsey Head of GRC at Swimlane explains why startups will no longer have the luxury of maturing later and how the AI era is pushing even early-stage teams into enterprise-grade security.</p>
<p>This episode covers why assurance needs to evolve, how 20X can level the playing field, why automation is changing everything about how companies prove trust, and Jack's brief era as "the richest fifth-year college student of all time."</p>
<p>Key Takeaways:
• Automation is reshaping how companies prove trust and security
• Startups will need enterprise-grade security earlier than ever
• Continuous monitoring is becoming the new foundation for real assurance</p>
<p>Chapters
00:00 Security teams are drowning
02:40 Scaling trust in public sector
06:10 Check-the-box isn’t cutting it
10:00 The promise of low-code automation
13:40 Swimlane’s mission and momentum
17:00 How to reduce alert fatigue
21:30 Integrating detection with compliance
26:15 CMMC and automation opportunities
30:00 Why orchestration needs flexibility
34:00 Future of GRC tooling
36:50 Final thoughts on doing more with less</p>
<p>Learn more about Jack Rumsey: 
https://www.linkedin.com/in/jack-rumsey-83303469/
Learn more about GRC Destroyer: https://grcdestroyer.substack.com
Learn more abou Swimlane: https://swimlane.com</p>
<p>
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/
Learn more about Paramify: https://www.paramify.com/</p>
<p>Chapters
00:00 Security teams are drowning
02:40 Scaling trust in public sector
06:10 Check-the-box isn’t cutting it
10:00 The promise of low-code automation
13:40 Swimlane’s mission and momentum
17:00 How to reduce alert fatigue
21:30 Integrating detection with compliance
26:15 CMMC and automation opportunities
30:00 Why orchestration needs flexibility
34:00 Future of GRC tooling
36:50 Final thoughts on doing more with less</p>
<p>Learn more about Jack Rumsey: 
https://www.linkedin.com/in/jack-rumsey-83303469/
Learn more about GRC Destroyer: https://grcdestroyer.substack.com
Learn more abou Swimlane: https://swimlane.com</p>
<p>
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/
Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>"The AI age we're in is going to force startups to compete in the higher upper echelon of risk assurance."</p>
<p>Jack Rumsey Head of GRC at Swimlane explains why startups will no longer have the luxury of maturing later and how the AI era is pushing even early-stage teams into enterprise-grade security.</p>
<p>This episode covers why assurance needs to evolve, how 20X can level the playing field, why automation is changing everything about how companies prove trust, and Jack's brief era as "the richest fifth-year college student of all time."</p>
<p>Key Takeaways:<br>
• Automation is reshaping how companies prove trust and security<br>
• Startups will need enterprise-grade security earlier than ever<br>
• Continuous monitoring is becoming the new foundation for real assurance</p>
<p>Chapters<br>
00:00 Security teams are drowning<br>
02:40 Scaling trust in public sector<br>
06:10 Check-the-box isn’t cutting it<br>
10:00 The promise of low-code automation<br>
13:40 Swimlane’s mission and momentum<br>
17:00 How to reduce alert fatigue<br>
21:30 Integrating detection with compliance<br>
26:15 CMMC and automation opportunities<br>
30:00 Why orchestration needs flexibility<br>
34:00 Future of GRC tooling<br>
36:50 Final thoughts on doing more with less</p>
<p>Learn more about Jack Rumsey: <br>
https://www.linkedin.com/in/jack-rumsey-83303469/<br>
Learn more about GRC Destroyer: https://grcdestroyer.substack.com<br>
Learn more abou Swimlane: https://swimlane.com</p>
<p><br>
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/<br>
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/<br>
Learn more about Paramify: https://www.paramify.com/</p>
<p>Chapters<br>
00:00 Security teams are drowning<br>
02:40 Scaling trust in public sector<br>
06:10 Check-the-box isn’t cutting it<br>
10:00 The promise of low-code automation<br>
13:40 Swimlane’s mission and momentum<br>
17:00 How to reduce alert fatigue<br>
21:30 Integrating detection with compliance<br>
26:15 CMMC and automation opportunities<br>
30:00 Why orchestration needs flexibility<br>
34:00 Future of GRC tooling<br>
36:50 Final thoughts on doing more with less</p>
<p>Learn more about Jack Rumsey: <br>
https://www.linkedin.com/in/jack-rumsey-83303469/<br>
Learn more about GRC Destroyer: https://grcdestroyer.substack.com<br>
Learn more abou Swimlane: https://swimlane.com</p>
<p><br>
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/<br>
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/<br>
Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/daetaeiv4q8jq8s8/Jack_Rumsey_Full_Podcast9qg9w.mp3" length="50610309" type="audio/mpeg"/>
        <itunes:summary><![CDATA["The AI age we're in is going to force startups to compete in the higher upper echelon of risk assurance."
Jack Rumsey Head of GRC at Swimlane explains why startups will no longer have the luxury of maturing later and how the AI era is pushing even early-stage teams into enterprise-grade security.
This episode covers why assurance needs to evolve, how 20X can level the playing field, why automation is changing everything about how companies prove trust, and Jack's brief era as "the richest fifth-year college student of all time."
Key Takeaways:• Automation is reshaping how companies prove trust and security• Startups will need enterprise-grade security earlier than ever• Continuous monitoring is becoming the new foundation for real assurance
Chapters00:00 Security teams are drowning02:40 Scaling trust in public sector06:10 Check-the-box isn’t cutting it10:00 The promise of low-code automation13:40 Swimlane’s mission and momentum17:00 How to reduce alert fatigue21:30 Integrating detection with compliance26:15 CMMC and automation opportunities30:00 Why orchestration needs flexibility34:00 Future of GRC tooling36:50 Final thoughts on doing more with less
Learn more about Jack Rumsey: https://www.linkedin.com/in/jack-rumsey-83303469/Learn more about GRC Destroyer: https://grcdestroyer.substack.comLearn more abou Swimlane: https://swimlane.com
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/Learn more about Paramify: https://www.paramify.com/
Chapters00:00 Security teams are drowning02:40 Scaling trust in public sector06:10 Check-the-box isn’t cutting it10:00 The promise of low-code automation13:40 Swimlane’s mission and momentum17:00 How to reduce alert fatigue21:30 Integrating detection with compliance26:15 CMMC and automation opportunities30:00 Why orchestration needs flexibility34:00 Future of GRC tooling36:50 Final thoughts on doing more with less
Learn more about Jack Rumsey: https://www.linkedin.com/in/jack-rumsey-83303469/Learn more about GRC Destroyer: https://grcdestroyer.substack.comLearn more abou Swimlane: https://swimlane.com
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3163</itunes:duration>
                <itunes:episode>49</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Giant Washing Machine of Open Source: Container Security with George Manuelian</title>
        <itunes:title>The Giant Washing Machine of Open Source: Container Security with George Manuelian</itunes:title>
        <link>https://Paramify.podbean.com/e/the-giant-washing-machine-of-open-source-container-security-with-george-manuelian/</link>
                    <comments>https://Paramify.podbean.com/e/the-giant-washing-machine-of-open-source-container-security-with-george-manuelian/#comments</comments>        <pubDate>Mon, 27 Oct 2025 11:19:54 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/bb3ca8b6-081b-3580-8bbc-a094c836fd65</guid>
                                    <description><![CDATA[<p>Security isn’t sexy. It’s laundry. You know you need to do it, but you’d rather have a tool do it for you.</p>
<p>Kenny Scott and Mike Schreiner from Paramify sit down with George Manuelian from RapidFort to talk about freeing the captives — the engineers buried in spreadsheets, patch tickets, and compliance chaos.</p>
<p>They cover:</p>
<p> </p>
<p>Why security always seems at odds with progress</p>
<p> </p>
<p>How automation can fix what boredom created</p>
<p> </p>
<p>The giant washing machine for open source</p>
<p> </p>
<p>Starting clean, staying clean, and why “7 million vulnerabilities” isn’t a vibe</p>
<p> </p>
<p>FedRAMP, CMMC, and the art of not losing your mind in compliance</p>
<p> </p>
<p>It’s the least boring conversation you’ll ever hear about vulnerabilities.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Security isn’t sexy. It’s laundry. You know you need to do it, but you’d rather have a tool do it for you.</p>
<p>Kenny Scott and Mike Schreiner from Paramify sit down with George Manuelian from RapidFort to talk about freeing the captives — the engineers buried in spreadsheets, patch tickets, and compliance chaos.</p>
<p>They cover:</p>
<p> </p>
<p>Why security always seems at odds with progress</p>
<p> </p>
<p>How automation can fix what boredom created</p>
<p> </p>
<p>The giant washing machine for open source</p>
<p> </p>
<p>Starting clean, staying clean, and why “7 million vulnerabilities” isn’t a vibe</p>
<p> </p>
<p>FedRAMP, CMMC, and the art of not losing your mind in compliance</p>
<p> </p>
<p>It’s the least boring conversation you’ll ever hear about vulnerabilities.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/chh5anwqgpcxb9mw/George_Manuelian_Full_Podcastasuwi.mp3" length="49857565" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Security isn’t sexy. It’s laundry. You know you need to do it, but you’d rather have a tool do it for you.
Kenny Scott and Mike Schreiner from Paramify sit down with George Manuelian from RapidFort to talk about freeing the captives — the engineers buried in spreadsheets, patch tickets, and compliance chaos.
They cover:
 
Why security always seems at odds with progress
 
How automation can fix what boredom created
 
The giant washing machine for open source
 
Starting clean, staying clean, and why “7 million vulnerabilities” isn’t a vibe
 
FedRAMP, CMMC, and the art of not losing your mind in compliance
 
It’s the least boring conversation you’ll ever hear about vulnerabilities.]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3116</itunes:duration>
                <itunes:episode>48</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The End of FedRAMP as We Know It? Mike Craig on 20x, DoD, and What’s Next</title>
        <itunes:title>The End of FedRAMP as We Know It? Mike Craig on 20x, DoD, and What’s Next</itunes:title>
        <link>https://Paramify.podbean.com/e/the-end-of-fedramp-as-we-know-it-mike-craig-on-20x-dod-and-what-s-next/</link>
                    <comments>https://Paramify.podbean.com/e/the-end-of-fedramp-as-we-know-it-mike-craig-on-20x-dod-and-what-s-next/#comments</comments>        <pubDate>Mon, 22 Sep 2025 12:11:49 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/ee553ae2-7ebf-3889-bae5-81550dd9d84b</guid>
                                    <description><![CDATA[<p>FedRAMP as we know it is changing. In this episode, Mike and Kenny sit down with Mike “Waffle” Craig, founder and CEO of Vanaheim Security and longtime cloud and cybersecurity leader, to unpack what FedRAMP 20x means for agencies and vendors across FedCiv and DoD. We get into compliance philosophy, how to define your boundary the right way, why sponsorship strategies matter, and where scalability will make or break 20x.</p>
<p>Mike Craig shares hard-won lessons from incident response, multi-cloud ATOs, and advising startups so they don’t burn six or seven figures chasing the wrong path.</p>
<p>What we cover:</p>
<p>  • Why FedRAMP 20x signals the future of federal compliance</p>
<p>  • Sponsorship realities, Ready pitfalls, and how small vendors survive</p>
<p>  • Boundary, data flows, and “if you can’t draw it, you can’t secure it”</p>
<p>  • Zero trust in practice and multi-zone risk profiles across stacks</p>
<p>  • AI and LLM/RAG inside a FedRAMP world and change approval at scale</p>
<p>  • JAB is gone, human variance is not, and how to navigate the psychology of yes</p>
<p>  • CSFC as a model for defined stacks and what that could mean for AI patterns</p>
<p>  • Practical diagramming tips and the surprising power of PowerPoint</p>
<p>  • The “Waffle” origin story and a DoD “Beta Blocks” style experiment</p>
<p>Guest:
Learn more about Mike Craig: https://www.linkedin.com/in/michaelcraig26/
Learn more about Vanaheim Security: www.vanaheimsecurity.com</p>
<p>Learn more about Paramify: 
https://www.paramify.com/?utm_source=MikeCraig&amp;utm_medium=Podcast&amp;utm_campaign=Mikecraig&amp;utm_id=Podcast&amp;utm_term=podcast&amp;utm_content=Mikecraig</p>
<p>Exploring FedRAMP 20x, GovRAMP, FISMA, or CMMC and want a faster path to audit-ready deliverables and ConMon at scale? Talk to Paramify. We help teams get compliant and stay compliant 90% faster at a quarter of the cost.</p>
<p>Timestamps / Chapters
0:00 — “FedRAMP as we know it” and the 20x future
1:42 — Welcome back to The Paramify Podcast (Mike &amp; Kenny)
3:01 — Meet Mike “Waffle” Craig (Vanaheim Security)
4:04 — Hero’s journey: Air Force → cyber → IR → compliance
5:04 — “Cyber warfare” era and being the translator across teams
6:02 — Global regs, midnight IR, and burnout
7:04 — From IR to compliance architecture &amp; multi-cloud ATOs
8:05 — Protecting small vendors from six–seven figure mistakes
9:11 — When compliance runway kills a program (DoD case)
11:03 — Waffle’s 0% abandonment rate and why it matters
11:14 — DoD “defense combine” experiment (Beta Blocks vibe)
13:41 — Operators, COs, entrepreneurs: fixing feedback loops
16:26 — Federal sponsorship 101 (pre-20x) and targeting wisely
18:16 — Two bad options for first-timers: sponsor vs. Ready gamble
21:02 — FedRAMP Ready pitfalls and the 12-month clock
22:08 — Cost realities (150k+ assessments) for small teams
22:44 — Why 20x changes the game (starting low, scaling up)
27:04 — Compliance philosophy: scope, boundaries, and frameworks
30:00 — “If you can’t draw it, you can’t secure it” (data flows)
31:04 — Hot take: PowerPoint is the best diagramming tool
33:39 — Prototype confession: Excel/Sheets and millennial ops
37:39 — 20x at scale: staffing, humans-in-the-loop, and risk
39:07 — Post-JAB reality: more variance, harder prediction
40:05 — LLM/RAG in FedRAMP: data sources &amp; significant change
42:05 — Boundaries got harder—how to think about them
43:08 — Paramify’s CIA risk profile approach across stacks
47:01 — Corporate, dev, infosec, tech-ops: multi-zone modeling
49:05 — Knowing your data (AI makes the gap bigger, faster)
50:06 — Control weighting &amp; psychology of “yes”
50:47 — NSA CSFC as a model for defined stacks
52:02 — Could FedRAMP define AI patterns? (playbook potential)
54:46 — Where to find Mike / Vanaheim Security
55:31 — Name jokes and close</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>FedRAMP as we know it is changing. In this episode, Mike and Kenny sit down with Mike “Waffle” Craig, founder and CEO of Vanaheim Security and longtime cloud and cybersecurity leader, to unpack what FedRAMP 20x means for agencies and vendors across FedCiv and DoD. We get into compliance philosophy, how to define your boundary the right way, why sponsorship strategies matter, and where scalability will make or break 20x.</p>
<p>Mike Craig shares hard-won lessons from incident response, multi-cloud ATOs, and advising startups so they don’t burn six or seven figures chasing the wrong path.</p>
<p>What we cover:</p>
<p>  • Why FedRAMP 20x signals the future of federal compliance</p>
<p>  • Sponsorship realities, Ready pitfalls, and how small vendors survive</p>
<p>  • Boundary, data flows, and “if you can’t draw it, you can’t secure it”</p>
<p>  • Zero trust in practice and multi-zone risk profiles across stacks</p>
<p>  • AI and LLM/RAG inside a FedRAMP world and change approval at scale</p>
<p>  • JAB is gone, human variance is not, and how to navigate the psychology of yes</p>
<p>  • CSFC as a model for defined stacks and what that could mean for AI patterns</p>
<p>  • Practical diagramming tips and the surprising power of PowerPoint</p>
<p>  • The “Waffle” origin story and a DoD “Beta Blocks” style experiment</p>
<p>Guest:<br>
Learn more about Mike Craig: https://www.linkedin.com/in/michaelcraig26/<br>
Learn more about Vanaheim Security: www.vanaheimsecurity.com</p>
<p>Learn more about Paramify: <br>
https://www.paramify.com/?utm_source=MikeCraig&amp;utm_medium=Podcast&amp;utm_campaign=Mikecraig&amp;utm_id=Podcast&amp;utm_term=podcast&amp;utm_content=Mikecraig</p>
<p>Exploring FedRAMP 20x, GovRAMP, FISMA, or CMMC and want a faster path to audit-ready deliverables and ConMon at scale? Talk to Paramify. We help teams get compliant and stay compliant 90% faster at a quarter of the cost.</p>
<p>Timestamps / Chapters<br>
0:00 — “FedRAMP as we know it” and the 20x future<br>
1:42 — Welcome back to The Paramify Podcast (Mike &amp; Kenny)<br>
3:01 — Meet Mike “Waffle” Craig (Vanaheim Security)<br>
4:04 — Hero’s journey: Air Force → cyber → IR → compliance<br>
5:04 — “Cyber warfare” era and being the translator across teams<br>
6:02 — Global regs, midnight IR, and burnout<br>
7:04 — From IR to compliance architecture &amp; multi-cloud ATOs<br>
8:05 — Protecting small vendors from six–seven figure mistakes<br>
9:11 — When compliance runway kills a program (DoD case)<br>
11:03 — Waffle’s 0% abandonment rate and why it matters<br>
11:14 — DoD “defense combine” experiment (Beta Blocks vibe)<br>
13:41 — Operators, COs, entrepreneurs: fixing feedback loops<br>
16:26 — Federal sponsorship 101 (pre-20x) and targeting wisely<br>
18:16 — Two bad options for first-timers: sponsor vs. Ready gamble<br>
21:02 — FedRAMP Ready pitfalls and the 12-month clock<br>
22:08 — Cost realities (150k+ assessments) for small teams<br>
22:44 — Why 20x changes the game (starting low, scaling up)<br>
27:04 — Compliance philosophy: scope, boundaries, and frameworks<br>
30:00 — “If you can’t draw it, you can’t secure it” (data flows)<br>
31:04 — Hot take: PowerPoint is the best diagramming tool<br>
33:39 — Prototype confession: Excel/Sheets and millennial ops<br>
37:39 — 20x at scale: staffing, humans-in-the-loop, and risk<br>
39:07 — Post-JAB reality: more variance, harder prediction<br>
40:05 — LLM/RAG in FedRAMP: data sources &amp; significant change<br>
42:05 — Boundaries got harder—how to think about them<br>
43:08 — Paramify’s CIA risk profile approach across stacks<br>
47:01 — Corporate, dev, infosec, tech-ops: multi-zone modeling<br>
49:05 — Knowing your data (AI makes the gap bigger, faster)<br>
50:06 — Control weighting &amp; psychology of “yes”<br>
50:47 — NSA CSFC as a model for defined stacks<br>
52:02 — Could FedRAMP define AI patterns? (playbook potential)<br>
54:46 — Where to find Mike / Vanaheim Security<br>
55:31 — Name jokes and close</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/bgrmxwapgy82n32e/Vanaheim_Full_Podcast7wcw2.mp3" length="80781111" type="audio/mpeg"/>
        <itunes:summary><![CDATA[FedRAMP as we know it is changing. In this episode, Mike and Kenny sit down with Mike “Waffle” Craig, founder and CEO of Vanaheim Security and longtime cloud and cybersecurity leader, to unpack what FedRAMP 20x means for agencies and vendors across FedCiv and DoD. We get into compliance philosophy, how to define your boundary the right way, why sponsorship strategies matter, and where scalability will make or break 20x.
Mike Craig shares hard-won lessons from incident response, multi-cloud ATOs, and advising startups so they don’t burn six or seven figures chasing the wrong path.
What we cover:
  • Why FedRAMP 20x signals the future of federal compliance
  • Sponsorship realities, Ready pitfalls, and how small vendors survive
  • Boundary, data flows, and “if you can’t draw it, you can’t secure it”
  • Zero trust in practice and multi-zone risk profiles across stacks
  • AI and LLM/RAG inside a FedRAMP world and change approval at scale
  • JAB is gone, human variance is not, and how to navigate the psychology of yes
  • CSFC as a model for defined stacks and what that could mean for AI patterns
  • Practical diagramming tips and the surprising power of PowerPoint
  • The “Waffle” origin story and a DoD “Beta Blocks” style experiment
Guest:Learn more about Mike Craig: https://www.linkedin.com/in/michaelcraig26/Learn more about Vanaheim Security: www.vanaheimsecurity.com
Learn more about Paramify: https://www.paramify.com/?utm_source=MikeCraig&amp;utm_medium=Podcast&amp;utm_campaign=Mikecraig&amp;utm_id=Podcast&amp;utm_term=podcast&amp;utm_content=Mikecraig
Exploring FedRAMP 20x, GovRAMP, FISMA, or CMMC and want a faster path to audit-ready deliverables and ConMon at scale? Talk to Paramify. We help teams get compliant and stay compliant 90% faster at a quarter of the cost.
Timestamps / Chapters0:00 — “FedRAMP as we know it” and the 20x future1:42 — Welcome back to The Paramify Podcast (Mike &amp; Kenny)3:01 — Meet Mike “Waffle” Craig (Vanaheim Security)4:04 — Hero’s journey: Air Force → cyber → IR → compliance5:04 — “Cyber warfare” era and being the translator across teams6:02 — Global regs, midnight IR, and burnout7:04 — From IR to compliance architecture &amp; multi-cloud ATOs8:05 — Protecting small vendors from six–seven figure mistakes9:11 — When compliance runway kills a program (DoD case)11:03 — Waffle’s 0% abandonment rate and why it matters11:14 — DoD “defense combine” experiment (Beta Blocks vibe)13:41 — Operators, COs, entrepreneurs: fixing feedback loops16:26 — Federal sponsorship 101 (pre-20x) and targeting wisely18:16 — Two bad options for first-timers: sponsor vs. Ready gamble21:02 — FedRAMP Ready pitfalls and the 12-month clock22:08 — Cost realities (150k+ assessments) for small teams22:44 — Why 20x changes the game (starting low, scaling up)27:04 — Compliance philosophy: scope, boundaries, and frameworks30:00 — “If you can’t draw it, you can’t secure it” (data flows)31:04 — Hot take: PowerPoint is the best diagramming tool33:39 — Prototype confession: Excel/Sheets and millennial ops37:39 — 20x at scale: staffing, humans-in-the-loop, and risk39:07 — Post-JAB reality: more variance, harder prediction40:05 — LLM/RAG in FedRAMP: data sources &amp; significant change42:05 — Boundaries got harder—how to think about them43:08 — Paramify’s CIA risk profile approach across stacks47:01 — Corporate, dev, infosec, tech-ops: multi-zone modeling49:05 — Knowing your data (AI makes the gap bigger, faster)50:06 — Control weighting &amp; psychology of “yes”50:47 — NSA CSFC as a model for defined stacks52:02 — Could FedRAMP define AI patterns? (playbook potential)54:46 — Where to find Mike / Vanaheim Security55:31 — Name jokes and close]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3365</itunes:duration>
                <itunes:episode>47</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#45 - The Evolution of FedRAMP and FedRAMP 20x with Jason Oksenhendler</title>
        <itunes:title>#45 - The Evolution of FedRAMP and FedRAMP 20x with Jason Oksenhendler</itunes:title>
        <link>https://Paramify.podbean.com/e/the-evolution-of-fedramp-and-fedramp-20x-with-jason-oksenhendler/</link>
                    <comments>https://Paramify.podbean.com/e/the-evolution-of-fedramp-and-fedramp-20x-with-jason-oksenhendler/#comments</comments>        <pubDate>Mon, 25 Aug 2025 15:13:45 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/bee99a5d-8e86-3d7b-8985-c5128923a91e</guid>
                                    <description><![CDATA[<p>“Once you’re in Hotel FedRAMP, you can’t leave.”</p>
<p>Jason Oksenhendler, Cybersecurity Director of FedRAMP®/GovRAMP at Baker Tilly x Moss Adams, sits down with Kenny and Isaac to talk about FedRAMP’s past, how 20x is shaping the future, and why nobody ever really checks out of Hotel FedRAMP.</p>
<p>👉  Key Takeaways:</p>
<p>• FedRAMP 20x was a “hand grenade” for everyone’s roadmap, and it’s already transforming compliance speed and evidence collection.</p>
<p> • Risk-first programs survive change — smart architecture and design decisions matter more than chasing checklists.</p>
<p> • Flexibility vs. rigor — 20X offers new freedom, but assessors must still enforce strong security.</p>
<p> • Collaboration wins — assessors and CSPs working together can turn impossible timelines into success.</p>
<p>Learn more about Jason:</p>
<p><a href='https://www.linkedin.com/in/jason-oksenhendler/'>https://www.linkedin.com/in/jason-oksenhendler/</a></p>
<p>Learn more about Baker Tilly x Moss Adams:</p>
<p><a href='https://www.bakertilly.com/'>https://www.bakertilly.com/</a></p>
<p><a href='https://www.mossadams.com/'>https://www.mossadams.com/</a></p>
<p>Learn more about Kenny:</p>
<p>https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Isaac:</p>
<p>https://www.linkedin.com/in/isaacteuscher/ </p>
<p>Learn more about Paramify: </p>
<p><a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
<p>Timestamps:</p>
<p>00:00 – Moss Adams x Paramify team-up
Jason recounts how a shared client pushed both teams into the deep end of 20X, asking to include the auditors before Paramify even had an assessment portal built.</p>
<p>01:00 – Less than two-week deadline
The group describes the chaos of spinning up a 20X package in record time, with Rob (the auditor) agreeing to figure things out alongside them.</p>
<p>01:44 – Submitting against moving targets
Just as the package was ready to go, the final low 20X KSIs dropped — forcing last-minute changes and stress.</p>
<p>02:24 – Nature of FedRAMP change
Jason compares FedRAMP shifts to “big boulders” coming at you, not “mousy” tweaks — change is always disruptive and massive.</p>
<p>02:56 – Success despite chaos
Teams (Paramify, Flock, Baker Tilly) pulled it together, got the package in on time, and landed among the first four 20X submissions posted publicly.</p>
<p>03:07 – The reality check
Jason: not everything in FedRAMP is “dillydallying” — clients, deadlines, and bills make delivery non-negotiable.</p>
<p>03:13 – Official podcast kickoff
Kenny introduces the episode: Jason Oksenhendler (Baker Tilly, formerly Moss Adams), and Paramify’s “rising star” Isaac Teuscher.</p>
<p>04:01 – Jason’s career origin story
From news anchor ➝ IT tech writer ➝ into FedRAMP (starting around NIST 800-53 Rev 2).</p>
<p>05:40 – First FedRAMP assignment
Jason recalls his boss handing him a paper: “Go do FedRAMP.” He walks through early JAB/ISSO processes, feedback loops, and working with Matt Goodrich and Ashley Mahan.</p>
<p>11:43 – Co-creating the FedRAMP High Baseline
Jason describes working with DoD’s Ron Rice to build the High Baseline from scratch.</p>
<p>13:00 – Early FedRAMP pain
Microsoft Word &amp; Excel “hell,” endless regurgitated control statements, and why some CSPs made assessors want to “bang their heads on the desk.”</p>
<p>15:32 – “You could do a Seinfeld routine on this crap.”
Jason on version control disasters and 600-page SSP reviews without track changes.</p>
<p>17:30 – Culture shock of change
Reactions to FedRAMP 20X mirror the same resistance to earlier shifts — but it’s always been “do once, use many.”</p>
<p>20:00 – Continuous monitoring reality
Jason emphasizes executive buy-in as essential, recalling how ConMon and POA&amp;Ms separate prepared orgs from overwhelmed ones.</p>
<p>22:50 – FedRAMP rigor vs. other frameworks
Jason argues FedRAMP is among the toughest frameworks, on par with DoD IL4-6.</p>
<p>25:00 – 20X blows up the roadmap
Kenny calls 20X a “hand grenade” for Paramify’s product plans.</p>
<p>29:00 – Cross-team collaboration
Jason highlights how six strangers in a Slack channel worked seamlessly under pressure — “like a chocolate fountain.”</p>
<p>34:00 – 20X flexibility vs. rigor
Jason explains the challenge of balancing new freedoms with maintaining strong security.</p>
<p>38:00 – Scaling 20X &amp; future baselines
Speculation about moderate and high 20X baselines and how CSPs will adapt.</p>
<p>46:00 – Tools then vs. now
From CSAM, RSAM, and E-MASS to Paramify — Jason praises ease-of-use as critical to speed and quality.</p>
<p>49:30 – Lifelong learning
FedRAMP’s ever-changing landscape keeps security careers fresh, like his days in broadcasting.</p>
<p>55:00 – “Get over it. This is the future.”
Jason’s blunt advice on 20X: stop resisting change, go where the work is, and be all-in.</p>
<p>59:02 – Career lesson from a mentor
Jason shares the Navy SEAL “my way, the right way, or the wrong way?” story — the moment that launched his assessment career.</p>
<p>1:02:04 – Closing
Relationships last longer than frameworks; Kenny, Jason, and Isaac wrap up the episode.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>“Once you’re in Hotel FedRAMP, you can’t leave.”</p>
<p>Jason Oksenhendler, Cybersecurity Director of FedRAMP®/GovRAMP at Baker Tilly x Moss Adams, sits down with Kenny and Isaac to talk about FedRAMP’s past, how 20x is shaping the future, and why nobody ever really checks out of Hotel FedRAMP.</p>
<p>👉  Key Takeaways:</p>
<p>• FedRAMP 20x was a “hand grenade” for everyone’s roadmap, and it’s already transforming compliance speed and evidence collection.</p>
<p> • Risk-first programs survive change — smart architecture and design decisions matter more than chasing checklists.</p>
<p> • Flexibility vs. rigor — 20X offers new freedom, but assessors must still enforce strong security.</p>
<p> • Collaboration wins — assessors and CSPs working together can turn impossible timelines into success.</p>
<p>Learn more about Jason:</p>
<p><a href='https://www.linkedin.com/in/jason-oksenhendler/'>https://www.linkedin.com/in/jason-oksenhendler/</a></p>
<p>Learn more about Baker Tilly x Moss Adams:</p>
<p><a href='https://www.bakertilly.com/'>https://www.bakertilly.com/</a></p>
<p><a href='https://www.mossadams.com/'>https://www.mossadams.com/</a></p>
<p>Learn more about Kenny:</p>
<p>https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Isaac:</p>
<p>https://www.linkedin.com/in/isaacteuscher/ </p>
<p>Learn more about Paramify: </p>
<p><a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
<p>Timestamps:</p>
<p>00:00 – Moss Adams x Paramify team-up<br>
Jason recounts how a shared client pushed both teams into the deep end of 20X, asking to include the auditors before Paramify even had an assessment portal built.</p>
<p>01:00 – Less than two-week deadline<br>
The group describes the chaos of spinning up a 20X package in record time, with Rob (the auditor) agreeing to figure things out alongside them.</p>
<p>01:44 – Submitting against moving targets<br>
Just as the package was ready to go, the final low 20X KSIs dropped — forcing last-minute changes and stress.</p>
<p>02:24 – Nature of FedRAMP change<br>
Jason compares FedRAMP shifts to “big boulders” coming at you, not “mousy” tweaks — change is always disruptive and massive.</p>
<p>02:56 – Success despite chaos<br>
Teams (Paramify, Flock, Baker Tilly) pulled it together, got the package in on time, and landed among the first four 20X submissions posted publicly.</p>
<p>03:07 – The reality check<br>
Jason: not everything in FedRAMP is “dillydallying” — clients, deadlines, and bills make delivery non-negotiable.</p>
<p>03:13 – Official podcast kickoff<br>
Kenny introduces the episode: Jason Oksenhendler (Baker Tilly, formerly Moss Adams), and Paramify’s “rising star” Isaac Teuscher.</p>
<p>04:01 – Jason’s career origin story<br>
From news anchor ➝ IT tech writer ➝ into FedRAMP (starting around NIST 800-53 Rev 2).</p>
<p>05:40 – First FedRAMP assignment<br>
Jason recalls his boss handing him a paper: “Go do FedRAMP.” He walks through early JAB/ISSO processes, feedback loops, and working with Matt Goodrich and Ashley Mahan.</p>
<p>11:43 – Co-creating the FedRAMP High Baseline<br>
Jason describes working with DoD’s Ron Rice to build the High Baseline from scratch.</p>
<p>13:00 – Early FedRAMP pain<br>
Microsoft Word &amp; Excel “hell,” endless regurgitated control statements, and why some CSPs made assessors want to “bang their heads on the desk.”</p>
<p>15:32 – “You could do a Seinfeld routine on this crap.”<br>
Jason on version control disasters and 600-page SSP reviews without track changes.</p>
<p>17:30 – Culture shock of change<br>
Reactions to FedRAMP 20X mirror the same resistance to earlier shifts — but it’s always been “do once, use many.”</p>
<p>20:00 – Continuous monitoring reality<br>
Jason emphasizes executive buy-in as essential, recalling how ConMon and POA&amp;Ms separate prepared orgs from overwhelmed ones.</p>
<p>22:50 – FedRAMP rigor vs. other frameworks<br>
Jason argues FedRAMP is among the toughest frameworks, on par with DoD IL4-6.</p>
<p>25:00 – 20X blows up the roadmap<br>
Kenny calls 20X a “hand grenade” for Paramify’s product plans.</p>
<p>29:00 – Cross-team collaboration<br>
Jason highlights how six strangers in a Slack channel worked seamlessly under pressure — “like a chocolate fountain.”</p>
<p>34:00 – 20X flexibility vs. rigor<br>
Jason explains the challenge of balancing new freedoms with maintaining strong security.</p>
<p>38:00 – Scaling 20X &amp; future baselines<br>
Speculation about moderate and high 20X baselines and how CSPs will adapt.</p>
<p>46:00 – Tools then vs. now<br>
From CSAM, RSAM, and E-MASS to Paramify — Jason praises ease-of-use as critical to speed and quality.</p>
<p>49:30 – Lifelong learning<br>
FedRAMP’s ever-changing landscape keeps security careers fresh, like his days in broadcasting.</p>
<p>55:00 – “Get over it. This is the future.”<br>
Jason’s blunt advice on 20X: stop resisting change, go where the work is, and be all-in.</p>
<p>59:02 – Career lesson from a mentor<br>
Jason shares the Navy SEAL “my way, the right way, or the wrong way?” story — the moment that launched his assessment career.</p>
<p>1:02:04 – Closing<br>
Relationships last longer than frameworks; Kenny, Jason, and Isaac wrap up the episode.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kk9u5mnbmebzger8/mp3_Jason_Podcast_audio8f51b.mp3" length="90153219" type="audio/mpeg"/>
        <itunes:summary><![CDATA[“Once you’re in Hotel FedRAMP, you can’t leave.”
Jason Oksenhendler, Cybersecurity Director of FedRAMP®/GovRAMP at Baker Tilly x Moss Adams, sits down with Kenny and Isaac to talk about FedRAMP’s past, how 20x is shaping the future, and why nobody ever really checks out of Hotel FedRAMP.
👉  Key Takeaways:
• FedRAMP 20x was a “hand grenade” for everyone’s roadmap, and it’s already transforming compliance speed and evidence collection.
 • Risk-first programs survive change — smart architecture and design decisions matter more than chasing checklists.
 • Flexibility vs. rigor — 20X offers new freedom, but assessors must still enforce strong security.
 • Collaboration wins — assessors and CSPs working together can turn impossible timelines into success.
Learn more about Jason:
https://www.linkedin.com/in/jason-oksenhendler/
Learn more about Baker Tilly x Moss Adams:
https://www.bakertilly.com/
https://www.mossadams.com/
Learn more about Kenny:
https://www.linkedin.com/in/kenny-g-scott/
Learn more about Isaac:
https://www.linkedin.com/in/isaacteuscher/ 
Learn more about Paramify: 
https://www.paramify.com/
 
Timestamps:
00:00 – Moss Adams x Paramify team-upJason recounts how a shared client pushed both teams into the deep end of 20X, asking to include the auditors before Paramify even had an assessment portal built.
01:00 – Less than two-week deadlineThe group describes the chaos of spinning up a 20X package in record time, with Rob (the auditor) agreeing to figure things out alongside them.
01:44 – Submitting against moving targetsJust as the package was ready to go, the final low 20X KSIs dropped — forcing last-minute changes and stress.
02:24 – Nature of FedRAMP changeJason compares FedRAMP shifts to “big boulders” coming at you, not “mousy” tweaks — change is always disruptive and massive.
02:56 – Success despite chaosTeams (Paramify, Flock, Baker Tilly) pulled it together, got the package in on time, and landed among the first four 20X submissions posted publicly.
03:07 – The reality checkJason: not everything in FedRAMP is “dillydallying” — clients, deadlines, and bills make delivery non-negotiable.
03:13 – Official podcast kickoffKenny introduces the episode: Jason Oksenhendler (Baker Tilly, formerly Moss Adams), and Paramify’s “rising star” Isaac Teuscher.
04:01 – Jason’s career origin storyFrom news anchor ➝ IT tech writer ➝ into FedRAMP (starting around NIST 800-53 Rev 2).
05:40 – First FedRAMP assignmentJason recalls his boss handing him a paper: “Go do FedRAMP.” He walks through early JAB/ISSO processes, feedback loops, and working with Matt Goodrich and Ashley Mahan.
11:43 – Co-creating the FedRAMP High BaselineJason describes working with DoD’s Ron Rice to build the High Baseline from scratch.
13:00 – Early FedRAMP painMicrosoft Word &amp; Excel “hell,” endless regurgitated control statements, and why some CSPs made assessors want to “bang their heads on the desk.”
15:32 – “You could do a Seinfeld routine on this crap.”Jason on version control disasters and 600-page SSP reviews without track changes.
17:30 – Culture shock of changeReactions to FedRAMP 20X mirror the same resistance to earlier shifts — but it’s always been “do once, use many.”
20:00 – Continuous monitoring realityJason emphasizes executive buy-in as essential, recalling how ConMon and POA&amp;Ms separate prepared orgs from overwhelmed ones.
22:50 – FedRAMP rigor vs. other frameworksJason argues FedRAMP is among the toughest frameworks, on par with DoD IL4-6.
25:00 – 20X blows up the roadmapKenny calls 20X a “hand grenade” for Paramify’s product plans.
29:00 – Cross-team collaborationJason highlights how six strangers in a Slack channel worked seamlessly under pressure — “like a chocolate fountain.”
34:00 – 20X flexibility vs. rigorJason explains the challenge of balancing new freedoms with maintaining strong security.
38:00 – Scaling 20X &amp; future baselinesSpeculation about moderate and high 20X baselines and how CSPs will adapt.
46:00 –]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3756</itunes:duration>
                <itunes:episode>46</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#44 - Karen Laughton on FedRAMP 20X, AI, and the Future of Compliance</title>
        <itunes:title>#44 - Karen Laughton on FedRAMP 20X, AI, and the Future of Compliance</itunes:title>
        <link>https://Paramify.podbean.com/e/44-karen-laughton-on-fedramp-20x-ai-and-the-future-of-compliance/</link>
                    <comments>https://Paramify.podbean.com/e/44-karen-laughton-on-fedramp-20x-ai-and-the-future-of-compliance/#comments</comments>        <pubDate>Tue, 12 Aug 2025 11:54:55 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/8dab8535-6a0e-3787-9730-90d8ae7067cc</guid>
                                    <description><![CDATA[<p>In this episode of the Paramify Podcast, Karen Laughton, EVP of Advisory at Coalfire, joins Kenny Scott (CEO of Paramify) and Mike Schreiner to unpack the future of government cybersecurity and compliance modernization. From the hard realities of FedRAMP 20X to lessons learned from the early days of FSMA and CMMC confusion, this conversation pulls no punches.</p>
<p>Karen shares how she broke into cybersecurity via HR (and a saltine-fueled CISSP exam), why automation without strategy won’t scale, and what it's going to take to make 20X work at moderate and high baselines. If you're curious where compliance, automation, AI, and public sector modernization are headed—you’ll want to tune in.</p>
<p>⏱️ Timestamps:
00:00 – "Dang, we need to modernize our government" — Karen's IRS nightmare becomes a metaphor for digital transformation.</p>
<p>02:44 – Meet Karen Laughton: Coalfire EVP, community leader, and accidental cyber exec.</p>
<p>03:35 – Saltines, pregnancy, and passing the CISSP: Karen’s origin story in cyber.</p>
<p>08:01 – AC-7 and the mouse jiggler: when coarse-grained controls meet real-world demos.</p>
<p>10:03 – FedRAMP in the early days: the “marathon in flip-flops” era of inconsistent TR feedback.</p>
<p>13:01 – The worst documentation nitpicks Karen’s ever seen (IP addresses and diagram chaos).</p>
<p>14:46 – FedRAMP then vs. now: why decentralization could hurt even as risk-focus improves.</p>
<p>17:28 – What scaling 20X to moderate and high will actually require.</p>
<p>20:03 – Are we solving the right problem with KSIs? Recapping Coalfire's “automation of arrested development” blog.</p>
<p>23:08 – Why automation isn’t a silver bullet (and why it still needs humans).</p>
<p>24:57 – 3PAOs aren't going anywhere — and that’s not just job security talk.</p>
<p>26:15 – Andrej Karpathy, robot soccer, and the early innings of AI assurance.</p>
<p>29:30 – Why agencies aren’t lining up to sponsor FedRAMP 20X.</p>
<p>31:08 – How Coalfire responded to 20X: culture, planning, and Compliance Essentials.</p>
<p>33:41 – Leveraging Paramify to accelerate automation where it makes sense.</p>
<p>36:42 – Politics, acquisitions, and why automation hits limits in complex orgs.</p>
<p>37:27 – DoD, CMMC, and 20X: where things stand and why there’s still confusion.</p>
<p>41:01 – The case for CMMC enclaves (and why most orgs want to isolate the mess).</p>
<p>42:00 – Mentorship, career pivots, and embracing “knowing nothing” as a superpower.</p>
<p>47:58 – Why questions make you smarter — and why cybersecurity people love answering them.</p>
<p>50:00 – Why cybersecurity never gets boring (and feels like a family reunion at every conference).</p>
<p>50:59 – Wrap-up &amp; future part two tease.</p>
<p>
Learn more about Coalfire: https://coalfire.com/
Learn more about Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/</p>
<p>Learn more about Paramify: https://www.paramify.com/
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode of the Paramify Podcast, Karen Laughton, EVP of Advisory at Coalfire, joins Kenny Scott (CEO of Paramify) and Mike Schreiner to unpack the future of government cybersecurity and compliance modernization. From the hard realities of FedRAMP 20X to lessons learned from the early days of FSMA and CMMC confusion, this conversation pulls no punches.</p>
<p>Karen shares how she broke into cybersecurity via HR (and a saltine-fueled CISSP exam), why automation without strategy won’t scale, and what it's going to take to make 20X work at moderate and high baselines. If you're curious where compliance, automation, AI, and public sector modernization are headed—you’ll want to tune in.</p>
<p>⏱️ Timestamps:<br>
00:00 – "Dang, we need to modernize our government" — Karen's IRS nightmare becomes a metaphor for digital transformation.</p>
<p>02:44 – Meet Karen Laughton: Coalfire EVP, community leader, and accidental cyber exec.</p>
<p>03:35 – Saltines, pregnancy, and passing the CISSP: Karen’s origin story in cyber.</p>
<p>08:01 – AC-7 and the mouse jiggler: when coarse-grained controls meet real-world demos.</p>
<p>10:03 – FedRAMP in the early days: the “marathon in flip-flops” era of inconsistent TR feedback.</p>
<p>13:01 – The worst documentation nitpicks Karen’s ever seen (IP addresses and diagram chaos).</p>
<p>14:46 – FedRAMP then vs. now: why decentralization could hurt even as risk-focus improves.</p>
<p>17:28 – What scaling 20X to moderate and high will actually require.</p>
<p>20:03 – Are we solving the right problem with KSIs? Recapping Coalfire's “automation of arrested development” blog.</p>
<p>23:08 – Why automation isn’t a silver bullet (and why it still needs humans).</p>
<p>24:57 – 3PAOs aren't going anywhere — and that’s not just job security talk.</p>
<p>26:15 – Andrej Karpathy, robot soccer, and the early innings of AI assurance.</p>
<p>29:30 – Why agencies aren’t lining up to sponsor FedRAMP 20X.</p>
<p>31:08 – How Coalfire responded to 20X: culture, planning, and Compliance Essentials.</p>
<p>33:41 – Leveraging Paramify to accelerate automation where it makes sense.</p>
<p>36:42 – Politics, acquisitions, and why automation hits limits in complex orgs.</p>
<p>37:27 – DoD, CMMC, and 20X: where things stand and why there’s still confusion.</p>
<p>41:01 – The case for CMMC enclaves (and why most orgs want to isolate the mess).</p>
<p>42:00 – Mentorship, career pivots, and embracing “knowing nothing” as a superpower.</p>
<p>47:58 – Why questions make you smarter — and why cybersecurity people love answering them.</p>
<p>50:00 – Why cybersecurity never gets boring (and feels like a family reunion at every conference).</p>
<p>50:59 – Wrap-up &amp; future part two tease.</p>
<p><br>
Learn more about Coalfire: https://coalfire.com/<br>
Learn more about Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/</p>
<p>Learn more about Paramify: https://www.paramify.com/<br>
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/<br>
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/89egpuwxrjc5c2r4/coalfirepod.mp3" length="49413274" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of the Paramify Podcast, Karen Laughton, EVP of Advisory at Coalfire, joins Kenny Scott (CEO of Paramify) and Mike Schreiner to unpack the future of government cybersecurity and compliance modernization. From the hard realities of FedRAMP 20X to lessons learned from the early days of FSMA and CMMC confusion, this conversation pulls no punches.
Karen shares how she broke into cybersecurity via HR (and a saltine-fueled CISSP exam), why automation without strategy won’t scale, and what it's going to take to make 20X work at moderate and high baselines. If you're curious where compliance, automation, AI, and public sector modernization are headed—you’ll want to tune in.
⏱️ Timestamps:00:00 – "Dang, we need to modernize our government" — Karen's IRS nightmare becomes a metaphor for digital transformation.
02:44 – Meet Karen Laughton: Coalfire EVP, community leader, and accidental cyber exec.
03:35 – Saltines, pregnancy, and passing the CISSP: Karen’s origin story in cyber.
08:01 – AC-7 and the mouse jiggler: when coarse-grained controls meet real-world demos.
10:03 – FedRAMP in the early days: the “marathon in flip-flops” era of inconsistent TR feedback.
13:01 – The worst documentation nitpicks Karen’s ever seen (IP addresses and diagram chaos).
14:46 – FedRAMP then vs. now: why decentralization could hurt even as risk-focus improves.
17:28 – What scaling 20X to moderate and high will actually require.
20:03 – Are we solving the right problem with KSIs? Recapping Coalfire's “automation of arrested development” blog.
23:08 – Why automation isn’t a silver bullet (and why it still needs humans).
24:57 – 3PAOs aren't going anywhere — and that’s not just job security talk.
26:15 – Andrej Karpathy, robot soccer, and the early innings of AI assurance.
29:30 – Why agencies aren’t lining up to sponsor FedRAMP 20X.
31:08 – How Coalfire responded to 20X: culture, planning, and Compliance Essentials.
33:41 – Leveraging Paramify to accelerate automation where it makes sense.
36:42 – Politics, acquisitions, and why automation hits limits in complex orgs.
37:27 – DoD, CMMC, and 20X: where things stand and why there’s still confusion.
41:01 – The case for CMMC enclaves (and why most orgs want to isolate the mess).
42:00 – Mentorship, career pivots, and embracing “knowing nothing” as a superpower.
47:58 – Why questions make you smarter — and why cybersecurity people love answering them.
50:00 – Why cybersecurity never gets boring (and feels like a family reunion at every conference).
50:59 – Wrap-up &amp; future part two tease.
Learn more about Coalfire: https://coalfire.com/Learn more about Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/
Learn more about Paramify: https://www.paramify.com/Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3088</itunes:duration>
                <itunes:episode>45</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>FedRAMP 20X Roundtable with FedRAMP Director Pete Waterman</title>
        <itunes:title>FedRAMP 20X Roundtable with FedRAMP Director Pete Waterman</itunes:title>
        <link>https://Paramify.podbean.com/e/fedramp-20x-roundtable-with-fedramp-director-pete-waterman/</link>
                    <comments>https://Paramify.podbean.com/e/fedramp-20x-roundtable-with-fedramp-director-pete-waterman/#comments</comments>        <pubDate>Thu, 17 Jul 2025 10:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/81817cdf-369d-350a-aec7-a3017844ddb9</guid>
                                    <description><![CDATA[<p>It’s not only about faster authorizations—it’s about unlocking the full potential of modern cloud for government.</p>
<p>FedRAMP 20X is how we get there.</p>
<p>In this exclusive roundtable, Pete Waterman (FedRAMP Director), Karen Laughton (EVP of Advisory, CoalFire), Rob Otten (Sr. Director, Risk &amp; Compliance, Flock Safety), Kenny Scott (Founder &amp; CEO, Paramify), and Mike Schreiner (COO, Paramify) break down:</p>
<p>- The mission, process &amp; real impact of the 20X pilot</p>
<p>- How Key Security Indicators (KSIs) make compliance faster &amp; smarter</p>
<p>- What Continuous ATO looks like in practice</p>
<p>- Why agencies are holding the line—and what they actually want</p>
<p>- The bold vision to transform FedRAMP from 50 authorizations a year… to 50 a week</p>
<p>Timestamps:
0:00 – The Big Question
Pete Waterman shares the spark: “What if we did 50 FedRAMP authorizations a week?”</p>
<p>1:56 – Welcome &amp; Introductions
Meet the panel: Pete Waterman, Karen Laughton, Rob Upton, Kenny Scott.</p>
<p>2:53 – Pilot Progress Update
Pete dives into pilot metrics, early submissions, and success stories.</p>
<p>5:17 – Industry Perspective: CoalFire
Karen Laughton shares lessons learned from advising CSPs and 3PAOs.</p>
<p>8:40 – CSP Perspective: Flock Safety + Paramify
Rob &amp; Kenny reveal how they rapidly pivoted into the pilot and delivered results in 2 weeks.</p>
<p>12:03 – Why It Worked
Why KSIs resonated and how automation made it achievable.</p>
<p>14:22 – The Risk-Based Shift
Security is about risk, not checklists. Kenny, Rob, and Pete riff on the deeper mindset change.</p>
<p>17:06 – ATO vs Authorization
Pete clarifies the difference and why 20X is fixing the current barriers.</p>
<p>19:02 – The Good, The Bad, and the Fast
Karen details what’s working well—and what’s still a mess (agency sponsorship, complex systems, DoD holdouts).</p>
<p>24:04 – Rob's Advice to CSPs
Rob advocates a risk-first approach and common sense improvements.</p>
<p>25:48 – Breaking Outdated Rules
Kenny rants about FIPS encryption requirements and why 20X could fix it.</p>
<p>27:07 – Agency Buy-In: Will They Accept 20X?
Pete confirms: Yes. OMB and formal policy will mandate adoption.</p>
<p>36:40 – Continuous ATO in Practice
What’s working, what’s confusing, and what the FedRAMP team is learning.</p>
<p>42:00 – The Integration Trap
Kenny explains why black-box integrations don’t cut it—and what CSPs must do instead.</p>
<p>44:55 – End User Risk Responsibilities
A critical callout: security breaches are often misconfigurations by users—not tech failures.</p>
<p>47:00 – Monitoring What Actually Matters
Forget CVEs. Pete &amp; Karen emphasize real-time config validation (e.g., MFA being disabled).</p>
<p>50:00 – Change Processes &amp; CI/CD
How continuous snapshots and CICD can coexist with security—without slowing innovation.</p>
<p>56:00 – Driving Innovation Through Standards
Why 20X exists: to force the ecosystem to build what’s long been talked about but never delivered.</p>
<p>1:00:00 – Final Advice to CSPs
Should you jump into 20X? Panelists give concrete guidance for startups, hyperscalers, and advisors.</p>
<p>1:06:04 – Reframing the Goal
Pete closes with a powerful vision: delivering equal access to secure cloud tech for federal workers—faster, better, and at scale.</p>
<p>Learn more about our guests: </p>
<p>Pete Waterman: https://www.linkedin.com/in/petewaterman/
FedRAMP: https://www.fedramp.gov/</p>
<p>Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/
Coalfire: https://coalfire.com/</p>
<p>Rob Otten: https://www.linkedin.com/in/robertotten/ 
Flock Safety: https://www.flocksafety.com/</p>
<p>
Learn more about Paramify: 
Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/
Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/
Paramify: www.paramify.com</p>
<p>Looking into FedRAMP or FedRAMP 20X? Lets' talk:  https://www.paramify.com/frameworks/fedramp</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>It’s not only about faster authorizations—it’s about unlocking the full potential of modern cloud for government.</p>
<p>FedRAMP 20X is how we get there.</p>
<p>In this exclusive roundtable, Pete Waterman (FedRAMP Director), Karen Laughton (EVP of Advisory, CoalFire), Rob Otten (Sr. Director, Risk &amp; Compliance, Flock Safety), Kenny Scott (Founder &amp; CEO, Paramify), and Mike Schreiner (COO, Paramify) break down:</p>
<p>- The mission, process &amp; real impact of the 20X pilot</p>
<p>- How Key Security Indicators (KSIs) make compliance faster &amp; smarter</p>
<p>- What Continuous ATO looks like in practice</p>
<p>- Why agencies are holding the line—and what they actually want</p>
<p>- The bold vision to transform FedRAMP from 50 authorizations a year… to 50 a week</p>
<p>Timestamps:<br>
0:00 – The Big Question<br>
Pete Waterman shares the spark: “What if we did 50 FedRAMP authorizations a week?”</p>
<p>1:56 – Welcome &amp; Introductions<br>
Meet the panel: Pete Waterman, Karen Laughton, Rob Upton, Kenny Scott.</p>
<p>2:53 – Pilot Progress Update<br>
Pete dives into pilot metrics, early submissions, and success stories.</p>
<p>5:17 – Industry Perspective: CoalFire<br>
Karen Laughton shares lessons learned from advising CSPs and 3PAOs.</p>
<p>8:40 – CSP Perspective: Flock Safety + Paramify<br>
Rob &amp; Kenny reveal how they rapidly pivoted into the pilot and delivered results in 2 weeks.</p>
<p>12:03 – Why It Worked<br>
Why KSIs resonated and how automation made it achievable.</p>
<p>14:22 – The Risk-Based Shift<br>
Security is about risk, not checklists. Kenny, Rob, and Pete riff on the deeper mindset change.</p>
<p>17:06 – ATO vs Authorization<br>
Pete clarifies the difference and why 20X is fixing the current barriers.</p>
<p>19:02 – The Good, The Bad, and the Fast<br>
Karen details what’s working well—and what’s still a mess (agency sponsorship, complex systems, DoD holdouts).</p>
<p>24:04 – Rob's Advice to CSPs<br>
Rob advocates a risk-first approach and common sense improvements.</p>
<p>25:48 – Breaking Outdated Rules<br>
Kenny rants about FIPS encryption requirements and why 20X could fix it.</p>
<p>27:07 – Agency Buy-In: Will They Accept 20X?<br>
Pete confirms: Yes. OMB and formal policy will mandate adoption.</p>
<p>36:40 – Continuous ATO in Practice<br>
What’s working, what’s confusing, and what the FedRAMP team is learning.</p>
<p>42:00 – The Integration Trap<br>
Kenny explains why black-box integrations don’t cut it—and what CSPs must do instead.</p>
<p>44:55 – End User Risk Responsibilities<br>
A critical callout: security breaches are often misconfigurations by users—not tech failures.</p>
<p>47:00 – Monitoring What Actually Matters<br>
Forget CVEs. Pete &amp; Karen emphasize real-time config validation (e.g., MFA being disabled).</p>
<p>50:00 – Change Processes &amp; CI/CD<br>
How continuous snapshots and CICD can coexist with security—without slowing innovation.</p>
<p>56:00 – Driving Innovation Through Standards<br>
Why 20X exists: to force the ecosystem to build what’s long been talked about but never delivered.</p>
<p>1:00:00 – Final Advice to CSPs<br>
Should you jump into 20X? Panelists give concrete guidance for startups, hyperscalers, and advisors.</p>
<p>1:06:04 – Reframing the Goal<br>
Pete closes with a powerful vision: delivering equal access to secure cloud tech for federal workers—faster, better, and at scale.</p>
<p>Learn more about our guests: </p>
<p>Pete Waterman: https://www.linkedin.com/in/petewaterman/<br>
FedRAMP: https://www.fedramp.gov/</p>
<p>Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/<br>
Coalfire: https://coalfire.com/</p>
<p>Rob Otten: https://www.linkedin.com/in/robertotten/ <br>
Flock Safety: https://www.flocksafety.com/</p>
<p><br>
Learn more about Paramify: <br>
Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/<br>
Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/<br>
Paramify: www.paramify.com</p>
<p>Looking into FedRAMP or FedRAMP 20X? Lets' talk:  https://www.paramify.com/frameworks/fedramp</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/m4ujv5amgajpazxu/FedRAMP_20x_roundtable_with_Pete_Waterman860de.mp3" length="70013228" type="audio/mpeg"/>
        <itunes:summary><![CDATA[It’s not only about faster authorizations—it’s about unlocking the full potential of modern cloud for government.
FedRAMP 20X is how we get there.
In this exclusive roundtable, Pete Waterman (FedRAMP Director), Karen Laughton (EVP of Advisory, CoalFire), Rob Otten (Sr. Director, Risk &amp; Compliance, Flock Safety), Kenny Scott (Founder &amp; CEO, Paramify), and Mike Schreiner (COO, Paramify) break down:
- The mission, process &amp; real impact of the 20X pilot
- How Key Security Indicators (KSIs) make compliance faster &amp; smarter
- What Continuous ATO looks like in practice
- Why agencies are holding the line—and what they actually want
- The bold vision to transform FedRAMP from 50 authorizations a year… to 50 a week
Timestamps:0:00 – The Big QuestionPete Waterman shares the spark: “What if we did 50 FedRAMP authorizations a week?”
1:56 – Welcome &amp; IntroductionsMeet the panel: Pete Waterman, Karen Laughton, Rob Upton, Kenny Scott.
2:53 – Pilot Progress UpdatePete dives into pilot metrics, early submissions, and success stories.
5:17 – Industry Perspective: CoalFireKaren Laughton shares lessons learned from advising CSPs and 3PAOs.
8:40 – CSP Perspective: Flock Safety + ParamifyRob &amp; Kenny reveal how they rapidly pivoted into the pilot and delivered results in 2 weeks.
12:03 – Why It WorkedWhy KSIs resonated and how automation made it achievable.
14:22 – The Risk-Based ShiftSecurity is about risk, not checklists. Kenny, Rob, and Pete riff on the deeper mindset change.
17:06 – ATO vs AuthorizationPete clarifies the difference and why 20X is fixing the current barriers.
19:02 – The Good, The Bad, and the FastKaren details what’s working well—and what’s still a mess (agency sponsorship, complex systems, DoD holdouts).
24:04 – Rob's Advice to CSPsRob advocates a risk-first approach and common sense improvements.
25:48 – Breaking Outdated RulesKenny rants about FIPS encryption requirements and why 20X could fix it.
27:07 – Agency Buy-In: Will They Accept 20X?Pete confirms: Yes. OMB and formal policy will mandate adoption.
36:40 – Continuous ATO in PracticeWhat’s working, what’s confusing, and what the FedRAMP team is learning.
42:00 – The Integration TrapKenny explains why black-box integrations don’t cut it—and what CSPs must do instead.
44:55 – End User Risk ResponsibilitiesA critical callout: security breaches are often misconfigurations by users—not tech failures.
47:00 – Monitoring What Actually MattersForget CVEs. Pete &amp; Karen emphasize real-time config validation (e.g., MFA being disabled).
50:00 – Change Processes &amp; CI/CDHow continuous snapshots and CICD can coexist with security—without slowing innovation.
56:00 – Driving Innovation Through StandardsWhy 20X exists: to force the ecosystem to build what’s long been talked about but never delivered.
1:00:00 – Final Advice to CSPsShould you jump into 20X? Panelists give concrete guidance for startups, hyperscalers, and advisors.
1:06:04 – Reframing the GoalPete closes with a powerful vision: delivering equal access to secure cloud tech for federal workers—faster, better, and at scale.
Learn more about our guests: 
Pete Waterman: https://www.linkedin.com/in/petewaterman/FedRAMP: https://www.fedramp.gov/
Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/Coalfire: https://coalfire.com/
Rob Otten: https://www.linkedin.com/in/robertotten/ Flock Safety: https://www.flocksafety.com/
Learn more about Paramify: Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/Paramify: www.paramify.com
Looking into FedRAMP or FedRAMP 20X? Lets' talk:  https://www.paramify.com/frameworks/fedramp]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4375</itunes:duration>
                <itunes:episode>44</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#43 - Martin Rieger on FedRAMP 20X, The Future of FedRAMP Compliance, Cloud, and Security</title>
        <itunes:title>#43 - Martin Rieger on FedRAMP 20X, The Future of FedRAMP Compliance, Cloud, and Security</itunes:title>
        <link>https://Paramify.podbean.com/e/43-martin-rieger-on-fedramp-20x-the-future-of-fedramp-compliance-cloud-and-security/</link>
                    <comments>https://Paramify.podbean.com/e/43-martin-rieger-on-fedramp-20x-the-future-of-fedramp-compliance-cloud-and-security/#comments</comments>        <pubDate>Mon, 12 May 2025 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/9b208823-7d5c-3698-97c4-76890b3e0879</guid>
                                    <description><![CDATA[<p>Today, we’re sitting down with StackArmor’s Martin Rieger — a FedRAMP veteran with over 300 engagements under his belt — for an unfiltered deep dive into the origin, evolution, and future of FedRAMP compliance.</p>
<p>We cover everything from the early days of DIACAP and gold images to today’s world of automation, OSCAL, and AI-powered documentation. Martin shares war stories, explains why so many companies fail audits even with AI, and gives his take on where FedRAMP 20x is headed.</p>
<p>Key takeaways
- AI can't replace expertise: Using ChatGPT (or any AI) to generate FedRAMP documentation without human validation leads to failure—AI is a tool, not a replacement for expertise.</p>
<p>- Right tools + right people = success: AI and automation can massively accelerate compliance work if handled by professionals who understand the frameworks deeply.</p>
<p>- FedRAMP’s evolution: FedRAMP has matured from infrastructure-heavy beginnings to a focus on SaaS and cloud-native tools, with an increasing push toward automation and standards like OSCAL.</p>
<p>- Common ATO pitfalls: Many companies underestimate the effort required for continuous monitoring (ConMon) and maintaining their ATO, mistakenly thinking the hardest part is getting authorized.</p>
<p>- Martin: FedRAMP may move toward sponsor-less paths (like StateRAMP) for Low/Moderate baselines, and AI + OSCAL will likely reshape how security packages are created, validated, and shared.</p>
<p>This episode is loaded with insights for anyone serious about federal cloud compliance.</p>
<p>⏱️ Timestamps:
04:10 – Martin’s early FedRAMP journey &amp; Navy background
10:00 – DIACAP, early tools, and Excel-era compliance
16:35 – How Kenny and Martin met (NIST OSCAL event story)
25:00 – StackArmor’s shift from golden images to modern cloud
35:00 – The problem with AI-generated SSPs
43:30 – POAMs, audit problems, and compliance documentation
49:45 – FISMA vs. FedRAMP, ‘FISRamp’, and ATO inefficiencies
56:40 – Predictions: FedRAMP 20x, agency sponsorship &amp; PMO
1:02:20 – The future of FedRAMP automation &amp; OSCAL + AI</p>
<p>🔗 Learn more about StackArmor: https://stackarmor.com/
👤Learn more about Martin Rieger: https://www.linkedin.com/in/martinrieger/</p>
<p>🔗 Learn more about Paramify: https://www.paramify.com/?utm_medium=social
👤 Connect with Kenny: Kenny G. Scott: / https://www.linkedin.com/in/kenny-g-scott/
👤 Connect with Mike: Mike Schreiner:  / https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we’re sitting down with StackArmor’s Martin Rieger — a FedRAMP veteran with over 300 engagements under his belt — for an unfiltered deep dive into the origin, evolution, and future of FedRAMP compliance.</p>
<p>We cover everything from the early days of DIACAP and gold images to today’s world of automation, OSCAL, and AI-powered documentation. Martin shares war stories, explains why so many companies fail audits even with AI, and gives his take on where FedRAMP 20x is headed.</p>
<p>Key takeaways<br>
- AI can't replace expertise: Using ChatGPT (or any AI) to generate FedRAMP documentation without human validation leads to failure—AI is a tool, not a replacement for expertise.</p>
<p>- Right tools + right people = success: AI and automation can massively accelerate compliance work if handled by professionals who understand the frameworks deeply.</p>
<p>- FedRAMP’s evolution: FedRAMP has matured from infrastructure-heavy beginnings to a focus on SaaS and cloud-native tools, with an increasing push toward automation and standards like OSCAL.</p>
<p>- Common ATO pitfalls: Many companies underestimate the effort required for continuous monitoring (ConMon) and maintaining their ATO, mistakenly thinking the hardest part is getting authorized.</p>
<p>- Martin: FedRAMP may move toward sponsor-less paths (like StateRAMP) for Low/Moderate baselines, and AI + OSCAL will likely reshape how security packages are created, validated, and shared.</p>
<p>This episode is loaded with insights for anyone serious about federal cloud compliance.</p>
<p>⏱️ Timestamps:<br>
04:10 – Martin’s early FedRAMP journey &amp; Navy background<br>
10:00 – DIACAP, early tools, and Excel-era compliance<br>
16:35 – How Kenny and Martin met (NIST OSCAL event story)<br>
25:00 – StackArmor’s shift from golden images to modern cloud<br>
35:00 – The problem with AI-generated SSPs<br>
43:30 – POAMs, audit problems, and compliance documentation<br>
49:45 – FISMA vs. FedRAMP, ‘FISRamp’, and ATO inefficiencies<br>
56:40 – Predictions: FedRAMP 20x, agency sponsorship &amp; PMO<br>
1:02:20 – The future of FedRAMP automation &amp; OSCAL + AI</p>
<p>🔗 Learn more about StackArmor: https://stackarmor.com/<br>
👤Learn more about Martin Rieger: https://www.linkedin.com/in/martinrieger/</p>
<p>🔗 Learn more about Paramify: https://www.paramify.com/?utm_medium=social<br>
👤 Connect with Kenny: Kenny G. Scott: / https://www.linkedin.com/in/kenny-g-scott/<br>
👤 Connect with Mike: Mike Schreiner:  / https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ywqhi8puhfiug2eb/Martin_podcast9l8zk.mp3" length="63059223" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we’re sitting down with StackArmor’s Martin Rieger — a FedRAMP veteran with over 300 engagements under his belt — for an unfiltered deep dive into the origin, evolution, and future of FedRAMP compliance.
We cover everything from the early days of DIACAP and gold images to today’s world of automation, OSCAL, and AI-powered documentation. Martin shares war stories, explains why so many companies fail audits even with AI, and gives his take on where FedRAMP 20x is headed.
Key takeaways- AI can't replace expertise: Using ChatGPT (or any AI) to generate FedRAMP documentation without human validation leads to failure—AI is a tool, not a replacement for expertise.
- Right tools + right people = success: AI and automation can massively accelerate compliance work if handled by professionals who understand the frameworks deeply.
- FedRAMP’s evolution: FedRAMP has matured from infrastructure-heavy beginnings to a focus on SaaS and cloud-native tools, with an increasing push toward automation and standards like OSCAL.
- Common ATO pitfalls: Many companies underestimate the effort required for continuous monitoring (ConMon) and maintaining their ATO, mistakenly thinking the hardest part is getting authorized.
- Martin: FedRAMP may move toward sponsor-less paths (like StateRAMP) for Low/Moderate baselines, and AI + OSCAL will likely reshape how security packages are created, validated, and shared.
This episode is loaded with insights for anyone serious about federal cloud compliance.
⏱️ Timestamps:04:10 – Martin’s early FedRAMP journey &amp; Navy background10:00 – DIACAP, early tools, and Excel-era compliance16:35 – How Kenny and Martin met (NIST OSCAL event story)25:00 – StackArmor’s shift from golden images to modern cloud35:00 – The problem with AI-generated SSPs43:30 – POAMs, audit problems, and compliance documentation49:45 – FISMA vs. FedRAMP, ‘FISRamp’, and ATO inefficiencies56:40 – Predictions: FedRAMP 20x, agency sponsorship &amp; PMO1:02:20 – The future of FedRAMP automation &amp; OSCAL + AI
🔗 Learn more about StackArmor: https://stackarmor.com/👤Learn more about Martin Rieger: https://www.linkedin.com/in/martinrieger/
🔗 Learn more about Paramify: https://www.paramify.com/?utm_medium=social👤 Connect with Kenny: Kenny G. Scott: / https://www.linkedin.com/in/kenny-g-scott/👤 Connect with Mike: Mike Schreiner:  / https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3941</itunes:duration>
                <itunes:episode>43</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#42 - FedRAMP 20x and The Creation of FedRAMP with Dave Fairburn Jr.</title>
        <itunes:title>#42 - FedRAMP 20x and The Creation of FedRAMP with Dave Fairburn Jr.</itunes:title>
        <link>https://Paramify.podbean.com/e/42-fedramp-20x-and-the-creation-of-fedramp-with-dave-fairburn-jr/</link>
                    <comments>https://Paramify.podbean.com/e/42-fedramp-20x-and-the-creation-of-fedramp-with-dave-fairburn-jr/#comments</comments>        <pubDate>Tue, 15 Apr 2025 13:54:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/c883c99f-8104-3774-846a-c46285eadb9c</guid>
                                    <description><![CDATA[<p>Today we're sitting down with the Father of FedRAMP himself — Dave Fairburn Jr. — for a raw, detailed, and at times hilarious deep dive into the origin story, evolution, and future of the FedRAMP program. From 16-hour days and bureaucracy battles to 2,500-page documentation drafts reduced by weight tests (yes, really), Dave walks us through how the entire FedRAMP framework was created, challenged, and still, nearly 15 years later, hasn’t been "screwed up" (his words). This episode is packed with insider stories, lessons learned, and real talk about: </p>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>Why the original FedRAMP design was JAB-only (no agency ATOs) </li>
</ul>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>How 3PAOs came to be — and the concern about quality today </li>
</ul>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>Why the “paperwork exercise” argument drives Dave crazy </li>
<li>What Dave thinks about FedRAMP 20x, AI, OSCAL, automation, and PMO changes</li>
<li>Predictions about what will (and won’t) change in the next 10 years</li>
</ul>
<p>Learn more about Dave Fairburn Jr.: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFpPTW1iMmU1eTd4UnNTSEhnZ0ZrS3Y4cmJqUXxBQ3Jtc0trN2d1dGpBT1d2Sl9jSXB0M3NrTDJjclAyWWdvY2NtUk85c0F2VHJNLS1uRHZNXzZQWUpzQ2ZZWWp0TjB1NV9ocGsySUR6U3RWU0Z0M2lkeUJIbFZ5dUg3NFBRdFA5aFYtb2RDbU9xVUoyVTRUNHJPMA&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2F%25E2%2598%2581%25EF%25B8%258F-dave-fairburn-jr-cissp-%25E2%2580%259Cfather-of-fedramp-93b87717%2F&amp;v=imy7zV7tCbc'>  / %e2%98%81%ef%b8%8f-dave-fairburn-jr-cissp-...  </a> 🔗 Learn more about Paramify: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbUUxVWNmN3BEc1kybDZDeWV5MzFkdnFZbG1yZ3xBQ3Jtc0tsN05YcFJlOC1EVWQ4b2FoTG4xaVdhV21lX0FwbjJ0bDEwanhvSjgyUGRwM0FrOVpZdjRnbk10T3M3bEoxb29PR3VUZ1ZlVUw3Q1lVbjZPUzA0ZnN4amFNQzFoX21zdEp3TS1fVTNlU0xwaHlETFVRTQ&amp;q=https%3A%2F%2Fwww.paramify.com%2F%3Futm_medium%3Dsocial&amp;v=imy7zV7tCbc'>https://www.paramify.com/?utm_medium=...</a> 👤 Connect with Kenny: Kenny G. Scott: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbURWblE1eGF6RVBqNFRNbnlXTTU3Y1RBQ3ZWZ3xBQ3Jtc0trYU5LcHFMQ3ZBRVJyV2htM0pNWFBUVkxxR3BhalZUSEZ0TVZ6NERWLWpIMWt6VUVvbk45WnlPYVpacVJQRW9UNXRyS0hzX3J1MFRtV0RmaHNaZUdYLXdLMDJqM1BHaEhKWTFvbWNoUkluNGZjRk1xZw&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fkenny-g-scott%2F&amp;v=imy7zV7tCbc'>  / kenny-g-scott  </a> 👤 Connect with Mike: Mike Schreiner: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFN4Rk84YmdjdDFfdkp3SU1iZUtlNWstQ01jQXxBQ3Jtc0ttU3FSb3dFdGxvNi1JaDBiaG1na1ZTZ3Iybzh3UWp4YkI4dkpZVHlvcXdROS1fTkwycjZyU2l3d2hFdXFTLU1XdlEzQks4azdPbWRzVi1yeTJ5NC1XZzRWWG5IbXdUR3FSSlVsZlNRUkRIMEVYOHZ5bw&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fmikecschreiner%2F&amp;v=imy7zV7tCbc'>  / mikecschreiner  </a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we're sitting down with the Father of FedRAMP himself — Dave Fairburn Jr. — for a raw, detailed, and at times hilarious deep dive into the origin story, evolution, and future of the FedRAMP program. From 16-hour days and bureaucracy battles to 2,500-page documentation drafts reduced by weight tests (yes, really), Dave walks us through how the entire FedRAMP framework was created, challenged, and still, nearly 15 years later, hasn’t been "screwed up" (his words). This episode is packed with insider stories, lessons learned, and real talk about: </p>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>Why the original FedRAMP design was JAB-only (no agency ATOs) </li>
</ul>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>How 3PAOs came to be — and the concern about quality today </li>
</ul>
<ul class="yt-core-attributed-string__list-group" dir="ltr">
<li>Why the “paperwork exercise” argument drives Dave crazy </li>
<li>What Dave thinks about FedRAMP 20x, AI, OSCAL, automation, and PMO changes</li>
<li>Predictions about what will (and won’t) change in the next 10 years</li>
</ul>
<p>Learn more about Dave Fairburn Jr.: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFpPTW1iMmU1eTd4UnNTSEhnZ0ZrS3Y4cmJqUXxBQ3Jtc0trN2d1dGpBT1d2Sl9jSXB0M3NrTDJjclAyWWdvY2NtUk85c0F2VHJNLS1uRHZNXzZQWUpzQ2ZZWWp0TjB1NV9ocGsySUR6U3RWU0Z0M2lkeUJIbFZ5dUg3NFBRdFA5aFYtb2RDbU9xVUoyVTRUNHJPMA&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2F%25E2%2598%2581%25EF%25B8%258F-dave-fairburn-jr-cissp-%25E2%2580%259Cfather-of-fedramp-93b87717%2F&amp;v=imy7zV7tCbc'>  / %e2%98%81%ef%b8%8f-dave-fairburn-jr-cissp-...  </a> 🔗 Learn more about Paramify: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbUUxVWNmN3BEc1kybDZDeWV5MzFkdnFZbG1yZ3xBQ3Jtc0tsN05YcFJlOC1EVWQ4b2FoTG4xaVdhV21lX0FwbjJ0bDEwanhvSjgyUGRwM0FrOVpZdjRnbk10T3M3bEoxb29PR3VUZ1ZlVUw3Q1lVbjZPUzA0ZnN4amFNQzFoX21zdEp3TS1fVTNlU0xwaHlETFVRTQ&amp;q=https%3A%2F%2Fwww.paramify.com%2F%3Futm_medium%3Dsocial&amp;v=imy7zV7tCbc'>https://www.paramify.com/?utm_medium=...</a> 👤 Connect with Kenny: Kenny G. Scott: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbURWblE1eGF6RVBqNFRNbnlXTTU3Y1RBQ3ZWZ3xBQ3Jtc0trYU5LcHFMQ3ZBRVJyV2htM0pNWFBUVkxxR3BhalZUSEZ0TVZ6NERWLWpIMWt6VUVvbk45WnlPYVpacVJQRW9UNXRyS0hzX3J1MFRtV0RmaHNaZUdYLXdLMDJqM1BHaEhKWTFvbWNoUkluNGZjRk1xZw&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fkenny-g-scott%2F&amp;v=imy7zV7tCbc'>  / kenny-g-scott  </a> 👤 Connect with Mike: Mike Schreiner: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFN4Rk84YmdjdDFfdkp3SU1iZUtlNWstQ01jQXxBQ3Jtc0ttU3FSb3dFdGxvNi1JaDBiaG1na1ZTZ3Iybzh3UWp4YkI4dkpZVHlvcXdROS1fTkwycjZyU2l3d2hFdXFTLU1XdlEzQks4azdPbWRzVi1yeTJ5NC1XZzRWWG5IbXdUR3FSSlVsZlNRUkRIMEVYOHZ5bw&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fmikecschreiner%2F&amp;v=imy7zV7tCbc'>  / mikecschreiner  </a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dutgt6wnpgquz99j/0415_1_bi16e.mp3" length="62113800" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we're sitting down with the Father of FedRAMP himself — Dave Fairburn Jr. — for a raw, detailed, and at times hilarious deep dive into the origin story, evolution, and future of the FedRAMP program. From 16-hour days and bureaucracy battles to 2,500-page documentation drafts reduced by weight tests (yes, really), Dave walks us through how the entire FedRAMP framework was created, challenged, and still, nearly 15 years later, hasn’t been "screwed up" (his words). This episode is packed with insider stories, lessons learned, and real talk about: 

Why the original FedRAMP design was JAB-only (no agency ATOs) 


How 3PAOs came to be — and the concern about quality today 


Why the “paperwork exercise” argument drives Dave crazy 
What Dave thinks about FedRAMP 20x, AI, OSCAL, automation, and PMO changes
Predictions about what will (and won’t) change in the next 10 years

Learn more about Dave Fairburn Jr.:   / %e2%98%81%ef%b8%8f-dave-fairburn-jr-cissp-...   🔗 Learn more about Paramify: https://www.paramify.com/?utm_medium=... 👤 Connect with Kenny: Kenny G. Scott:   / kenny-g-scott   👤 Connect with Mike: Mike Schreiner:   / mikecschreiner  ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3882</itunes:duration>
                <itunes:episode>42</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#41 - Discussing FedRAMP 20x</title>
        <itunes:title>#41 - Discussing FedRAMP 20x</itunes:title>
        <link>https://Paramify.podbean.com/e/41-discussing-fedramp-20x/</link>
                    <comments>https://Paramify.podbean.com/e/41-discussing-fedramp-20x/#comments</comments>        <pubDate>Mon, 31 Mar 2025 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/21af8109-20b5-3d98-9b5b-e196d48ca773</guid>
                                    <description><![CDATA[<p>What do DC sneakers, HR-approved marriage advice, and compliance robots have in common? They’re all part of this episode as Kenny and Mike dive into the bold future of FedRAMP 20X — and why it’s finally time to fix the pain points for both private companies and government agencies.</p>
<p>Here’s what they cover:</p>
<p>- The (not) shift in risk ownership — why agencies have always owned the risk and the PMO will focus on standards</p>
<p>- The myth of "set-it-and-forget-it" security — and the need for continuous monitoring</p>
<p>- The problem with screenshot audits — and smarter ways to prove assurance</p>
<p>- The role of auditors vs. automation — balancing trust and verification</p>
<p>- Why developers don’t love security — and how to make it less painful</p>
<p>- The future for faster authorizations, and why you shouldn't wait for the FedRAMP changes to happen to get FedRAMP Authorized.</p>
<p>If you’ve ever yelled at your SSP or cried over a screenshot audit, this one’s for you.</p>
<p>Sign up for the FedRAMP working groups here:
https://www.fedramp.gov/20x/working-groups/</p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What do DC sneakers, HR-approved marriage advice, and compliance robots have in common? They’re all part of this episode as Kenny and Mike dive into the bold future of FedRAMP 20X — and why it’s finally time to fix the pain points for both private companies and government agencies.</p>
<p>Here’s what they cover:</p>
<p>- The (not) shift in risk ownership — why agencies have always owned the risk and the PMO will focus on standards</p>
<p>- The myth of "set-it-and-forget-it" security — and the need for continuous monitoring</p>
<p>- The problem with screenshot audits — and smarter ways to prove assurance</p>
<p>- The role of auditors vs. automation — balancing trust and verification</p>
<p>- Why developers don’t love security — and how to make it less painful</p>
<p>- The future for faster authorizations, and why you shouldn't wait for the FedRAMP changes to happen to get FedRAMP Authorized.</p>
<p>If you’ve ever yelled at your SSP or cried over a screenshot audit, this one’s for you.</p>
<p>Sign up for the FedRAMP working groups here:<br>
https://www.fedramp.gov/20x/working-groups/</p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/upsqer9qisdetqmi/FedRAMP_20X_AUDIO84k7h.mp3" length="31109611" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What do DC sneakers, HR-approved marriage advice, and compliance robots have in common? They’re all part of this episode as Kenny and Mike dive into the bold future of FedRAMP 20X — and why it’s finally time to fix the pain points for both private companies and government agencies.
Here’s what they cover:
- The (not) shift in risk ownership — why agencies have always owned the risk and the PMO will focus on standards
- The myth of "set-it-and-forget-it" security — and the need for continuous monitoring
- The problem with screenshot audits — and smarter ways to prove assurance
- The role of auditors vs. automation — balancing trust and verification
- Why developers don’t love security — and how to make it less painful
- The future for faster authorizations, and why you shouldn't wait for the FedRAMP changes to happen to get FedRAMP Authorized.
If you’ve ever yelled at your SSP or cried over a screenshot audit, this one’s for you.
Sign up for the FedRAMP working groups here:https://www.fedramp.gov/20x/working-groups/
Learn more about Paramify here: https://www.paramify.com/
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn about Mike: https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1919</itunes:duration>
                <itunes:episode>41</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#40 - Discussing FedRAMP with Pete Waterman</title>
        <itunes:title>#40 - Discussing FedRAMP with Pete Waterman</itunes:title>
        <link>https://Paramify.podbean.com/e/40-discussing-fedramp-with-pete-waterman/</link>
                    <comments>https://Paramify.podbean.com/e/40-discussing-fedramp-with-pete-waterman/#comments</comments>        <pubDate>Wed, 19 Mar 2025 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/eabe425b-8d26-396c-a9a9-dfa5b85e78f8</guid>
                                    <description><![CDATA[<p>Today, we're pretending it's August 24, 2024, as Kenny and Mike sit down with Pete Waterman to talk about his backstory and what inspired him to apply to become the new FedRAMP Director. </p>
<p>Spoiler alert: we discuss frustration, bureaucracy, and a wild career move. Also these things:</p>
<p>- Pete's Origin Story – Every hero has one.
- Government Tech: Why Is It So Hard? – Bureaucracy, risk, and the myth of FISMA jail.
- The Future of FedRAMP – Can it get faster? 
- Motorcycles &amp; Risk Management – How intercontinental motorcycle camping trips bring perspective.
- Compliance Theater - "Can I get a screenshot of that?"</p>
<p>This episode is equal parts insightful, hilarious, and maybe a little chaotic—just the way we like it.</p>
<p>Learn more about Pete Waterman: https://www.linkedin.com/in/petewaterman/</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we're pretending it's August 24, 2024, as Kenny and Mike sit down with Pete Waterman to talk about his backstory and what inspired him to apply to become the new FedRAMP Director. </p>
<p>Spoiler alert: we discuss frustration, bureaucracy, and a wild career move. Also these things:</p>
<p>- Pete's Origin Story – Every hero has one.<br>
- Government Tech: Why Is It So Hard? – Bureaucracy, risk, and the myth of FISMA jail.<br>
- The Future of FedRAMP – Can it get faster? <br>
- Motorcycles &amp; Risk Management – How intercontinental motorcycle camping trips bring perspective.<br>
- Compliance Theater - "Can I get a screenshot of that?"</p>
<p>This episode is equal parts insightful, hilarious, and maybe a little chaotic—just the way we like it.</p>
<p>Learn more about Pete Waterman: https://www.linkedin.com/in/petewaterman/</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2xaje4577n9jjduy/The_paramify_podcast_with_pete_waterman_doneb0se6.mp3" length="71785375" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we're pretending it's August 24, 2024, as Kenny and Mike sit down with Pete Waterman to talk about his backstory and what inspired him to apply to become the new FedRAMP Director. 
Spoiler alert: we discuss frustration, bureaucracy, and a wild career move. Also these things:
- Pete's Origin Story – Every hero has one.- Government Tech: Why Is It So Hard? – Bureaucracy, risk, and the myth of FISMA jail.- The Future of FedRAMP – Can it get faster? - Motorcycles &amp; Risk Management – How intercontinental motorcycle camping trips bring perspective.- Compliance Theater - "Can I get a screenshot of that?"
This episode is equal parts insightful, hilarious, and maybe a little chaotic—just the way we like it.
Learn more about Pete Waterman: https://www.linkedin.com/in/petewaterman/
Learn more about Paramify: https://www.paramify.com/
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4486</itunes:duration>
                <itunes:episode>40</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#39 - Discussing FedRAMP with Jason Ford</title>
        <itunes:title>#39 - Discussing FedRAMP with Jason Ford</itunes:title>
        <link>https://Paramify.podbean.com/e/39-discussing-fedramp-with-jason-ford/</link>
                    <comments>https://Paramify.podbean.com/e/39-discussing-fedramp-with-jason-ford/#comments</comments>        <pubDate>Mon, 03 Mar 2025 12:27:06 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/fe487f73-aa79-311a-8583-9320b991f9d7</guid>
                                    <description><![CDATA[<p>Today <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Kenny</a> and <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Mike</a> are talking to the one and only <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Jason Ford</a>, CEO &amp; Founder of <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Steel Patriot Partners</a>—a true FedRAMP guru who's been securing systems since digital transformation was still a baby. Jason shares his battle-tested strategies for navigating security audits, implementing encryption the right way, and avoiding common pitfalls that can delay your compliance efforts for months.</p>
<p> </p>
<p>Here's what we're tackling in this episode:</p>
<p>- "If You Can't Draw It, You Can't Secure It" – Why mapping your architecture is step one in cybersecurity.</p>
<p>- FedRAMP High vs. Moderate – Why enterprises (not just government) are demanding higher security standards.</p>
<p>- Encryption 101 – What's really required, and why some ciphers belong in the dumpster.</p>
<p>- Privileged Access Done Right – No more random one-off permissions for Jeff! Use roles, not regrets.</p>
<p>- The Future of Security Compliance – Automation, AI, and why FedRAMP is about to change everything.</p>
<p> </p>
<p>If you're serious about building a security-first organization, tackling FedRAMP without losing your mind, or just figuring out how to keep your systems locked down like a fortress, this episode is for you.</p>
<p> </p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p>Learn more about Steel Patriot Partners here: <a href='https://www.steelpatriotpartners.com/'>https://www.steelpatriotpartners.com/</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Kenny</a> and <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Mike</a> are talking to the one and only <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Jason Ford</a>, CEO &amp; Founder of <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Steel Patriot Partners</a>—a true FedRAMP guru who's been securing systems since digital transformation was still a baby. Jason shares his battle-tested strategies for navigating security audits, implementing encryption the right way, and avoiding common pitfalls that can delay your compliance efforts for months.</p>
<p> </p>
<p>Here's what we're tackling in this episode:</p>
<p>- "If You Can't Draw It, You Can't Secure It" – Why mapping your architecture is step one in cybersecurity.</p>
<p>- FedRAMP High vs. Moderate – Why enterprises (not just government) are demanding higher security standards.</p>
<p>- Encryption 101 – What's really required, and why some ciphers belong in the dumpster.</p>
<p>- Privileged Access Done Right – No more random one-off permissions for Jeff! Use roles, not regrets.</p>
<p>- The Future of Security Compliance – Automation, AI, and why FedRAMP is about to change everything.</p>
<p> </p>
<p>If you're serious about building a security-first organization, tackling FedRAMP without losing your mind, or just figuring out how to keep your systems locked down like a fortress, this episode is for you.</p>
<p> </p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p>Learn more about Steel Patriot Partners here: <a href='https://www.steelpatriotpartners.com/'>https://www.steelpatriotpartners.com/</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/32qy5njd2hmberd4/Jason_Ford_Audio_podbean_8ckq3.mp3" length="61966260" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today Kenny and Mike are talking to the one and only Jason Ford, CEO &amp; Founder of Steel Patriot Partners—a true FedRAMP guru who's been securing systems since digital transformation was still a baby. Jason shares his battle-tested strategies for navigating security audits, implementing encryption the right way, and avoiding common pitfalls that can delay your compliance efforts for months.
 
Here's what we're tackling in this episode:
- "If You Can't Draw It, You Can't Secure It" – Why mapping your architecture is step one in cybersecurity.
- FedRAMP High vs. Moderate – Why enterprises (not just government) are demanding higher security standards.
- Encryption 101 – What's really required, and why some ciphers belong in the dumpster.
- Privileged Access Done Right – No more random one-off permissions for Jeff! Use roles, not regrets.
- The Future of Security Compliance – Automation, AI, and why FedRAMP is about to change everything.
 
If you're serious about building a security-first organization, tackling FedRAMP without losing your mind, or just figuring out how to keep your systems locked down like a fortress, this episode is for you.
 
Learn more about Paramify here: https://www.paramify.com/
Learn more about Steel Patriot Partners here: https://www.steelpatriotpartners.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3872</itunes:duration>
                <itunes:episode>39</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#38 - Building a Great Security Program with Google Sheets</title>
        <itunes:title>#38 - Building a Great Security Program with Google Sheets</itunes:title>
        <link>https://Paramify.podbean.com/e/38-building-a-great-security-program-with-google-sheets/</link>
                    <comments>https://Paramify.podbean.com/e/38-building-a-great-security-program-with-google-sheets/#comments</comments>        <pubDate>Mon, 17 Feb 2025 13:04:15 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/ecf9a7ad-86e9-3991-a294-3226e0560021</guid>
                                    <description><![CDATA[<p>Getting started with risk management is easier than you think- and you don’t need fancy tools to do it.</p>
<p> </p>
<p>In this episode, <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Kenny</a> and <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Mike</a> break down how a simple Google Sheet can be your secret weapon for designing a great security program. Whether you’re navigating FedRAMP, SOC 2, or ISO 27001, the key is just getting started—no expensive software required.</p>
<p> </p>
<p>If you're a startup founder, security pro, or just compliance-curious, this episode is packed with easy, actionable steps to help you kick off your compliance journey—without breaking the bank.</p>
<p> </p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Getting started with risk management is easier than you think- and you don’t need fancy tools to do it.</p>
<p> </p>
<p>In this episode, <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Kenny</a> and <a href='https://www.linkedin.com/company/80788473/admin/page-posts/published/?share=true'>Mike</a> break down how a simple Google Sheet can be your secret weapon for designing a great security program. Whether you’re navigating FedRAMP, SOC 2, or ISO 27001, the key is just getting started—no expensive software required.</p>
<p> </p>
<p>If you're a startup founder, security pro, or just compliance-curious, this episode is packed with easy, actionable steps to help you kick off your compliance journey—without breaking the bank.</p>
<p> </p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
<p>Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/reqak69nx4nbgrar/audio_for_podagfrw.mp3" length="33330205" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Getting started with risk management is easier than you think- and you don’t need fancy tools to do it.
 
In this episode, Kenny and Mike break down how a simple Google Sheet can be your secret weapon for designing a great security program. Whether you’re navigating FedRAMP, SOC 2, or ISO 27001, the key is just getting started—no expensive software required.
 
If you're a startup founder, security pro, or just compliance-curious, this episode is packed with easy, actionable steps to help you kick off your compliance journey—without breaking the bank.
 
Learn more about Paramify: https://www.paramify.com/
Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2083</itunes:duration>
                <itunes:episode>38</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#37 - A Journey Into FedRAMP with Eric Britton Adams</title>
        <itunes:title>#37 - A Journey Into FedRAMP with Eric Britton Adams</itunes:title>
        <link>https://Paramify.podbean.com/e/37-a-journey-into-fedramp-with-eric-britton-adams/</link>
                    <comments>https://Paramify.podbean.com/e/37-a-journey-into-fedramp-with-eric-britton-adams/#comments</comments>        <pubDate>Mon, 03 Feb 2025 14:34:27 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/3635de0d-7ed1-3903-8c87-bfeff8a2a7ec</guid>
                                    <description><![CDATA[<p>Eric, the CISO at Federal Cyber Defense Solutions and former Chief FedRAMP Strategist at IBM and FedRAMP Leader at HP, shares his journey from growing up on a farm to becoming a CISO and FedRAMP expert. We dive into the challenges of FedRAMP compliance, the evolution of cybersecurity, and how today's security teams can strike the balance between technical expertise and meeting compliance demands.</p>
<p>In this episode, we cover:
- The real struggles of legacy tech and security controls
- How cybersecurity careers have evolved—then vs. now
- The shift toward security by design and the future of security operations
- Advice for new cybersecurity professionals on breaking into the industry</p>
<p>If you're interested in FedRAMP in 2025, compliance innovation, or cybersecurity career growth, this episode is a must-listen!</p>
<p>Learn more about Eric here: 
LinkedIn: https://www.linkedin.com/in/eadams2/</p>
<p>Learn more about Paramify: 
https://www.paramify.com/</p>
<p>Learn more about Kenny:  
Linkedin: https://www.linkedin.com/in/kenny-g-scott/</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Eric, the CISO at Federal Cyber Defense Solutions and former Chief FedRAMP Strategist at IBM and FedRAMP Leader at HP, shares his journey from growing up on a farm to becoming a CISO and FedRAMP expert. We dive into the challenges of FedRAMP compliance, the evolution of cybersecurity, and how today's security teams can strike the balance between technical expertise and meeting compliance demands.</p>
<p>In this episode, we cover:<br>
- The real struggles of legacy tech and security controls<br>
- How cybersecurity careers have evolved—then vs. now<br>
- The shift toward security by design and the future of security operations<br>
- Advice for new cybersecurity professionals on breaking into the industry</p>
<p>If you're interested in FedRAMP in 2025, compliance innovation, or cybersecurity career growth, this episode is a must-listen!</p>
<p>Learn more about Eric here: <br>
LinkedIn: https://www.linkedin.com/in/eadams2/</p>
<p>Learn more about Paramify: <br>
https://www.paramify.com/</p>
<p>Learn more about Kenny:  <br>
Linkedin: https://www.linkedin.com/in/kenny-g-scott/</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4ryxhqq963rw9a5d/ERic_Britton_Adams_podcastbh0r7.mp3" length="58309117" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Eric, the CISO at Federal Cyber Defense Solutions and former Chief FedRAMP Strategist at IBM and FedRAMP Leader at HP, shares his journey from growing up on a farm to becoming a CISO and FedRAMP expert. We dive into the challenges of FedRAMP compliance, the evolution of cybersecurity, and how today's security teams can strike the balance between technical expertise and meeting compliance demands.
In this episode, we cover:- The real struggles of legacy tech and security controls- How cybersecurity careers have evolved—then vs. now- The shift toward security by design and the future of security operations- Advice for new cybersecurity professionals on breaking into the industry
If you're interested in FedRAMP in 2025, compliance innovation, or cybersecurity career growth, this episode is a must-listen!
Learn more about Eric here: LinkedIn: https://www.linkedin.com/in/eadams2/
Learn more about Paramify: https://www.paramify.com/
Learn more about Kenny:  Linkedin: https://www.linkedin.com/in/kenny-g-scott/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3644</itunes:duration>
                <itunes:episode>37</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#36 - What are the Control Assessment Phases?</title>
        <itunes:title>#36 - What are the Control Assessment Phases?</itunes:title>
        <link>https://Paramify.podbean.com/e/36-what-are-the-control-assessment-phases/</link>
                    <comments>https://Paramify.podbean.com/e/36-what-are-the-control-assessment-phases/#comments</comments>        <pubDate>Tue, 21 Jan 2025 12:53:47 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/ffd25ccc-59f3-3a25-939d-d909a4817d57</guid>
                                    <description><![CDATA[<p>Whether you’re launching a brand-new security program or fine-tuning your existing one, this episode has everything you need to know.</p>
<p>Kenny and Mike are breaking down the 𝗰𝗼𝗻𝘁𝗿𝗼𝗹 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁 𝗽𝗵𝗮𝘀𝗲𝘀 – why they matter and how they can transform your security processes.</p>
<p>Here’s what’s on deck in this episode of The Paramify Podcast:
- How to plan your security framework so it’s rock-solid from the start.
- Common pitfalls in frameworks like FedRAMP (and how to avoid them, no trench runs required).
- The importance of boundaries, collaboration, and a digital-first approach.
- Real-world lessons (and Star Wars stories) for simplifying security challenges.</p>
<p>𝗟𝗶𝘀𝘁𝗲𝗻 𝗻𝗼𝘄 and learn how planning, assessing, and reporting can level up your risk management game.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Whether you’re launching a brand-new security program or fine-tuning your existing one, this episode has everything you need to know.</p>
<p>Kenny and Mike are breaking down the 𝗰𝗼𝗻𝘁𝗿𝗼𝗹 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁 𝗽𝗵𝗮𝘀𝗲𝘀 – why they matter and how they can transform your security processes.</p>
<p>Here’s what’s on deck in this episode of The Paramify Podcast:<br>
- How to plan your security framework so it’s rock-solid from the start.<br>
- Common pitfalls in frameworks like FedRAMP (and how to avoid them, no trench runs required).<br>
- The importance of boundaries, collaboration, and a digital-first approach.<br>
- Real-world lessons (and Star Wars stories) for simplifying security challenges.</p>
<p>𝗟𝗶𝘀𝘁𝗲𝗻 𝗻𝗼𝘄 and learn how planning, assessing, and reporting can level up your risk management game.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/whgemthyeeuvujnk/Podcast_Audio7ewbn.mp3" length="22002257" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Whether you’re launching a brand-new security program or fine-tuning your existing one, this episode has everything you need to know.
Kenny and Mike are breaking down the 𝗰𝗼𝗻𝘁𝗿𝗼𝗹 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁 𝗽𝗵𝗮𝘀𝗲𝘀 – why they matter and how they can transform your security processes.
Here’s what’s on deck in this episode of The Paramify Podcast:- How to plan your security framework so it’s rock-solid from the start.- Common pitfalls in frameworks like FedRAMP (and how to avoid them, no trench runs required).- The importance of boundaries, collaboration, and a digital-first approach.- Real-world lessons (and Star Wars stories) for simplifying security challenges.
𝗟𝗶𝘀𝘁𝗲𝗻 𝗻𝗼𝘄 and learn how planning, assessing, and reporting can level up your risk management game.]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1375</itunes:duration>
                <itunes:episode>36</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#35 - Risk Management Explained Through Star Wars</title>
        <itunes:title>#35 - Risk Management Explained Through Star Wars</itunes:title>
        <link>https://Paramify.podbean.com/e/35-risk-management-explained-through-star-wars/</link>
                    <comments>https://Paramify.podbean.com/e/35-risk-management-explained-through-star-wars/#comments</comments>        <pubDate>Mon, 06 Jan 2025 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d50f351a-bb40-3ee1-96b7-58966976f694</guid>
                                    <description><![CDATA[<p>We’ve heard you. We all want to know just how much it cost The Empire when the first Death Star was blown to oblivion by a young boy from Tatooine? How could the Empire let this happen?</p>
<p>Kenny Scott and Mike Schreiner dive deep into risk management and cybersecurity—all through the lens of Star Wars.</p>
<p>Kenny uses Star Wars analogies to break down key concepts like:
• 𝗔𝘀𝘀𝗲𝘁𝘀  (Death Stars)
• 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀  (Thermal Exhaust Ports)
• 𝗧𝗵𝗿𝗲𝗮𝘁𝘀 (X-wings)
• 𝗖𝗼𝗻𝘁𝗿𝗼𝗹𝘀 (Force fields, turrets, the Dark Side and Darth Vader)
• 𝗥𝗶𝘀𝗸 𝗧𝗿𝗲𝗮𝘁𝗺𝗲𝗻𝘁 𝗦𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗲𝘀:
     • 𝗠𝗶𝘁𝗶𝗴𝗮𝘁𝗲 all by yourself
     • 𝗦𝗵𝗮𝗿𝗲 risk like pizza
     • 𝗧𝗿𝗮𝗻𝘀𝗳𝗲𝗿 it to some do-gooder
     • 𝗔𝗰𝗰𝗲𝗽𝘁 the risk (aka, just flat out ignore it)
     • 𝗔𝘃𝗼𝗶𝗱 the risk it cuz you’re just too scared.</p>
<p>Whether you're looking to build a risk management program OR just geek out over Star Wars references, this episode has something for you.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We’ve heard you. We all want to know just how much it cost The Empire when the first Death Star was blown to oblivion by a young boy from Tatooine? How could the Empire let this happen?</p>
<p>Kenny Scott and Mike Schreiner dive deep into risk management and cybersecurity—all through the lens of Star Wars.</p>
<p>Kenny uses Star Wars analogies to break down key concepts like:<br>
• 𝗔𝘀𝘀𝗲𝘁𝘀  (Death Stars)<br>
• 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀  (Thermal Exhaust Ports)<br>
• 𝗧𝗵𝗿𝗲𝗮𝘁𝘀 (X-wings)<br>
• 𝗖𝗼𝗻𝘁𝗿𝗼𝗹𝘀 (Force fields, turrets, the Dark Side and Darth Vader)<br>
• 𝗥𝗶𝘀𝗸 𝗧𝗿𝗲𝗮𝘁𝗺𝗲𝗻𝘁 𝗦𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗲𝘀:<br>
     • 𝗠𝗶𝘁𝗶𝗴𝗮𝘁𝗲 all by yourself<br>
     • 𝗦𝗵𝗮𝗿𝗲 risk like pizza<br>
     • 𝗧𝗿𝗮𝗻𝘀𝗳𝗲𝗿 it to some do-gooder<br>
     • 𝗔𝗰𝗰𝗲𝗽𝘁 the risk (aka, just flat out ignore it)<br>
     • 𝗔𝘃𝗼𝗶𝗱 the risk it cuz you’re just too scared.</p>
<p>Whether you're looking to build a risk management program OR just geek out over Star Wars references, this episode has something for you.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/d9264xmv3vwcs9es/StarWars_Podcast_Audio62c5m.mp3" length="27479612" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We’ve heard you. We all want to know just how much it cost The Empire when the first Death Star was blown to oblivion by a young boy from Tatooine? How could the Empire let this happen?
Kenny Scott and Mike Schreiner dive deep into risk management and cybersecurity—all through the lens of Star Wars.
Kenny uses Star Wars analogies to break down key concepts like:• 𝗔𝘀𝘀𝗲𝘁𝘀  (Death Stars)• 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀  (Thermal Exhaust Ports)• 𝗧𝗵𝗿𝗲𝗮𝘁𝘀 (X-wings)• 𝗖𝗼𝗻𝘁𝗿𝗼𝗹𝘀 (Force fields, turrets, the Dark Side and Darth Vader)• 𝗥𝗶𝘀𝗸 𝗧𝗿𝗲𝗮𝘁𝗺𝗲𝗻𝘁 𝗦𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗲𝘀:     • 𝗠𝗶𝘁𝗶𝗴𝗮𝘁𝗲 all by yourself     • 𝗦𝗵𝗮𝗿𝗲 risk like pizza     • 𝗧𝗿𝗮𝗻𝘀𝗳𝗲𝗿 it to some do-gooder     • 𝗔𝗰𝗰𝗲𝗽𝘁 the risk (aka, just flat out ignore it)     • 𝗔𝘃𝗼𝗶𝗱 the risk it cuz you’re just too scared.
Whether you're looking to build a risk management program OR just geek out over Star Wars references, this episode has something for you.]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1717</itunes:duration>
                <itunes:episode>35</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#34 - Discussing CMMC with Tony Bai from RISCPoint</title>
        <itunes:title>#34 - Discussing CMMC with Tony Bai from RISCPoint</itunes:title>
        <link>https://Paramify.podbean.com/e/34-discussing-cmmc-with-tony-bai-from-riscpoint/</link>
                    <comments>https://Paramify.podbean.com/e/34-discussing-cmmc-with-tony-bai-from-riscpoint/#comments</comments>        <pubDate>Mon, 09 Dec 2024 10:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/040c223e-ec9d-390b-9b4d-6860102c8ff3</guid>
                                    <description><![CDATA[<p>Today we’re talking to Tony Bai. He’s got 25 years of experience in cyber defense and operations, Tony Bai serves as the Chief Solutions Officer at RISCPoint. A United States Air Force veteran and lots of leadership experience at leading consulting organizations. Tony specializes in FedRAMP, CMMC and other NIST frameworks and is a leading voice on their latest developments that seem to be pretty intense these days. This is a great episode!</p>
 
Learn more about Tony Bai:
https://www.linkedin.com/in/williamtbai/
 
Learn more about RISCPoint:
RISCPoint is an industry-leading management consulting firm, specializing in cybersecurity, compliance, and risk management, providing both strategy and tactical implementation. Our founding vision is a seamless integration with your team, focusing on creating impactful solutions to help you achieve your objectives.
https://www.riscpoint.com/ https://www.riscpoint.com/services/public-sector
https://www.riscpoint.com/contact
 


Learn more about Kenny Scott:
https://www.linkedin.com/in/kenny-g-scott/
 
Learn more about Paramify:
https://www.paramify.com/]]></description>
                                                            <content:encoded><![CDATA[<p>Today we’re talking to Tony Bai. He’s got 25 years of experience in cyber defense and operations, Tony Bai serves as the Chief Solutions Officer at RISCPoint. A United States Air Force veteran and lots of leadership experience at leading consulting organizations. Tony specializes in FedRAMP, CMMC and other NIST frameworks and is a leading voice on their latest developments that seem to be pretty intense these days. This is a great episode!</p>
 
Learn more about Tony Bai:
https://www.linkedin.com/in/williamtbai/
 
Learn more about RISCPoint:
RISCPoint is an industry-leading management consulting firm, specializing in cybersecurity, compliance, and risk management, providing both strategy and tactical implementation. Our founding vision is a seamless integration with your team, focusing on creating impactful solutions to help you achieve your objectives.
https://www.riscpoint.com/ https://www.riscpoint.com/services/public-sector
https://www.riscpoint.com/contact
 


Learn more about Kenny Scott:
https://www.linkedin.com/in/kenny-g-scott/
 
Learn more about Paramify:
https://www.paramify.com/]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/bpyijgem4dxn22fu/TONY_BAI_PODCAST7qknf.mp3" length="45368683" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we’re talking to Tony Bai. He’s got 25 years of experience in cyber defense and operations, Tony Bai serves as the Chief Solutions Officer at RISCPoint. A United States Air Force veteran and lots of leadership experience at leading consulting organizations. Tony specializes in FedRAMP, CMMC and other NIST frameworks and is a leading voice on their latest developments that seem to be pretty intense these days. This is a great episode!
 
Learn more about Tony Bai:
https://www.linkedin.com/in/williamtbai/
 
Learn more about RISCPoint:
RISCPoint is an industry-leading management consulting firm, specializing in cybersecurity, compliance, and risk management, providing both strategy and tactical implementation. Our founding vision is a seamless integration with your team, focusing on creating impactful solutions to help you achieve your objectives.
https://www.riscpoint.com/ https://www.riscpoint.com/services/public-sector
https://www.riscpoint.com/contact
 


Learn more about Kenny Scott:
https://www.linkedin.com/in/kenny-g-scott/
 
Learn more about Paramify:
https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2835</itunes:duration>
                <itunes:episode>34</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#33 - Discussing Cybersecurity with Mandy Andress CISO at Elastic</title>
        <itunes:title>#33 - Discussing Cybersecurity with Mandy Andress CISO at Elastic</itunes:title>
        <link>https://Paramify.podbean.com/e/33-grc-with-mandy-andress-ciso-at-elastic/</link>
                    <comments>https://Paramify.podbean.com/e/33-grc-with-mandy-andress-ciso-at-elastic/#comments</comments>        <pubDate>Mon, 25 Nov 2024 10:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/ec38b8eb-9686-36ba-9c61-ca701f12a05d</guid>
                                    <description><![CDATA[<p>We're talking with Mandy Andress, Chief Information Security Officer (CISO) at Elastic. Mandy is making a huge impact in the security industry as the author of Surviving Security: How to Integrate People, Process, and Technology, a Top 100 CISO (C100) Award recipient, and a LinkedIn Top Voice. Her leadership goes well beyond her role as CISO – she's also a trusted advisor to many organizations, a frequent speaker at global conferences like BlackHat and Networld + Interop, and a driving force behind Elastic's IPO success.</p>
<p>Learn more about Mandy Andress:
Mandy's Linkedin: https://www.linkedin.com/in/mandyandress/</p>
<p>Learn more about Elastic:
Elastic's Website: https://www.elastic.co/</p>
<p>Learn more about Kenny Scott:
Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify:
Paramify's website: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We're talking with Mandy Andress, Chief Information Security Officer (CISO) at Elastic. Mandy is making a huge impact in the security industry as the author of Surviving Security: How to Integrate People, Process, and Technology, a Top 100 CISO (C100) Award recipient, and a LinkedIn Top Voice. Her leadership goes well beyond her role as CISO – she's also a trusted advisor to many organizations, a frequent speaker at global conferences like BlackHat and Networld + Interop, and a driving force behind Elastic's IPO success.</p>
<p>Learn more about Mandy Andress:<br>
Mandy's Linkedin: https://www.linkedin.com/in/mandyandress/</p>
<p>Learn more about Elastic:<br>
Elastic's Website: https://www.elastic.co/</p>
<p>Learn more about Kenny Scott:<br>
Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify:<br>
Paramify's website: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9jgur9z9s9n89bzm/Mandy_Andress_Podcast_AUDIO_99hgc.mp3" length="40305107" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We're talking with Mandy Andress, Chief Information Security Officer (CISO) at Elastic. Mandy is making a huge impact in the security industry as the author of Surviving Security: How to Integrate People, Process, and Technology, a Top 100 CISO (C100) Award recipient, and a LinkedIn Top Voice. Her leadership goes well beyond her role as CISO – she's also a trusted advisor to many organizations, a frequent speaker at global conferences like BlackHat and Networld + Interop, and a driving force behind Elastic's IPO success.
Learn more about Mandy Andress:Mandy's Linkedin: https://www.linkedin.com/in/mandyandress/
Learn more about Elastic:Elastic's Website: https://www.elastic.co/
Learn more about Kenny Scott:Kenny's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Paramify:Paramify's website: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2519</itunes:duration>
                <itunes:episode>33</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#32 - Discussing FedRAMP with Michael Carter</title>
        <itunes:title>#32 - Discussing FedRAMP with Michael Carter</itunes:title>
        <link>https://Paramify.podbean.com/e/32-discussing-fedramp-with-michael-carter/</link>
                    <comments>https://Paramify.podbean.com/e/32-discussing-fedramp-with-michael-carter/#comments</comments>        <pubDate>Fri, 06 Sep 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/269a3bdd-537e-3bfb-bef6-aa836cd39589</guid>
                                    <description><![CDATA[<p>Today, we’re honored to have Michael Carter on the show! Michael is the Managing Partner and Co-founder of Fortreum. Michael brings over two decades of expertise in cybersecurity and compliance, specializing in FedRAMP, FISMA, PCI, and more. He has held key leadership roles at Coalfire and Veris Group, shaping compliance strategies for top organizations across both government and commercial sectors. Michael’s deep insights into security and risk management make him a leading voice in the industry.</p>
<p>Learn more about Michael Carter: / carte2ms</p>
<p>Learn more about Fortreum: <a href='https://fortreum.com/'>https://fortreum.com/ </a></p>
<p>Learn more about Kenny Scott: / kenny-g-scott</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we’re honored to have Michael Carter on the show! Michael is the Managing Partner and Co-founder of Fortreum. Michael brings over two decades of expertise in cybersecurity and compliance, specializing in FedRAMP, FISMA, PCI, and more. He has held key leadership roles at Coalfire and Veris Group, shaping compliance strategies for top organizations across both government and commercial sectors. Michael’s deep insights into security and risk management make him a leading voice in the industry.</p>
<p>Learn more about Michael Carter: / carte2ms</p>
<p>Learn more about Fortreum: <a href='https://fortreum.com/'>https://fortreum.com/ </a></p>
<p>Learn more about Kenny Scott: / kenny-g-scott</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ed2j6i8q4ca3scax/The_Paramify_Podcast_with_Michael_Carter_DONEDONEDakkqw.mp3" length="51954466" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we’re honored to have Michael Carter on the show! Michael is the Managing Partner and Co-founder of Fortreum. Michael brings over two decades of expertise in cybersecurity and compliance, specializing in FedRAMP, FISMA, PCI, and more. He has held key leadership roles at Coalfire and Veris Group, shaping compliance strategies for top organizations across both government and commercial sectors. Michael’s deep insights into security and risk management make him a leading voice in the industry.
Learn more about Michael Carter: / carte2ms
Learn more about Fortreum: https://fortreum.com/ 
Learn more about Kenny Scott: / kenny-g-scott
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3247</itunes:duration>
                <itunes:episode>32</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#31 - Discussing OSCAL and Cybersecurity with Alexander Stein</title>
        <itunes:title>#31 - Discussing OSCAL and Cybersecurity with Alexander Stein</itunes:title>
        <link>https://Paramify.podbean.com/e/31-discussing-oscal-and-cybersecurity-with-alexander-stein/</link>
                    <comments>https://Paramify.podbean.com/e/31-discussing-oscal-and-cybersecurity-with-alexander-stein/#comments</comments>        <pubDate>Fri, 23 Aug 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/160ef65f-d2e4-3bea-8a2c-7f300f213eea</guid>
                                    <description><![CDATA[<p>Today, we're honored to have Alexander Stein on the show. Alexander has a host of experience in Cybersecurity. He has worked as an IT Cybersecurity Specialist at the National Institute of Standards and Technology (NIST). With over two years at NIST focusing on Information Technology and Vulnerability Management, Alex has also held key roles at Flexion Inc. as a Security Practice Lead and Application Security Engineer,</p>
<p>and at BAM Technologies Learn more about Alexander Stein here: LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbHh6WWI4MDl5RUNGNFRzM2dieHQtdU5VNHlPZ3xBQ3Jtc0trTS1yLTB0WWllNVlOcy1Rb25abWJJYlBtMURDM0EyMzJWUWxDVDhUWDFqWVk4cHRWd0FieVNjOVlsWk9vbHYyTE1nSGpNTUxIcjRDWFBISG5aSjMwT0pEeXZzSmlDUGNEMDRaeEVuM3ZwRnY3bnY0QQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Falexanderjstein%2F&amp;v=IOwJ8nw1Dgs'>  / alexanderjstein  </a></p>
<p>GitHub: <a href='https://github.com/aj-stein'>github.com/aj-stein</a>.</p>
<p> Learn more about NIST: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbjZYT1lGS1FWd28zXzFXb1ZLa2NHWnUwN0dud3xBQ3Jtc0tscWtIeEttTWlBZmh1dF81XzlqbTRrSXAwb1g3T25IYS1vUmI5ajJiVU9qSWJNb2dPNXNTQW9EMGtiOG9FeUJMYnR2eHh4d3M1X3ZxQzJ2aGR1a08xRl9lREpsZ3lDTlBydDlZdnNPRWc1QUpsT0dSYw&amp;q=https%3A%2F%2Fwww.nist.gov%2F&amp;v=IOwJ8nw1Dgs'>https://www.nist.gov/</a> </p>
<p> </p>
<p>Learn more about Kenny Scott: LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqblktTVVuZ3RYT2RjcFY1bkx5eXVoZGdzQU1oUXxBQ3Jtc0tsZ2ljVVRSblZiUmlxWWo3eFpUUHp6ck5FVDJJb0R2c2FNWHpWb2Z1c01wUjlHaUxwUTZ3ZHRFY214UnN6YmcyQlBzRVZXQzVGOEVqcFlsckNGYVdkdUJKOVF4VVI1Q2Y2X25GSXRMbU9rRXUwRDhQVQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fkenny-g-scott%2F&amp;v=IOwJ8nw1Dgs'>  / kenny-g-scott  </a> Learn more about Paramify: Website: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqazlRTi1YcnZxb3pKcFJ4MERJb3c0UjRoakxUUXxBQ3Jtc0tub2lUQUViMjFRNmxTRjZuamY0Q0hhYmhnckRqUmpKU2pOeHVaemJqWGtUbXRaQTlXdXd4cUVnRmxUaVdEdDRjbDN5ZFAwbG1QampJdGlaZjFXS0RGNTRlWWtuME1hRnk3cURuRkVTM3F3VE5RNV9uNA&amp;q=https%3A%2F%2Fwww.paramify.com%2F&amp;v=IOwJ8nw1Dgs'>https://www.paramify.com/</a> LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGxocnZnalpRTHRMZEw3NlJVYnJaa3pVVGdrd3xBQ3Jtc0tucExiT05SXzZrdzhaVXhqaHEwc1NaQjk4MXJxTkJUWFVGdGJRUjhEYUJZR2Ztc2ZGQXBZLWJYR0hpSnY5dHZlNVdqTEIxS3RXNFVuQ3ZEWlN1UTY4LUc4U1diUWl0UVZKdEIzb3BheTRxcUtyY3pPVQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F80788473%2Fadmin%2Fdashboard%2F&amp;v=IOwJ8nw1Dgs'>  / dashboard  </a></p>





]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we're honored to have Alexander Stein on the show. Alexander has a host of experience in Cybersecurity. He has worked as an IT Cybersecurity Specialist at the National Institute of Standards and Technology (NIST). With over two years at NIST focusing on Information Technology and Vulnerability Management, Alex has also held key roles at Flexion Inc. as a Security Practice Lead and Application Security Engineer,</p>
<p>and at BAM Technologies Learn more about Alexander Stein here: LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbHh6WWI4MDl5RUNGNFRzM2dieHQtdU5VNHlPZ3xBQ3Jtc0trTS1yLTB0WWllNVlOcy1Rb25abWJJYlBtMURDM0EyMzJWUWxDVDhUWDFqWVk4cHRWd0FieVNjOVlsWk9vbHYyTE1nSGpNTUxIcjRDWFBISG5aSjMwT0pEeXZzSmlDUGNEMDRaeEVuM3ZwRnY3bnY0QQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Falexanderjstein%2F&amp;v=IOwJ8nw1Dgs'>  / alexanderjstein  </a></p>
<p>GitHub: <a href='https://github.com/aj-stein'>github.com/aj-stein</a>.</p>
<p> Learn more about NIST: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbjZYT1lGS1FWd28zXzFXb1ZLa2NHWnUwN0dud3xBQ3Jtc0tscWtIeEttTWlBZmh1dF81XzlqbTRrSXAwb1g3T25IYS1vUmI5ajJiVU9qSWJNb2dPNXNTQW9EMGtiOG9FeUJMYnR2eHh4d3M1X3ZxQzJ2aGR1a08xRl9lREpsZ3lDTlBydDlZdnNPRWc1QUpsT0dSYw&amp;q=https%3A%2F%2Fwww.nist.gov%2F&amp;v=IOwJ8nw1Dgs'>https://www.nist.gov/</a> </p>
<p> </p>
<p>Learn more about Kenny Scott: LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqblktTVVuZ3RYT2RjcFY1bkx5eXVoZGdzQU1oUXxBQ3Jtc0tsZ2ljVVRSblZiUmlxWWo3eFpUUHp6ck5FVDJJb0R2c2FNWHpWb2Z1c01wUjlHaUxwUTZ3ZHRFY214UnN6YmcyQlBzRVZXQzVGOEVqcFlsckNGYVdkdUJKOVF4VVI1Q2Y2X25GSXRMbU9rRXUwRDhQVQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fkenny-g-scott%2F&amp;v=IOwJ8nw1Dgs'>  / kenny-g-scott  </a> Learn more about Paramify: Website: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqazlRTi1YcnZxb3pKcFJ4MERJb3c0UjRoakxUUXxBQ3Jtc0tub2lUQUViMjFRNmxTRjZuamY0Q0hhYmhnckRqUmpKU2pOeHVaemJqWGtUbXRaQTlXdXd4cUVnRmxUaVdEdDRjbDN5ZFAwbG1QampJdGlaZjFXS0RGNTRlWWtuME1hRnk3cURuRkVTM3F3VE5RNV9uNA&amp;q=https%3A%2F%2Fwww.paramify.com%2F&amp;v=IOwJ8nw1Dgs'>https://www.paramify.com/</a> LinkedIn: <a href='https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGxocnZnalpRTHRMZEw3NlJVYnJaa3pVVGdrd3xBQ3Jtc0tucExiT05SXzZrdzhaVXhqaHEwc1NaQjk4MXJxTkJUWFVGdGJRUjhEYUJZR2Ztc2ZGQXBZLWJYR0hpSnY5dHZlNVdqTEIxS3RXNFVuQ3ZEWlN1UTY4LUc4U1diUWl0UVZKdEIzb3BheTRxcUtyY3pPVQ&amp;q=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F80788473%2Fadmin%2Fdashboard%2F&amp;v=IOwJ8nw1Dgs'>  / dashboard  </a></p>





]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rqcgaqz2immwmvb6/ALEXANDER_FULL_POD_AUDIOae42u.mp3" length="58457493" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we're honored to have Alexander Stein on the show. Alexander has a host of experience in Cybersecurity. He has worked as an IT Cybersecurity Specialist at the National Institute of Standards and Technology (NIST). With over two years at NIST focusing on Information Technology and Vulnerability Management, Alex has also held key roles at Flexion Inc. as a Security Practice Lead and Application Security Engineer,
and at BAM Technologies Learn more about Alexander Stein here: LinkedIn:   / alexanderjstein  
GitHub: github.com/aj-stein.
 Learn more about NIST: https://www.nist.gov/ 
 
Learn more about Kenny Scott: LinkedIn:   / kenny-g-scott   Learn more about Paramify: Website: https://www.paramify.com/ LinkedIn:   / dashboard  





]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3653</itunes:duration>
                <itunes:episode>31</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#30 - Discussing Government Affairs &amp; Compliance with Michael Clauser</title>
        <itunes:title>#30 - Discussing Government Affairs &amp; Compliance with Michael Clauser</itunes:title>
        <link>https://Paramify.podbean.com/e/30-discussing-government-affairs-compliance-with-michael-clauser/</link>
                    <comments>https://Paramify.podbean.com/e/30-discussing-government-affairs-compliance-with-michael-clauser/#comments</comments>        <pubDate>Fri, 09 Aug 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d1ddd7a5-27d2-3128-8fa4-42a6da020bd7</guid>
                                    <description><![CDATA[<p>Today, we're honored to have Michael Clauser, on the show. Mike is the Founder &amp; Managing Director of Ark where he helps tech and defense companies navigate government relations. He is a seasoned professional in government affairs, cybersecurity, and national security. Michael has led pivotal roles at Okta, Access Partnership, Analog Devices, and Fujitsu Limited, and served as a national security aide in the Pentagon. With a decade as an Intelligence Officer in the U.S. Navy, he has also held leadership roles supporting veterans and contributing to public policy. </p>
<p>Learn more about Michael Clauser: 
LinkedIn: https://www.linkedin.com/in/michaelaclauser/</p>
<p>Learn more about Ark: https://ark.ga/</p>
<p>Learn more about Kenny Scott: 
LinkedIn: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify: 
Website: https://www.paramify.com/</p>
<p>LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we're honored to have Michael Clauser, on the show. Mike is the Founder &amp; Managing Director of Ark where he helps tech and defense companies navigate government relations. He is a seasoned professional in government affairs, cybersecurity, and national security. Michael has led pivotal roles at Okta, Access Partnership, Analog Devices, and Fujitsu Limited, and served as a national security aide in the Pentagon. With a decade as an Intelligence Officer in the U.S. Navy, he has also held leadership roles supporting veterans and contributing to public policy. </p>
<p>Learn more about Michael Clauser: <br>
LinkedIn: https://www.linkedin.com/in/michaelaclauser/</p>
<p>Learn more about Ark: https://ark.ga/</p>
<p>Learn more about Kenny Scott: <br>
LinkedIn: https://www.linkedin.com/in/kenny-g-scott/</p>
<p>Learn more about Paramify: <br>
Website: https://www.paramify.com/</p>
<p>LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hamhbejdbhsqdvyp/Mike_and_Kenny_Capcut_Render_Podcast86cgt.mp3" length="43573966" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we're honored to have Michael Clauser, on the show. Mike is the Founder &amp; Managing Director of Ark where he helps tech and defense companies navigate government relations. He is a seasoned professional in government affairs, cybersecurity, and national security. Michael has led pivotal roles at Okta, Access Partnership, Analog Devices, and Fujitsu Limited, and served as a national security aide in the Pentagon. With a decade as an Intelligence Officer in the U.S. Navy, he has also held leadership roles supporting veterans and contributing to public policy. 
Learn more about Michael Clauser: LinkedIn: https://www.linkedin.com/in/michaelaclauser/
Learn more about Ark: https://ark.ga/
Learn more about Kenny Scott: LinkedIn: https://www.linkedin.com/in/kenny-g-scott/
Learn more about Paramify: Website: https://www.paramify.com/
LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2723</itunes:duration>
                <itunes:episode>30</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#29 - Discussing GRC Automation with Matt Hillary</title>
        <itunes:title>#29 - Discussing GRC Automation with Matt Hillary</itunes:title>
        <link>https://Paramify.podbean.com/e/29-discussing-grc-automation-with-matt-hillary/</link>
                    <comments>https://Paramify.podbean.com/e/29-discussing-grc-automation-with-matt-hillary/#comments</comments>        <pubDate>Fri, 26 Jul 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/55db0a24-e337-3fbe-89ec-4376800cc810</guid>
                                    <description><![CDATA[<p>Today we're honored to have Matt Hillary on the podcast. Matt is the Vice President of Security and Chief Information Security Officer at Drata. He is a seasoned cybersecurity leader with 15 years of experience and a passion for enabling innovation. </p>
<p>Learn more about Matt Hillary:
LinkedIn: https://www.linkedin.com/in/matthewhillary/
Matt Hillary's Forbes Article: https://www.forbes.com/sites/forbestechcouncil/2024/06/20/privacy-by-design-and-its-impact-on-security-and-grc/</p>
<p>Learn More about Drata:
Drata's Website: https://drata.com/
Drata's LinkedIn: https://www.linkedin.com/company/drata/posts/?feedView=all</p>
<p>Learn more about Paramify: 
Paramify's Website: https://www.paramify.com/
Paramify's LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/</p>
<p>Matt Hillary brings over 15 years of experience in executive security leadership, risk management, and compliance. His impressive track record includes roles at Lumio, Weave HQ, Workfront, and Instructure. Matt holds a Master’s in Information Systems Management from Brigham Young University and is a CISA-certified professional. Known for his strong technical background, positive leadership style, and effective communication, Matt is dedicated to building tailored security solutions that drive measurable success.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we're honored to have Matt Hillary on the podcast. Matt is the Vice President of Security and Chief Information Security Officer at Drata. He is a seasoned cybersecurity leader with 15 years of experience and a passion for enabling innovation. </p>
<p>Learn more about Matt Hillary:<br>
LinkedIn: https://www.linkedin.com/in/matthewhillary/<br>
Matt Hillary's Forbes Article: https://www.forbes.com/sites/forbestechcouncil/2024/06/20/privacy-by-design-and-its-impact-on-security-and-grc/</p>
<p>Learn More about Drata:<br>
Drata's Website: https://drata.com/<br>
Drata's LinkedIn: https://www.linkedin.com/company/drata/posts/?feedView=all</p>
<p>Learn more about Paramify: <br>
Paramify's Website: https://www.paramify.com/<br>
Paramify's LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/</p>
<p>Matt Hillary brings over 15 years of experience in executive security leadership, risk management, and compliance. His impressive track record includes roles at Lumio, Weave HQ, Workfront, and Instructure. Matt holds a Master’s in Information Systems Management from Brigham Young University and is a CISA-certified professional. Known for his strong technical background, positive leadership style, and effective communication, Matt is dedicated to building tailored security solutions that drive measurable success.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ipwgmggh5xj5pnsu/MATT_HILLARY_PODCAST_AUDIO_NEW8h613.mp3" length="49722564" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we're honored to have Matt Hillary on the podcast. Matt is the Vice President of Security and Chief Information Security Officer at Drata. He is a seasoned cybersecurity leader with 15 years of experience and a passion for enabling innovation. 
Learn more about Matt Hillary:LinkedIn: https://www.linkedin.com/in/matthewhillary/Matt Hillary's Forbes Article: https://www.forbes.com/sites/forbestechcouncil/2024/06/20/privacy-by-design-and-its-impact-on-security-and-grc/
Learn More about Drata:Drata's Website: https://drata.com/Drata's LinkedIn: https://www.linkedin.com/company/drata/posts/?feedView=all
Learn more about Paramify: Paramify's Website: https://www.paramify.com/Paramify's LinkedIn: https://www.linkedin.com/company/80788473/admin/dashboard/
Matt Hillary brings over 15 years of experience in executive security leadership, risk management, and compliance. His impressive track record includes roles at Lumio, Weave HQ, Workfront, and Instructure. Matt holds a Master’s in Information Systems Management from Brigham Young University and is a CISA-certified professional. Known for his strong technical background, positive leadership style, and effective communication, Matt is dedicated to building tailored security solutions that drive measurable success.]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3107</itunes:duration>
                <itunes:episode>29</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#28 - Discussing Cloud Security and GRC with Eric Evans</title>
        <itunes:title>#28 - Discussing Cloud Security and GRC with Eric Evans</itunes:title>
        <link>https://Paramify.podbean.com/e/28-discussing-cloud-security-and-grc-with-eric-evans/</link>
                    <comments>https://Paramify.podbean.com/e/28-discussing-cloud-security-and-grc-with-eric-evans/#comments</comments>        <pubDate>Fri, 12 Jul 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/380e7f17-1766-33ae-a7d2-ef4fa1d0811d</guid>
                                    <description><![CDATA[<p>Today we're honored to have Eric Evans on the show! Eric is the Founder and CTO of HanaByte, he is a cloud security and compliance expert. He has led security initiatives for startups to Fortune 10 companies and is a renowned public speaker on cloud security and compliance automation.</p>
<p>Learn more about Hanabyte:</p>
<p>https://www.hanabyte.com/ <a href='https://www.linkedin.com/company/hanabyte/posts/?feedView=all'>https://www.linkedin.com/company/hanabyte/posts/?feedView=all </a></p>
<p>Hanabyte's write-up on the OMB Memo:</p>
<p><a href='https://www.hanabyte.com/a-look-at-the-modernizing-fedramp-memo/'> https://www.hanabyte.com/a-look-at-the-modernizing-fedramp-memo/ </a></p>
<p>Eric Evans's LinkedIn: <a href='https://www.linkedin.com/in/ericgonzalesevans/'>https://www.linkedin.com/in/ericgonzalesevans/ </a></p>
<p>Kenny Scott's LinkedIn: <a href='https://www.linkedin.com/in/kenny-g-scott/'>https://www.linkedin.com/in/kenny-g-scott/ </a></p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we're honored to have Eric Evans on the show! Eric is the Founder and CTO of HanaByte, he is a cloud security and compliance expert. He has led security initiatives for startups to Fortune 10 companies and is a renowned public speaker on cloud security and compliance automation.</p>
<p>Learn more about Hanabyte:</p>
<p>https://www.hanabyte.com/ <a href='https://www.linkedin.com/company/hanabyte/posts/?feedView=all'>https://www.linkedin.com/company/hanabyte/posts/?feedView=all </a></p>
<p>Hanabyte's write-up on the OMB Memo:</p>
<p><a href='https://www.hanabyte.com/a-look-at-the-modernizing-fedramp-memo/'> https://www.hanabyte.com/a-look-at-the-modernizing-fedramp-memo/ </a></p>
<p>Eric Evans's LinkedIn: <a href='https://www.linkedin.com/in/ericgonzalesevans/'>https://www.linkedin.com/in/ericgonzalesevans/ </a></p>
<p>Kenny Scott's LinkedIn: <a href='https://www.linkedin.com/in/kenny-g-scott/'>https://www.linkedin.com/in/kenny-g-scott/ </a></p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kep4ecuuijd25qjs/Kenny_and_Eric_Podcast_Audio_Only96afs.mp3" length="89522663" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we're honored to have Eric Evans on the show! Eric is the Founder and CTO of HanaByte, he is a cloud security and compliance expert. He has led security initiatives for startups to Fortune 10 companies and is a renowned public speaker on cloud security and compliance automation.
Learn more about Hanabyte:
https://www.hanabyte.com/ https://www.linkedin.com/company/hanabyte/posts/?feedView=all 
Hanabyte's write-up on the OMB Memo:
 https://www.hanabyte.com/a-look-at-the-modernizing-fedramp-memo/ 
Eric Evans's LinkedIn: https://www.linkedin.com/in/ericgonzalesevans/ 
Kenny Scott's LinkedIn: https://www.linkedin.com/in/kenny-g-scott/ 
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3727</itunes:duration>
                <itunes:episode>28</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#27 - Discussing Cybersecurity and Compliance with Den Jones</title>
        <itunes:title>#27 - Discussing Cybersecurity and Compliance with Den Jones</itunes:title>
        <link>https://Paramify.podbean.com/e/27-discussing-cybersecurity-and-compliance-with-den-jones/</link>
                    <comments>https://Paramify.podbean.com/e/27-discussing-cybersecurity-and-compliance-with-den-jones/#comments</comments>        <pubDate>Fri, 28 Jun 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/c7256894-5c74-3b7a-a6bb-f2313fd7ca5f</guid>
                                    <description><![CDATA[<p>Today, we're honored to be joined by Den Jones, Founder and CEO of 909Cyber and a veteran in cybersecurity. With a robust career that includes roles as Chief Security Officer at SonicWall, CSO at Banyan Security and Senior Director of Enterprise Security at Cisco, Den brings a wealth of experience to the table. He's a Stanford alumnus with a focus on Cyber Security and Executive Strategy, holds a Higher National Certificate in Computing from West Lothian College, and is a certified CISSP. Den also hosts 'Get IT Started. Get IT Done.', a podcast that discusses the cybersecurity industry. He’s here to share his expertise on the evolving cybersecurity landscape, tackling complex security challenges, and his approach to leadership in this crucial sector.</p>
<p>Learn more about Den Jones: <a href='https://www.linkedin.com/in/denwjones/'>https://www.linkedin.com/in/denwjones/ </a></p>
<p>Get IT Started. Get IT Done. Podcast: <a href='https://podcasters.spotify.com/pod/show/banyan-security'>https://podcasters.spotify.com/pod/show/banyan-security </a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p>Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we're honored to be joined by Den Jones, Founder and CEO of 909Cyber and a veteran in cybersecurity. With a robust career that includes roles as Chief Security Officer at SonicWall, CSO at Banyan Security and Senior Director of Enterprise Security at Cisco, Den brings a wealth of experience to the table. He's a Stanford alumnus with a focus on Cyber Security and Executive Strategy, holds a Higher National Certificate in Computing from West Lothian College, and is a certified CISSP. Den also hosts 'Get IT Started. Get IT Done.', a podcast that discusses the cybersecurity industry. He’s here to share his expertise on the evolving cybersecurity landscape, tackling complex security challenges, and his approach to leadership in this crucial sector.</p>
<p>Learn more about Den Jones: <a href='https://www.linkedin.com/in/denwjones/'>https://www.linkedin.com/in/denwjones/ </a></p>
<p>Get IT Started. Get IT Done. Podcast: <a href='https://podcasters.spotify.com/pod/show/banyan-security'>https://podcasters.spotify.com/pod/show/banyan-security </a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p>Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/5w97xi5e5hubnwpe/The_Paramify_Podcast_with_Den_Jones7lzax.mp3" length="46301568" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we're honored to be joined by Den Jones, Founder and CEO of 909Cyber and a veteran in cybersecurity. With a robust career that includes roles as Chief Security Officer at SonicWall, CSO at Banyan Security and Senior Director of Enterprise Security at Cisco, Den brings a wealth of experience to the table. He's a Stanford alumnus with a focus on Cyber Security and Executive Strategy, holds a Higher National Certificate in Computing from West Lothian College, and is a certified CISSP. Den also hosts 'Get IT Started. Get IT Done.', a podcast that discusses the cybersecurity industry. He’s here to share his expertise on the evolving cybersecurity landscape, tackling complex security challenges, and his approach to leadership in this crucial sector.
Learn more about Den Jones: https://www.linkedin.com/in/denwjones/ 
Get IT Started. Get IT Done. Podcast: https://podcasters.spotify.com/pod/show/banyan-security 
Learn more about Paramify here: https://www.paramify.com/
Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2893</itunes:duration>
                <itunes:episode>27</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#26 - Exploring OSCAL and GRC with Rob Sherwood</title>
        <itunes:title>#26 - Exploring OSCAL and GRC with Rob Sherwood</itunes:title>
        <link>https://Paramify.podbean.com/e/26-exploring-oscal-and-grc-with-rob-sherwood/</link>
                    <comments>https://Paramify.podbean.com/e/26-exploring-oscal-and-grc-with-rob-sherwood/#comments</comments>        <pubDate>Fri, 14 Jun 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/02e7d697-e306-337d-b9eb-596073828968</guid>
                                    <description><![CDATA[<p>Today, we’re honored to have Rob Sherwood on the podcast. Rob is a seasoned cybersecurity professional with extensive experience in policy management, PKI architecture, and identity management. With over two decades in the field, Rob has left a lasting impact through his dedication to standards development, including his significant contributions to the Open Security Controls Assessment Language (OSCAL). From his role as a Principal Consultant at Credentive Security to his pivotal involvement in projects like the oscal-pki-policy-converter tool, Rob's passion for advancing cybersecurity practices is evident. As an advocate for collaboration and knowledge-sharing, his insights into OSCAL offer invaluable perspectives for professionals and organizations navigating the complexities of cybersecurity policy management.</p>
<p>Learn more about Rob: <a href='https://www.linkedin.com/in/rob-sherwood-credentive/'>https://www.linkedin.com/in/rob-sherwood-credentive/ </a></p>
<p>Credentive Security: <a href='https://www.credentive.com/'>https://www.credentive.com/ </a></p>
<p>Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we’re honored to have Rob Sherwood on the podcast. Rob is a seasoned cybersecurity professional with extensive experience in policy management, PKI architecture, and identity management. With over two decades in the field, Rob has left a lasting impact through his dedication to standards development, including his significant contributions to the Open Security Controls Assessment Language (OSCAL). From his role as a Principal Consultant at Credentive Security to his pivotal involvement in projects like the oscal-pki-policy-converter tool, Rob's passion for advancing cybersecurity practices is evident. As an advocate for collaboration and knowledge-sharing, his insights into OSCAL offer invaluable perspectives for professionals and organizations navigating the complexities of cybersecurity policy management.</p>
<p>Learn more about Rob: <a href='https://www.linkedin.com/in/rob-sherwood-credentive/'>https://www.linkedin.com/in/rob-sherwood-credentive/ </a></p>
<p>Credentive Security: <a href='https://www.credentive.com/'>https://www.credentive.com/ </a></p>
<p>Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/sj4e6msd9ht8ypja/Rob_Sherwood_FULL_PODCAST7iz39.mp3" length="57899935" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we’re honored to have Rob Sherwood on the podcast. Rob is a seasoned cybersecurity professional with extensive experience in policy management, PKI architecture, and identity management. With over two decades in the field, Rob has left a lasting impact through his dedication to standards development, including his significant contributions to the Open Security Controls Assessment Language (OSCAL). From his role as a Principal Consultant at Credentive Security to his pivotal involvement in projects like the oscal-pki-policy-converter tool, Rob's passion for advancing cybersecurity practices is evident. As an advocate for collaboration and knowledge-sharing, his insights into OSCAL offer invaluable perspectives for professionals and organizations navigating the complexities of cybersecurity policy management.
Learn more about Rob: https://www.linkedin.com/in/rob-sherwood-credentive/ 
Credentive Security: https://www.credentive.com/ 
Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3618</itunes:duration>
                <itunes:episode>26</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#25 - Exploring GRC &amp; FedRAMP with Matthew Graham</title>
        <itunes:title>#25 - Exploring GRC &amp; FedRAMP with Matthew Graham</itunes:title>
        <link>https://Paramify.podbean.com/e/25-exploring-grc-fedramp-with-matthew-graham/</link>
                    <comments>https://Paramify.podbean.com/e/25-exploring-grc-fedramp-with-matthew-graham/#comments</comments>        <pubDate>Fri, 31 May 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/43b025be-20a7-3fc5-a040-326aeec0b547</guid>
                                    <description><![CDATA[<p>Today we had the honor to talk with Matthew Graham, the Director of US Federal Practice at Prescient Security. Matthew is a seasoned cybersecurity expert whose extensive career has spanned technical and strategic leadership roles. With a rich background that includes high-level certifications such as CISSP, CASP+, and CCNA, Matthew brings a wealth of knowledge on FedRAMP &amp; cybersecurity practices and trends.</p>
<p>In this episode, we talk about everything from FedRAMP Rev 5 to Hurricane Katrina and police interrogations.</p>
<p>Learn more about Matthew Graham: <a href='https://www.linkedin.com/in/msgcyberassessments/'>https://www.linkedin.com/in/msgcyberassessments/ </a></p>
<p>Learn more about Prescient Security: prescientsecurity.com</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to talk with Matthew Graham, the Director of US Federal Practice at Prescient Security. Matthew is a seasoned cybersecurity expert whose extensive career has spanned technical and strategic leadership roles. With a rich background that includes high-level certifications such as CISSP, CASP+, and CCNA, Matthew brings a wealth of knowledge on FedRAMP &amp; cybersecurity practices and trends.</p>
<p>In this episode, we talk about everything from FedRAMP Rev 5 to Hurricane Katrina and police interrogations.</p>
<p>Learn more about Matthew Graham: <a href='https://www.linkedin.com/in/msgcyberassessments/'>https://www.linkedin.com/in/msgcyberassessments/ </a></p>
<p>Learn more about Prescient Security: prescientsecurity.com</p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7ig3n9s8hnrcus6r/MATT_GRAHAM_FINISHED_3212313216e48k.mp3" length="44217205" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to talk with Matthew Graham, the Director of US Federal Practice at Prescient Security. Matthew is a seasoned cybersecurity expert whose extensive career has spanned technical and strategic leadership roles. With a rich background that includes high-level certifications such as CISSP, CASP+, and CCNA, Matthew brings a wealth of knowledge on FedRAMP &amp; cybersecurity practices and trends.
In this episode, we talk about everything from FedRAMP Rev 5 to Hurricane Katrina and police interrogations.
Learn more about Matthew Graham: https://www.linkedin.com/in/msgcyberassessments/ 
Learn more about Prescient Security: prescientsecurity.com
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2763</itunes:duration>
                <itunes:episode>25</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#24 - Discussing GRC &amp; OSCAL with Brandt Keller</title>
        <itunes:title>#24 - Discussing GRC &amp; OSCAL with Brandt Keller</itunes:title>
        <link>https://Paramify.podbean.com/e/24-discussing-grc-oscal-with-brandt-keller/</link>
                    <comments>https://Paramify.podbean.com/e/24-discussing-grc-oscal-with-brandt-keller/#comments</comments>        <pubDate>Fri, 17 May 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/3b1e4d7c-aa63-35ab-8310-e75ddff58f1e</guid>
                                    <description><![CDATA[<p>Today we had honor to talk with Brandt Keller, a distinguished software engineer and open source developer advocate with a comprehensive background that spans significant achievements in both the military and technology sectors. A veteran of the U.S. Marine Corps, Brandt has transitioned his disciplined and strategic approach from the field of communications within the military to the forefront of software engineering and cybersecurity. His recent endeavors have led him to explore the intricacies of Governance, Risk Management, and Compliance (GRC), focusing on the adoption of the Open Security Controls Assessment Language (OSCAL) by NIST to promote data freedom and enhance the automation of compliance processes. Brandt's commitment to leveraging his expertise for the advancement of technology and compliance standards showcases his dedication to innovation and continuous improvement. We're truly excited to have Brandt on the show to delve into his rich experience, explore his contributions to the field of technology, and discuss his visionary work in making compliance data more accessible and actionable.</p>
<p>Brandt Keller's open source project: <a href='https://www.linkedin.com/safety/go?url=https%3A%2F%2Fgithub.com%2Fdefenseunicorns%2Flula&amp;trk=flagship-messaging-web&amp;messageThreadUrn=urn%3Ali%3AmessagingThread%3A2-YTIxN2JkYzgtZjk3OC00ZDllLWI0NWQtYjcxM2IwNjA1Nzc5XzAxMg%3D%3D&amp;lipi=urn%3Ali%3Apage%3Ad_flagship3_messaging_conversation_detail%3BLReifSRSRrel35KkzQYD8A%3D%3D'>https://github.com/defenseunicorns/lula</a></p>
<p>Brant Keller's LinkedIn: <a href='https://www.linkedin.com/in/brandtkeller/'>https://www.linkedin.com/in/brandtkeller/</a></p>
<p>Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had honor to talk with Brandt Keller, a distinguished software engineer and open source developer advocate with a comprehensive background that spans significant achievements in both the military and technology sectors. A veteran of the U.S. Marine Corps, Brandt has transitioned his disciplined and strategic approach from the field of communications within the military to the forefront of software engineering and cybersecurity. His recent endeavors have led him to explore the intricacies of Governance, Risk Management, and Compliance (GRC), focusing on the adoption of the Open Security Controls Assessment Language (OSCAL) by NIST to promote data freedom and enhance the automation of compliance processes. Brandt's commitment to leveraging his expertise for the advancement of technology and compliance standards showcases his dedication to innovation and continuous improvement. We're truly excited to have Brandt on the show to delve into his rich experience, explore his contributions to the field of technology, and discuss his visionary work in making compliance data more accessible and actionable.</p>
<p>Brandt Keller's open source project: <a href='https://www.linkedin.com/safety/go?url=https%3A%2F%2Fgithub.com%2Fdefenseunicorns%2Flula&amp;trk=flagship-messaging-web&amp;messageThreadUrn=urn%3Ali%3AmessagingThread%3A2-YTIxN2JkYzgtZjk3OC00ZDllLWI0NWQtYjcxM2IwNjA1Nzc5XzAxMg%3D%3D&amp;lipi=urn%3Ali%3Apage%3Ad_flagship3_messaging_conversation_detail%3BLReifSRSRrel35KkzQYD8A%3D%3D'>https://github.com/defenseunicorns/lula</a></p>
<p>Brant Keller's LinkedIn: <a href='https://www.linkedin.com/in/brandtkeller/'>https://www.linkedin.com/in/brandtkeller/</a></p>
<p>Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/icgn4m9gdppk6e44/The_Paramify_Podcast_with_Brandt_Keller63t4i.mp3" length="46066257" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had honor to talk with Brandt Keller, a distinguished software engineer and open source developer advocate with a comprehensive background that spans significant achievements in both the military and technology sectors. A veteran of the U.S. Marine Corps, Brandt has transitioned his disciplined and strategic approach from the field of communications within the military to the forefront of software engineering and cybersecurity. His recent endeavors have led him to explore the intricacies of Governance, Risk Management, and Compliance (GRC), focusing on the adoption of the Open Security Controls Assessment Language (OSCAL) by NIST to promote data freedom and enhance the automation of compliance processes. Brandt's commitment to leveraging his expertise for the advancement of technology and compliance standards showcases his dedication to innovation and continuous improvement. We're truly excited to have Brandt on the show to delve into his rich experience, explore his contributions to the field of technology, and discuss his visionary work in making compliance data more accessible and actionable.
Brandt Keller's open source project: https://github.com/defenseunicorns/lula
Brant Keller's LinkedIn: https://www.linkedin.com/in/brandtkeller/
Paramify: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2879</itunes:duration>
                <itunes:episode>24</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#23 - Discussing Data Privacy with Tommy Hoschouer</title>
        <itunes:title>#23 - Discussing Data Privacy with Tommy Hoschouer</itunes:title>
        <link>https://Paramify.podbean.com/e/23-discussing-data-privacy-with-tommy-hoschouer/</link>
                    <comments>https://Paramify.podbean.com/e/23-discussing-data-privacy-with-tommy-hoschouer/#comments</comments>        <pubDate>Fri, 03 May 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/1bf697a5-fb09-3fd1-a5c9-488818888edc</guid>
                                    <description><![CDATA[<p>Today we're honored to host Tommy Hoschouer, who currently leads the global public sector efforts at DeleteMe. Tommy's rich history at companies like Sprinklr, Medallia, SAP, and Qualtrics has equipped him with a unique perspective on using technology to enhance public sector operations, leading to significant improvements in revenue and efficiency. Now at DeleteMe, he is dedicated to defending personal and professional information from increasingly sophisticated digital threats, such as identity theft and cyber attacks. His focus on strengthening data privacy and security is crucial in our digital era. We look forward to unpacking his valuable insights on how to protect digital identities and adapt to the evolving technological landscape in the public sector.</p>
<p>In today's episode Kenny, Keaton, and Tommy talk about everything from data privacy, the importance of protecting your data, to our favorite ice cream shakes.</p>
<p>Learn more about Tommy: <a href='https://www.linkedin.com/in/tommy-h-18484087/'>https://www.linkedin.com/in/tommy-h-18484087/ </a></p>
<p>Learn more about DeleteMe: <a href='https://joindeleteme.com/'>https://joindeleteme.com/ </a></p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we're honored to host Tommy Hoschouer, who currently leads the global public sector efforts at DeleteMe. Tommy's rich history at companies like Sprinklr, Medallia, SAP, and Qualtrics has equipped him with a unique perspective on using technology to enhance public sector operations, leading to significant improvements in revenue and efficiency. Now at DeleteMe, he is dedicated to defending personal and professional information from increasingly sophisticated digital threats, such as identity theft and cyber attacks. His focus on strengthening data privacy and security is crucial in our digital era. We look forward to unpacking his valuable insights on how to protect digital identities and adapt to the evolving technological landscape in the public sector.</p>
<p>In today's episode Kenny, Keaton, and Tommy talk about everything from data privacy, the importance of protecting your data, to our favorite ice cream shakes.</p>
<p>Learn more about Tommy: <a href='https://www.linkedin.com/in/tommy-h-18484087/'>https://www.linkedin.com/in/tommy-h-18484087/ </a></p>
<p>Learn more about DeleteMe: <a href='https://joindeleteme.com/'>https://joindeleteme.com/ </a></p>
<p>Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/djjgh8xt29jhtf6x/Tommy_podcast_audio_bbq6h.mp3" length="40079410" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we're honored to host Tommy Hoschouer, who currently leads the global public sector efforts at DeleteMe. Tommy's rich history at companies like Sprinklr, Medallia, SAP, and Qualtrics has equipped him with a unique perspective on using technology to enhance public sector operations, leading to significant improvements in revenue and efficiency. Now at DeleteMe, he is dedicated to defending personal and professional information from increasingly sophisticated digital threats, such as identity theft and cyber attacks. His focus on strengthening data privacy and security is crucial in our digital era. We look forward to unpacking his valuable insights on how to protect digital identities and adapt to the evolving technological landscape in the public sector.
In today's episode Kenny, Keaton, and Tommy talk about everything from data privacy, the importance of protecting your data, to our favorite ice cream shakes.
Learn more about Tommy: https://www.linkedin.com/in/tommy-h-18484087/ 
Learn more about DeleteMe: https://joindeleteme.com/ 
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2504</itunes:duration>
                <itunes:episode>23</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#22 - A Journey from Journalism to GRC with Brian Martinez</title>
        <itunes:title>#22 - A Journey from Journalism to GRC with Brian Martinez</itunes:title>
        <link>https://Paramify.podbean.com/e/22-a-journey-from-journalism-to-grc-with-brian-martinez/</link>
                    <comments>https://Paramify.podbean.com/e/22-a-journey-from-journalism-to-grc-with-brian-martinez/#comments</comments>        <pubDate>Fri, 19 Apr 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d4db0992-badd-382c-89e0-5c0600d54f0f</guid>
                                    <description><![CDATA[<p class="p1">Today, we had the honor to have Brian Martinez, a leading expert in governance, risk, and compliance (GRC) with over two decades of experience at Michigan State University and the broader cybersecurity community. As the Governance, Risk, and Compliance Lead at MSU, Brian has spearheaded critical security projects and compliance frameworks, contributing significantly to the university's research and security posture. Beyond MSU, Brian enriches the cybersecurity field through his roles as Founder and President of BIDE Consulting and Director at #misec, alongside his volunteer work with (ISC)² in developing the CISSP certification exam. In this episode, we'll dive into Brian's extensive career, his approach to GRC in academia, and his insights into the future of cybersecurity. It's a pleasure to have Brian join us to share his valuable experience, expertise, and perspectives.</p>
<p class="p1"> </p>
<p class="p1">Brian's LinkedIn: https://www.linkedin.com/in/brianrmartinez/</p>
<p class="p1"> </p>
<p class="p1">Learn more about Paramify: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p class="p1">Today, we had the honor to have Brian Martinez, a leading expert in governance, risk, and compliance (GRC) with over two decades of experience at Michigan State University and the broader cybersecurity community. As the Governance, Risk, and Compliance Lead at MSU, Brian has spearheaded critical security projects and compliance frameworks, contributing significantly to the university's research and security posture. Beyond MSU, Brian enriches the cybersecurity field through his roles as Founder and President of BIDE Consulting and Director at #misec, alongside his volunteer work with (ISC)² in developing the CISSP certification exam. In this episode, we'll dive into Brian's extensive career, his approach to GRC in academia, and his insights into the future of cybersecurity. It's a pleasure to have Brian join us to share his valuable experience, expertise, and perspectives.</p>
<p class="p1"> </p>
<p class="p1">Brian's LinkedIn: https://www.linkedin.com/in/brianrmartinez/</p>
<p class="p1"> </p>
<p class="p1">Learn more about Paramify: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/n6j2a7zhgpwpyjsa/Brian_Martinez_audio_draft_28bgjh.mp3" length="44157437" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we had the honor to have Brian Martinez, a leading expert in governance, risk, and compliance (GRC) with over two decades of experience at Michigan State University and the broader cybersecurity community. As the Governance, Risk, and Compliance Lead at MSU, Brian has spearheaded critical security projects and compliance frameworks, contributing significantly to the university's research and security posture. Beyond MSU, Brian enriches the cybersecurity field through his roles as Founder and President of BIDE Consulting and Director at #misec, alongside his volunteer work with (ISC)² in developing the CISSP certification exam. In this episode, we'll dive into Brian's extensive career, his approach to GRC in academia, and his insights into the future of cybersecurity. It's a pleasure to have Brian join us to share his valuable experience, expertise, and perspectives.
 
Brian's LinkedIn: https://www.linkedin.com/in/brianrmartinez/
 
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2759</itunes:duration>
                <itunes:episode>22</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#21 - Discussing Cybersecurity &amp; GRC with Troy Fine</title>
        <itunes:title>#21 - Discussing Cybersecurity &amp; GRC with Troy Fine</itunes:title>
        <link>https://Paramify.podbean.com/e/21-discussing-cybersecurity-grc-with-troy-fine/</link>
                    <comments>https://Paramify.podbean.com/e/21-discussing-cybersecurity-grc-with-troy-fine/#comments</comments>        <pubDate>Fri, 05 Apr 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/fd788a90-1547-3ea9-810a-07d1f330058a</guid>
                                    <description><![CDATA[<p>Today we had the honor to speak with Troy Fine, the Senior Advisor at Geels Norton,  where he's making significant strides in cybersecurity and compliance. With a rich history in the field, including key positions at Drata and Schneider Downs, Troy's credentials—boasting certifications like ISO 27001:2013 Lead Auditor and CISSP—speak volumes of his expertise. Beyond his professional acumen, Troy captures the cybersecurity community's attention with insightful, humorous memes on LinkedIn, making the dense world of GRC and IT audit accessible and engaging. His memes commonly refer to SOC 2 not being a certification.</p>
<p>In today's episode we talk about everything from SOC 2 not being a certification, Troy's legendary memes to Troy's history and how he started his career in Cybersecurity. </p>
<p> </p>
<p>Troy Fine's LinkedIn: <a href='https://www.linkedin.com/in/troyjfine/'>https://www.linkedin.com/in/troyjfine/ </a></p>
<p>Learn more Geels Norton: geelsnorton.com</p>
<p>Learn More about Paramify: paramify.com</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to speak with Troy Fine, the Senior Advisor at Geels Norton,  where he's making significant strides in cybersecurity and compliance. With a rich history in the field, including key positions at Drata and Schneider Downs, Troy's credentials—boasting certifications like ISO 27001:2013 Lead Auditor and CISSP—speak volumes of his expertise. Beyond his professional acumen, Troy captures the cybersecurity community's attention with insightful, humorous memes on LinkedIn, making the dense world of GRC and IT audit accessible and engaging. His memes commonly refer to SOC 2 not being a certification.</p>
<p>In today's episode we talk about everything from SOC 2 not being a certification, Troy's legendary memes to Troy's history and how he started his career in Cybersecurity. </p>
<p> </p>
<p>Troy Fine's LinkedIn: <a href='https://www.linkedin.com/in/troyjfine/'>https://www.linkedin.com/in/troyjfine/ </a></p>
<p>Learn more Geels Norton: geelsnorton.com</p>
<p>Learn More about Paramify: paramify.com</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4yzurr/The_Troy_fine_podcast_finished_92h1n.mp3" length="52466884" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to speak with Troy Fine, the Senior Advisor at Geels Norton,  where he's making significant strides in cybersecurity and compliance. With a rich history in the field, including key positions at Drata and Schneider Downs, Troy's credentials—boasting certifications like ISO 27001:2013 Lead Auditor and CISSP—speak volumes of his expertise. Beyond his professional acumen, Troy captures the cybersecurity community's attention with insightful, humorous memes on LinkedIn, making the dense world of GRC and IT audit accessible and engaging. His memes commonly refer to SOC 2 not being a certification.
In today's episode we talk about everything from SOC 2 not being a certification, Troy's legendary memes to Troy's history and how he started his career in Cybersecurity. 
 
Troy Fine's LinkedIn: https://www.linkedin.com/in/troyjfine/ 
Learn more Geels Norton: geelsnorton.com
Learn More about Paramify: paramify.com]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3279</itunes:duration>
                <itunes:episode>21</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#20 - Discussing GRC and Infosec with Beau Butaud</title>
        <itunes:title>#20 - Discussing GRC and Infosec with Beau Butaud</itunes:title>
        <link>https://Paramify.podbean.com/e/20-discussing-grc-and-infosec-with-beau-butaud/</link>
                    <comments>https://Paramify.podbean.com/e/20-discussing-grc-and-infosec-with-beau-butaud/#comments</comments>        <pubDate>Fri, 22 Mar 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/91aac897-6acf-3c74-9492-1f22a5be959d</guid>
                                    <description><![CDATA[<p>Today we had the honor to talk to Beau Butaud, a visionary in the compliance and cybersecurity field and the co-founder of Render Compliance. With a background that includes leading roles in risk advisory and compliance management at Moss Adams, and significant contributions at BDO USA, LLP, and Peterson Sullivan LLP, Beau brings a wealth of expertise to the forefront of cybersecurity. His credentials, including AWS Security Fundamentals, CISA, and CPA certifications, underscore his deep commitment to the industry. Beau's innovative approach to SOC 2 assessments at Render Compliance is redefining standards, making security compliance both accessible and impactful for businesses striving to build trust in today's digital landscape. Learn more about Paramify: https://www.paramify.com/ Learn more about Beau Butaud: https://www.linkedin.com/in/beaubutaud/ Learn about Beau's approach: https://rendercompliance.com/approach/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to talk to Beau Butaud, a visionary in the compliance and cybersecurity field and the co-founder of Render Compliance. With a background that includes leading roles in risk advisory and compliance management at Moss Adams, and significant contributions at BDO USA, LLP, and Peterson Sullivan LLP, Beau brings a wealth of expertise to the forefront of cybersecurity. His credentials, including AWS Security Fundamentals, CISA, and CPA certifications, underscore his deep commitment to the industry. Beau's innovative approach to SOC 2 assessments at Render Compliance is redefining standards, making security compliance both accessible and impactful for businesses striving to build trust in today's digital landscape. Learn more about Paramify: https://www.paramify.com/ Learn more about Beau Butaud: https://www.linkedin.com/in/beaubutaud/ Learn about Beau's approach: https://rendercompliance.com/approach/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8qcm55/The_Paramify_Podcast_with_Beau_Butaud_DRAFT_26zeob.mp3" length="53858270" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to talk to Beau Butaud, a visionary in the compliance and cybersecurity field and the co-founder of Render Compliance. With a background that includes leading roles in risk advisory and compliance management at Moss Adams, and significant contributions at BDO USA, LLP, and Peterson Sullivan LLP, Beau brings a wealth of expertise to the forefront of cybersecurity. His credentials, including AWS Security Fundamentals, CISA, and CPA certifications, underscore his deep commitment to the industry. Beau's innovative approach to SOC 2 assessments at Render Compliance is redefining standards, making security compliance both accessible and impactful for businesses striving to build trust in today's digital landscape. Learn more about Paramify: https://www.paramify.com/ Learn more about Beau Butaud: https://www.linkedin.com/in/beaubutaud/ Learn about Beau's approach: https://rendercompliance.com/approach/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3366</itunes:duration>
                <itunes:episode>20</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#19 - Discussing GRC and IT Audit with Jack Rumsey</title>
        <itunes:title>#19 - Discussing GRC and IT Audit with Jack Rumsey</itunes:title>
        <link>https://Paramify.podbean.com/e/19-discussing-grc-and-it-audit-with-jack-rumsey/</link>
                    <comments>https://Paramify.podbean.com/e/19-discussing-grc-and-it-audit-with-jack-rumsey/#comments</comments>        <pubDate>Fri, 08 Mar 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/d1b18818-a426-3416-a2f6-cd90169ad5ee</guid>
                                    <description><![CDATA[<p>Today we had the honor to talk to Jack Rumsey, the Head of GRC at Swimlane. With a rich background in IT security and audit, including roles at DaVita, Schellman, and KPMG, Jack is an expert in compliance standards like SOC II, ISO27001, GDPR, and FedRAMP. Holding a Bachelor's degree in Computer and Information Systems Security from Illinois State University.</p>
<p>In today's episode, we talk about everything from the difficulties of explaining a GRC career to someone outside of GRC, to building GRC tools in OSCAL.</p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/blog/accurate-fedramp-high-ssp-in-less-than-4-hours'>https://www.paramify.com/blog/accurate-fedramp-high-ssp-in-less-than-4-hours </a></p>
<p>Jack Rumsey's LinkedIn: <a href='https://www.linkedin.com/in/jack-rumsey-83303469/'>https://www.linkedin.com/in/jack-rumsey-83303469/ </a></p>
<p>The GRC Destroyer: <a href='https://grcdestroyer.substack.com/'>https://grcdestroyer.substack.com/ </a></p>
<p>Learn about Swimlane here: https://swimlane.com/cpg-swimlane-turbine/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=17300073347&amp;creative=691938325323&amp;keyword=swimlane&amp;matchtype=b&amp;network=g&amp;device=c&amp;gad_source=1&amp;gclid=CjwKCAiA6KWvBhAREiwAFPZM7qRRyeO8sghv0oF3G_HDQGIORB22_EHb64pCZJFTFI5L-4mIBwcj8hoC8goQAvD_BwE</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to talk to Jack Rumsey, the Head of GRC at Swimlane. With a rich background in IT security and audit, including roles at DaVita, Schellman, and KPMG, Jack is an expert in compliance standards like SOC II, ISO27001, GDPR, and FedRAMP. Holding a Bachelor's degree in Computer and Information Systems Security from Illinois State University.</p>
<p>In today's episode, we talk about everything from the difficulties of explaining a GRC career to someone outside of GRC, to building GRC tools in OSCAL.</p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/blog/accurate-fedramp-high-ssp-in-less-than-4-hours'>https://www.paramify.com/blog/accurate-fedramp-high-ssp-in-less-than-4-hours </a></p>
<p>Jack Rumsey's LinkedIn: <a href='https://www.linkedin.com/in/jack-rumsey-83303469/'>https://www.linkedin.com/in/jack-rumsey-83303469/ </a></p>
<p>The GRC Destroyer: <a href='https://grcdestroyer.substack.com/'>https://grcdestroyer.substack.com/ </a></p>
<p>Learn about Swimlane here: https://swimlane.com/cpg-swimlane-turbine/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=17300073347&amp;creative=691938325323&amp;keyword=swimlane&amp;matchtype=b&amp;network=g&amp;device=c&amp;gad_source=1&amp;gclid=CjwKCAiA6KWvBhAREiwAFPZM7qRRyeO8sghv0oF3G_HDQGIORB22_EHb64pCZJFTFI5L-4mIBwcj8hoC8goQAvD_BwE</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pr3bq2/The_Paramify_Podcast_with_Jack_Rumsey_FULL_DRAFT_2b91bv.mp3" length="58893424" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to talk to Jack Rumsey, the Head of GRC at Swimlane. With a rich background in IT security and audit, including roles at DaVita, Schellman, and KPMG, Jack is an expert in compliance standards like SOC II, ISO27001, GDPR, and FedRAMP. Holding a Bachelor's degree in Computer and Information Systems Security from Illinois State University.
In today's episode, we talk about everything from the difficulties of explaining a GRC career to someone outside of GRC, to building GRC tools in OSCAL.
Learn more about Paramify here: https://www.paramify.com/blog/accurate-fedramp-high-ssp-in-less-than-4-hours 
Jack Rumsey's LinkedIn: https://www.linkedin.com/in/jack-rumsey-83303469/ 
The GRC Destroyer: https://grcdestroyer.substack.com/ 
Learn about Swimlane here: https://swimlane.com/cpg-swimlane-turbine/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=17300073347&amp;creative=691938325323&amp;keyword=swimlane&amp;matchtype=b&amp;network=g&amp;device=c&amp;gad_source=1&amp;gclid=CjwKCAiA6KWvBhAREiwAFPZM7qRRyeO8sghv0oF3G_HDQGIORB22_EHb64pCZJFTFI5L-4mIBwcj8hoC8goQAvD_BwE]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3680</itunes:duration>
                <itunes:episode>19</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#18 - Discussing CMMC &amp; Cybersecurity with Fernando Machado</title>
        <itunes:title>#18 - Discussing CMMC &amp; Cybersecurity with Fernando Machado</itunes:title>
        <link>https://Paramify.podbean.com/e/discussing-cmmc-cybersecurity-with-fernando-machado-the-paramify-podcast-episode-18/</link>
                    <comments>https://Paramify.podbean.com/e/discussing-cmmc-cybersecurity-with-fernando-machado-the-paramify-podcast-episode-18/#comments</comments>        <pubDate>Fri, 23 Feb 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/7d2b849c-b5de-3c30-9ca0-77025f680169</guid>
                                    <description><![CDATA[<p>Today, we're excited to welcome a true luminary in the field of cybersecurity, Fernando Machado. Not only is he the Managing Principal and CISO at Cybersec Investments, LLC, but Fernando is also a recognized Certified Third-Party Assessment Organization (C3PAO) leader. His extensive experience spans over two decades with key roles in companies like L3Harris Technologies and Raytheon. Fernando is the author of "CMMC Simplified," a pivotal resource for understanding the complexities of the Cybersecurity Maturity Model Certification.</p>
<p>In today's episode, Fernando tells us about his invaluable insights on cybersecurity's evolving landscape and the nuances of CMMC 2.0.</p>
<p>Fernando Machado's book CMMC Simplified: <a href='https://www.amazon.com/CMMC-Simplified-'>https://www.amazon.com/CMMC-Simplified-</a></p>
<p>Fernando-Machado/dp/1088207707 Fernando Machado's LinkedIn: <a href='https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/'>https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/</a></p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we're excited to welcome a true luminary in the field of cybersecurity, Fernando Machado. Not only is he the Managing Principal and CISO at Cybersec Investments, LLC, but Fernando is also a recognized Certified Third-Party Assessment Organization (C3PAO) leader. His extensive experience spans over two decades with key roles in companies like L3Harris Technologies and Raytheon. Fernando is the author of "CMMC Simplified," a pivotal resource for understanding the complexities of the Cybersecurity Maturity Model Certification.</p>
<p>In today's episode, Fernando tells us about his invaluable insights on cybersecurity's evolving landscape and the nuances of CMMC 2.0.</p>
<p>Fernando Machado's book CMMC Simplified: <a href='https://www.amazon.com/CMMC-Simplified-'>https://www.amazon.com/CMMC-Simplified-</a></p>
<p>Fernando-Machado/dp/1088207707 Fernando Machado's LinkedIn: <a href='https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/'>https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/</a></p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2ig9c3/FERNANDO_PODCAST_FINISHEDb0lhm.mp3" length="27892974" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we're excited to welcome a true luminary in the field of cybersecurity, Fernando Machado. Not only is he the Managing Principal and CISO at Cybersec Investments, LLC, but Fernando is also a recognized Certified Third-Party Assessment Organization (C3PAO) leader. His extensive experience spans over two decades with key roles in companies like L3Harris Technologies and Raytheon. Fernando is the author of "CMMC Simplified," a pivotal resource for understanding the complexities of the Cybersecurity Maturity Model Certification.
In today's episode, Fernando tells us about his invaluable insights on cybersecurity's evolving landscape and the nuances of CMMC 2.0.
Fernando Machado's book CMMC Simplified: https://www.amazon.com/CMMC-Simplified-
Fernando-Machado/dp/1088207707 Fernando Machado's LinkedIn: https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/
Learn more about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1743</itunes:duration>
                <itunes:episode>18</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#17 - Discussing FedRAMP and The Origin of Paramify with Brad Bartholomew</title>
        <itunes:title>#17 - Discussing FedRAMP and The Origin of Paramify with Brad Bartholomew</itunes:title>
        <link>https://Paramify.podbean.com/e/17-discussing-fedramp-and-the-origins-of-paramify-with-brad-bartholomew/</link>
                    <comments>https://Paramify.podbean.com/e/17-discussing-fedramp-and-the-origins-of-paramify-with-brad-bartholomew/#comments</comments>        <pubDate>Fri, 09 Feb 2024 08:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/efbbdae3-1922-3a35-afad-8a6604ecfeff</guid>
                                    <description><![CDATA[<p>Today we had the honor to sit down with <a href='https://www.linkedin.com/company/80788473/admin/feed/posts/'>Brad Bartholomew</a>, the Director of FedRAMP Compliance at Trellix, and a veteran in the cybersecurity field. With a rich history spanning Adobe to Palo Alto Networks, Brad brings invaluable insights into GRC, cloud security, and the evolving landscape of cybersecurity frameworks.</p>
<p>In this episode, we discuss everything from creating an ATO package in 3.5 hours to the challenges of FedRAMP and the origins of Paramify.</p>
<p> </p>
<p>Learn more about Brad Bartholomew: <a href='https://www.linkedin.com/in/bradbartholomew7/'>https://www.linkedin.com/in/bradbartholomew7/</a></p>
<p> </p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to sit down with <a href='https://www.linkedin.com/company/80788473/admin/feed/posts/'>Brad Bartholomew</a>, the Director of FedRAMP Compliance at Trellix, and a veteran in the cybersecurity field. With a rich history spanning Adobe to Palo Alto Networks, Brad brings invaluable insights into GRC, cloud security, and the evolving landscape of cybersecurity frameworks.</p>
<p>In this episode, we discuss everything from creating an ATO package in 3.5 hours to the challenges of FedRAMP and the origins of Paramify.</p>
<p> </p>
<p>Learn more about Brad Bartholomew: <a href='https://www.linkedin.com/in/bradbartholomew7/'>https://www.linkedin.com/in/bradbartholomew7/</a></p>
<p> </p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fdrzgy/The_Paramify_Podcast_Episode_17_Brad_DONEa2ayj.mp3" length="47677907" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to sit down with Brad Bartholomew, the Director of FedRAMP Compliance at Trellix, and a veteran in the cybersecurity field. With a rich history spanning Adobe to Palo Alto Networks, Brad brings invaluable insights into GRC, cloud security, and the evolving landscape of cybersecurity frameworks.
In this episode, we discuss everything from creating an ATO package in 3.5 hours to the challenges of FedRAMP and the origins of Paramify.
 
Learn more about Brad Bartholomew: https://www.linkedin.com/in/bradbartholomew7/
 
Learn more about Paramify: https://www.paramify.com/
 
 
 
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2979</itunes:duration>
                <itunes:episode>17</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#16 - Exploring The Fatal Funnel of Sales with Reade King</title>
        <itunes:title>#16 - Exploring The Fatal Funnel of Sales with Reade King</itunes:title>
        <link>https://Paramify.podbean.com/e/16-exploring-the-fatal-funnel-of-sales-with-reade-king/</link>
                    <comments>https://Paramify.podbean.com/e/16-exploring-the-fatal-funnel-of-sales-with-reade-king/#comments</comments>        <pubDate>Fri, 26 Jan 2024 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/82cfcb24-70e6-3320-8e81-23da151e913b</guid>
                                    <description><![CDATA[<p>Today we had the honor to sit down with Reade King, a seasoned professional whose dynamic career spans over 15 years, including roles in the Department of Defense, and the Utah Army National Guard, and is now involved in the fast-paced world of SaaS startups. Reade brings a unique blend of strategic relationship-building and resilience honed in high-pressure environments to his current role in Sales Development at Anonyome Labs, Inc.</p>
<p>In our conversation, we talk about everything from the "color of money" to fixing trucks. Perhaps the most interesting concept we discuss is the concept of the "Fatal Funnel" – a term that Reade learned throughout his military training. Reade masterfully draws parallels between this concept and his approach to sales, providing insights into how recognizing and navigating through the 'fatal funnels' in sales processes can lead to more successful outcomes.</p>
<p>Learn more about Reade King: </p>
<p>Reade King's LinkedIn: https://www.linkedin.com/in/readeking/</p>
<p>Anonyome Labs: <a href='https://anonyome.com'>https://anonyome.com</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we had the honor to sit down with Reade King, a seasoned professional whose dynamic career spans over 15 years, including roles in the Department of Defense, and the Utah Army National Guard, and is now involved in the fast-paced world of SaaS startups. Reade brings a unique blend of strategic relationship-building and resilience honed in high-pressure environments to his current role in Sales Development at Anonyome Labs, Inc.</p>
<p>In our conversation, we talk about everything from the "color of money" to fixing trucks. Perhaps the most interesting concept we discuss is the concept of the "Fatal Funnel" – a term that Reade learned throughout his military training. Reade masterfully draws parallels between this concept and his approach to sales, providing insights into how recognizing and navigating through the 'fatal funnels' in sales processes can lead to more successful outcomes.</p>
<p>Learn more about Reade King: </p>
<p>Reade King's LinkedIn: https://www.linkedin.com/in/readeking/</p>
<p>Anonyome Labs: <a href='https://anonyome.com'>https://anonyome.com</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2hq6sd/The_Paramify_Podcast_with_Reade_Kingav1te.mp3" length="50530479" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we had the honor to sit down with Reade King, a seasoned professional whose dynamic career spans over 15 years, including roles in the Department of Defense, and the Utah Army National Guard, and is now involved in the fast-paced world of SaaS startups. Reade brings a unique blend of strategic relationship-building and resilience honed in high-pressure environments to his current role in Sales Development at Anonyome Labs, Inc.
In our conversation, we talk about everything from the "color of money" to fixing trucks. Perhaps the most interesting concept we discuss is the concept of the "Fatal Funnel" – a term that Reade learned throughout his military training. Reade masterfully draws parallels between this concept and his approach to sales, providing insights into how recognizing and navigating through the 'fatal funnels' in sales processes can lead to more successful outcomes.
Learn more about Reade King: 
Reade King's LinkedIn: https://www.linkedin.com/in/readeking/
Anonyome Labs: https://anonyome.com
 
Learn more about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3158</itunes:duration>
                <itunes:episode>16</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#15 - Discussing Cybersecurity with Frank Kyazze</title>
        <itunes:title>#15 - Discussing Cybersecurity with Frank Kyazze</itunes:title>
        <link>https://Paramify.podbean.com/e/15-discussing-cybersecurity-with-frank-kyazze/</link>
                    <comments>https://Paramify.podbean.com/e/15-discussing-cybersecurity-with-frank-kyazze/#comments</comments>        <pubDate>Fri, 12 Jan 2024 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/a40b4176-cce4-3e64-8234-20c246c2e58a</guid>
                                    <description><![CDATA[<p>Frank is a renowned expert in cybersecurity and Governance, Risk Management, and Compliance (GRC). As the Founder and CEO of GRC Knight, he has spearheaded the integration of advanced detection technologies with comprehensive security and privacy compliance consulting. His rich experience includes key roles at TrustCloud, Cognizant, and Schellman &amp; Company. In Today's episode, we talk about everything from CMMC 2.0, to our love of pizza.</p>
<p>Learn more about Frank Kyazze here:</p>
<p>Frank Kyazze's LinkedIn: <a href='https://www.linkedin.com/in/grcknight/'>https://www.linkedin.com/in/grcknight/ </a></p>
<p>GRC Knight's website: https://www.linkedin.com/company/grcknight/ GRC Knight's</p>
<p>CMMC white paper: <a href='https://44444846.fs1.hubspotusercontent-na1.net/hubfs/44444846/A%20CMMC%20Survival%20Guide%20for%20Companies.pdf'>https://44444846.fs1.hubspotusercontent-na1.net/hubfs/44444846/A%20CMMC%20Survival%20Guide%20for%20Companies.pdf</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Frank is a renowned expert in cybersecurity and Governance, Risk Management, and Compliance (GRC). As the Founder and CEO of GRC Knight, he has spearheaded the integration of advanced detection technologies with comprehensive security and privacy compliance consulting. His rich experience includes key roles at TrustCloud, Cognizant, and Schellman &amp; Company. In Today's episode, we talk about everything from CMMC 2.0, to our love of pizza.</p>
<p>Learn more about Frank Kyazze here:</p>
<p>Frank Kyazze's LinkedIn: <a href='https://www.linkedin.com/in/grcknight/'>https://www.linkedin.com/in/grcknight/ </a></p>
<p>GRC Knight's website: https://www.linkedin.com/company/grcknight/ GRC Knight's</p>
<p>CMMC white paper: <a href='https://44444846.fs1.hubspotusercontent-na1.net/hubfs/44444846/A%20CMMC%20Survival%20Guide%20for%20Companies.pdf'>https://44444846.fs1.hubspotusercontent-na1.net/hubfs/44444846/A%20CMMC%20Survival%20Guide%20for%20Companies.pdf</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ybp9k7/FRANK_PODCAST_2229120b.mp3" length="56616801" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Frank is a renowned expert in cybersecurity and Governance, Risk Management, and Compliance (GRC). As the Founder and CEO of GRC Knight, he has spearheaded the integration of advanced detection technologies with comprehensive security and privacy compliance consulting. His rich experience includes key roles at TrustCloud, Cognizant, and Schellman &amp; Company. In Today's episode, we talk about everything from CMMC 2.0, to our love of pizza.
Learn more about Frank Kyazze here:
Frank Kyazze's LinkedIn: https://www.linkedin.com/in/grcknight/ 
GRC Knight's website: https://www.linkedin.com/company/grcknight/ GRC Knight's
CMMC white paper: https://44444846.fs1.hubspotusercontent-na1.net/hubfs/44444846/A%20CMMC%20Survival%20Guide%20for%20Companies.pdf
 
Learn more about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3538</itunes:duration>
                <itunes:episode>15</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#14 - Discussing Cybersecurity with Josh Pugmire and Bryson Loughmiller</title>
        <itunes:title>#14 - Discussing Cybersecurity with Josh Pugmire and Bryson Loughmiller</itunes:title>
        <link>https://Paramify.podbean.com/e/14-discussing-cybersecurity-with-josh-pugmire-and-bryson-loughmiller/</link>
                    <comments>https://Paramify.podbean.com/e/14-discussing-cybersecurity-with-josh-pugmire-and-bryson-loughmiller/#comments</comments>        <pubDate>Fri, 29 Dec 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/74d59d44-3ae0-3562-96d6-d64c9d31f26e</guid>
                                    <description><![CDATA[<p>In today's episode, Kenny and Keaton talk with Josh Pugmire and Bryson Loughmiller. Both men are notable figures in cybersecurity, each boasting extensive careers marked by significant contributions to the field. Their expertise and experience have made them influential voices in cybersecurity circles.</p>
<p>Currently, they hold pivotal roles at Entrata, a leading technology company in the property management industry. Josh Pugmire serves as the Head of Compliance and Information Security, a role critical for ensuring that Entrata adheres to various cybersecurity standards and regulatory requirements. Josh is also a Board Member of SL|CISO a group that focuses on bringing the Utah InfoSec Community together and giving back to the next generation of Security Leadership and Practitioners.</p>
<p>In parallel Bryson Loughmiller occupies the position of Principal Platform Security Engineer, where he plays a key role in safeguarding Entrata's technology platforms against potential cybersecurity threats. Together, their work at Entrata exemplifies their commitment to maintaining robust cybersecurity frameworks and protecting sensitive information in a digitalized world.</p>
<p>Entrata's website: <a href='https://loom.ly/ZhLecww'>https://loom.ly/ZhLecww</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>SL|CISO's website: <a href='http://www.slciso.org/'>http://www.slciso.org</a></p>
<p>Josh Pugmire's LinkedIn: https://loom.ly/JcNW4VI</p>
<p>Bryson Loughmiller's LinkedIn: https://loom.ly/nBCdypc</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In today's episode, Kenny and Keaton talk with Josh Pugmire and Bryson Loughmiller. Both men are notable figures in cybersecurity, each boasting extensive careers marked by significant contributions to the field. Their expertise and experience have made them influential voices in cybersecurity circles.</p>
<p>Currently, they hold pivotal roles at Entrata, a leading technology company in the property management industry. Josh Pugmire serves as the Head of Compliance and Information Security, a role critical for ensuring that Entrata adheres to various cybersecurity standards and regulatory requirements. Josh is also a Board Member of SL|CISO a group that focuses on bringing the Utah InfoSec Community together and giving back to the next generation of Security Leadership and Practitioners.</p>
<p>In parallel Bryson Loughmiller occupies the position of Principal Platform Security Engineer, where he plays a key role in safeguarding Entrata's technology platforms against potential cybersecurity threats. Together, their work at Entrata exemplifies their commitment to maintaining robust cybersecurity frameworks and protecting sensitive information in a digitalized world.</p>
<p>Entrata's website: <a href='https://loom.ly/ZhLecww'>https://loom.ly/ZhLecww</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>SL|CISO's website: <a href='http://www.slciso.org/'>http://www.slciso.org</a></p>
<p>Josh Pugmire's LinkedIn: https://loom.ly/JcNW4VI</p>
<p>Bryson Loughmiller's LinkedIn: https://loom.ly/nBCdypc</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/y7v9kw/ENTRATA_PODCAST_ACutALLY_DONE6l7vg.mp3" length="42588419" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In today's episode, Kenny and Keaton talk with Josh Pugmire and Bryson Loughmiller. Both men are notable figures in cybersecurity, each boasting extensive careers marked by significant contributions to the field. Their expertise and experience have made them influential voices in cybersecurity circles.
Currently, they hold pivotal roles at Entrata, a leading technology company in the property management industry. Josh Pugmire serves as the Head of Compliance and Information Security, a role critical for ensuring that Entrata adheres to various cybersecurity standards and regulatory requirements. Josh is also a Board Member of SL|CISO a group that focuses on bringing the Utah InfoSec Community together and giving back to the next generation of Security Leadership and Practitioners.
In parallel Bryson Loughmiller occupies the position of Principal Platform Security Engineer, where he plays a key role in safeguarding Entrata's technology platforms against potential cybersecurity threats. Together, their work at Entrata exemplifies their commitment to maintaining robust cybersecurity frameworks and protecting sensitive information in a digitalized world.
Entrata's website: https://loom.ly/ZhLecww
 
Learn more about Paramify here: https://www.paramify.com/
SL|CISO's website: http://www.slciso.org
Josh Pugmire's LinkedIn: https://loom.ly/JcNW4VI
Bryson Loughmiller's LinkedIn: https://loom.ly/nBCdypc]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2661</itunes:duration>
                <itunes:episode>14</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#13 - Discussing The Future of AI and Recruiting with Neal Schmidt</title>
        <itunes:title>#13 - Discussing The Future of AI and Recruiting with Neal Schmidt</itunes:title>
        <link>https://Paramify.podbean.com/e/13-discussing-the-future-of-ai-and-recruiting-with-neal-schmidt/</link>
                    <comments>https://Paramify.podbean.com/e/13-discussing-the-future-of-ai-and-recruiting-with-neal-schmidt/#comments</comments>        <pubDate>Fri, 15 Dec 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/f2cf640c-82bb-3066-835b-2a18a91d2ce0</guid>
                                    <description><![CDATA[<p class="p1">In today's episode, we talk with Neal Schmidt, the Founder of <a href='https://www.linkedin.com/company/80788473/admin/feed/posts/?share=true'>ScreenDoor.ai</a>, about everything from our favorite concerts to where we think the future of AI and recruiting is going.</p>
<p class="p2"> </p>
<p class="p1">Neal Schmidt’s LinkedIn <a href='https://www.linkedin.com/in/nealschmidt/overlay/about-this-profile/'>https://www.linkedin.com/in/nealschmidt/overlay/about-this-profile/</a></p>
<p class="p3"> </p>
<p class="p1">Neal’s business: <a href='https://screendoor.ai/'>https://screendoor.ai/</a></p>
<p class="p1"> </p>
<p class="p1">Learn more about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p class="p1">In today's episode, we talk with Neal Schmidt, the Founder of <a href='https://www.linkedin.com/company/80788473/admin/feed/posts/?share=true'>ScreenDoor.ai</a>, about everything from our favorite concerts to where we think the future of AI and recruiting is going.</p>
<p class="p2"> </p>
<p class="p1">Neal Schmidt’s LinkedIn <a href='https://www.linkedin.com/in/nealschmidt/overlay/about-this-profile/'>https://www.linkedin.com/in/nealschmidt/overlay/about-this-profile/</a></p>
<p class="p3"> </p>
<p class="p1">Neal’s business: <a href='https://screendoor.ai/'>https://screendoor.ai/</a></p>
<p class="p1"> </p>
<p class="p1">Learn more about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ev32pt/The_Paramify_Podcast_with_NEAL_SCHMIDT_FINISHED8s4tw.mp3" length="65931021" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In today's episode, we talk with Neal Schmidt, the Founder of ScreenDoor.ai, about everything from our favorite concerts to where we think the future of AI and recruiting is going.
 
Neal Schmidt’s LinkedIn https://www.linkedin.com/in/nealschmidt/overlay/about-this-profile/
 
Neal’s business: https://screendoor.ai/
 
Learn more about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4120</itunes:duration>
                <itunes:episode>13</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#12 - Discussing Mentorship and Cybersecurity with Blake Entrekin</title>
        <itunes:title>#12 - Discussing Mentorship and Cybersecurity with Blake Entrekin</itunes:title>
        <link>https://Paramify.podbean.com/e/12-discussing-mentorship-and-cybersecurity-with-blake-entrekin/</link>
                    <comments>https://Paramify.podbean.com/e/12-discussing-mentorship-and-cybersecurity-with-blake-entrekin/#comments</comments>        <pubDate>Fri, 01 Dec 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/7bcb1dd9-04d3-3d23-a5d9-6dec6efdf6d5</guid>
                                    <description><![CDATA[<p>Blake Entrekin is an experienced Security Compliance leader with a notable 21-year tenure in the Security and Technology field, complemented by a decade of expertise as a people manager. He is currently the Director of Security Compliance at HackerOne.</p>
<p>In this episode, we discuss FedRAMP, compliance, cybersecurity, and the importance of having a mentor.</p>
<p>Learn more about Blake Entrekin:</p>
<p><a href='https://www.linkedin.com/in/blake-entrekin/'>https://www.linkedin.com/in/blake-entrekin/ </a></p>
<p>Blakes's blog post about the new NIST control around public disclosure programs: <a href='https://www.hackerone.com/security-compliance/nist-vdp-control'>https://www.hackerone.com/security-compliance/nist-vdp-control</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Blake Entrekin is an experienced Security Compliance leader with a notable 21-year tenure in the Security and Technology field, complemented by a decade of expertise as a people manager. He is currently the Director of Security Compliance at HackerOne.</p>
<p>In this episode, we discuss FedRAMP, compliance, cybersecurity, and the importance of having a mentor.</p>
<p>Learn more about Blake Entrekin:</p>
<p><a href='https://www.linkedin.com/in/blake-entrekin/'>https://www.linkedin.com/in/blake-entrekin/ </a></p>
<p>Blakes's blog post about the new NIST control around public disclosure programs: <a href='https://www.hackerone.com/security-compliance/nist-vdp-control'>https://www.hackerone.com/security-compliance/nist-vdp-control</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/psey4q/The_Paramify_Podcast_Episode_1263y1q.mp3" length="53078776" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Blake Entrekin is an experienced Security Compliance leader with a notable 21-year tenure in the Security and Technology field, complemented by a decade of expertise as a people manager. He is currently the Director of Security Compliance at HackerOne.
In this episode, we discuss FedRAMP, compliance, cybersecurity, and the importance of having a mentor.
Learn more about Blake Entrekin:
https://www.linkedin.com/in/blake-entrekin/ 
Blakes's blog post about the new NIST control around public disclosure programs: https://www.hackerone.com/security-compliance/nist-vdp-control
 
Learn more about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3317</itunes:duration>
                <itunes:episode>12</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#11 - Discussing Cybersecurity with Bryce Kunz</title>
        <itunes:title>#11 - Discussing Cybersecurity with Bryce Kunz</itunes:title>
        <link>https://Paramify.podbean.com/e/11-discussing-cybersecurity-with-bryce-kunz/</link>
                    <comments>https://Paramify.podbean.com/e/11-discussing-cybersecurity-with-bryce-kunz/#comments</comments>        <pubDate>Fri, 17 Nov 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/1984e82e-b43b-3413-8a9f-e154bf4927ec</guid>
                                    <description><![CDATA[<p>Bryce Kunz is a prominent Information Security Researcher and the Chief Security Officer (CSO) at UltraViolet Cyber. Renowned for his expertise in exploiting cloud environments, Bryce has a keen focus on critical systems like containers, orchestration systems, and web applications. His rich professional background spans across key agencies such as the NSA, DoD, DHS, and CBP, and extends into the tech industry with notable companies like Adobe. In his role at UltraViolet Cyber, Bryce combines his extensive experience in vulnerability research, penetration testing, and incident response to spearhead innovative cybersecurity strategies. His academic credentials are equally impressive, holding an MBA with a focus in Information Assurance (IA) from Idaho State University, a program recognized as a "Center of Excellence" by the NSA, backed by a full academic scholarship from the National Science Foundation (NSF). Bryce is also distinguished by his numerous certifications, including OSCP and CISSP, and is a recognized voice in the cybersecurity community, having spoken at prestigious conferences like BlackHat, DerbyCon, and BSidesLV.</p>
<p>Learn more about Bryce Kunz:</p>
<p>UltraVIolet Cyber: <a href='https://www.uvcyber.com/'>https://www.uvcyber.com/</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>Twitter: <a href='https://twitter.com/TweekFawkes'>https://twitter.com/TweekFawkes </a></p>
<p>LinkedIn: https://www.linkedin.com/in/brycekunz/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Bryce Kunz is a prominent Information Security Researcher and the Chief Security Officer (CSO) at UltraViolet Cyber. Renowned for his expertise in exploiting cloud environments, Bryce has a keen focus on critical systems like containers, orchestration systems, and web applications. His rich professional background spans across key agencies such as the NSA, DoD, DHS, and CBP, and extends into the tech industry with notable companies like Adobe. In his role at UltraViolet Cyber, Bryce combines his extensive experience in vulnerability research, penetration testing, and incident response to spearhead innovative cybersecurity strategies. His academic credentials are equally impressive, holding an MBA with a focus in Information Assurance (IA) from Idaho State University, a program recognized as a "Center of Excellence" by the NSA, backed by a full academic scholarship from the National Science Foundation (NSF). Bryce is also distinguished by his numerous certifications, including OSCP and CISSP, and is a recognized voice in the cybersecurity community, having spoken at prestigious conferences like BlackHat, DerbyCon, and BSidesLV.</p>
<p>Learn more about Bryce Kunz:</p>
<p>UltraVIolet Cyber: <a href='https://www.uvcyber.com/'>https://www.uvcyber.com/</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p>Twitter: <a href='https://twitter.com/TweekFawkes'>https://twitter.com/TweekFawkes </a></p>
<p>LinkedIn: https://www.linkedin.com/in/brycekunz/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rrvgdh/The_Paramify_Podcast_with_Bryce_Kunz_Done704kl.mp3" length="71909509" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Bryce Kunz is a prominent Information Security Researcher and the Chief Security Officer (CSO) at UltraViolet Cyber. Renowned for his expertise in exploiting cloud environments, Bryce has a keen focus on critical systems like containers, orchestration systems, and web applications. His rich professional background spans across key agencies such as the NSA, DoD, DHS, and CBP, and extends into the tech industry with notable companies like Adobe. In his role at UltraViolet Cyber, Bryce combines his extensive experience in vulnerability research, penetration testing, and incident response to spearhead innovative cybersecurity strategies. His academic credentials are equally impressive, holding an MBA with a focus in Information Assurance (IA) from Idaho State University, a program recognized as a "Center of Excellence" by the NSA, backed by a full academic scholarship from the National Science Foundation (NSF). Bryce is also distinguished by his numerous certifications, including OSCP and CISSP, and is a recognized voice in the cybersecurity community, having spoken at prestigious conferences like BlackHat, DerbyCon, and BSidesLV.
Learn more about Bryce Kunz:
UltraVIolet Cyber: https://www.uvcyber.com/
 
Learn more about Paramify here: https://www.paramify.com/
Twitter: https://twitter.com/TweekFawkes 
LinkedIn: https://www.linkedin.com/in/brycekunz/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4494</itunes:duration>
                <itunes:episode>11</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#10 - Exploring Joshua Baron’s Transition to a Referral Based Business</title>
        <itunes:title>#10 - Exploring Joshua Baron’s Transition to a Referral Based Business</itunes:title>
        <link>https://Paramify.podbean.com/e/10-exploring-joshua-baron-s-transition-to-a-referral-based-business/</link>
                    <comments>https://Paramify.podbean.com/e/10-exploring-joshua-baron-s-transition-to-a-referral-based-business/#comments</comments>        <pubDate>Fri, 03 Nov 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/25041a76-4d70-33fc-9b94-44f89383cff4</guid>
                                    <description><![CDATA[<p>In today's episode, we sit down with seasoned criminal defense attorney, Joshua Baron, to delve into his journey of transitioning his law practice from being heavily ad-dependent to thriving on referrals.</p>
<p>When the COVID-19 pandemic hit and courtrooms shuttered, Joshua was faced with the daunting task of keeping his practice afloat amidst dwindling ad returns. His narrative of adaptation from spending over $30,000 monthly on ads to building a sustainable referral-based business model is nothing short of inspiring.</p>
<p>Get Joshua Baron's Book "The Business of Criminal Law: How to Build a Criminal Defense Practice You and Your Clients Will Love" here: <a href='https://www.amazon.com/dp/1521853576/ref=tsm_1_fb_lk'>https://www.amazon.com/dp/1521853576/ref=tsm_1_fb_lk</a></p>
<p>Joshua Baron's LinkedIn: <a href='https://www.linkedin.com/in/joshuabaron/'>https://www.linkedin.com/in/joshuabaron/</a></p>
<p>Joshua Baron's News Letter:<a href='https://businessofcriminallaw.substack.com/'>https://businessofcriminallaw.substack.com/</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In today's episode, we sit down with seasoned criminal defense attorney, Joshua Baron, to delve into his journey of transitioning his law practice from being heavily ad-dependent to thriving on referrals.</p>
<p>When the COVID-19 pandemic hit and courtrooms shuttered, Joshua was faced with the daunting task of keeping his practice afloat amidst dwindling ad returns. His narrative of adaptation from spending over $30,000 monthly on ads to building a sustainable referral-based business model is nothing short of inspiring.</p>
<p>Get Joshua Baron's Book "The Business of Criminal Law: How to Build a Criminal Defense Practice You and Your Clients Will Love" here: <a href='https://www.amazon.com/dp/1521853576/ref=tsm_1_fb_lk'>https://www.amazon.com/dp/1521853576/ref=tsm_1_fb_lk</a></p>
<p>Joshua Baron's LinkedIn: <a href='https://www.linkedin.com/in/joshuabaron/'>https://www.linkedin.com/in/joshuabaron/</a></p>
<p>Joshua Baron's News Letter:<a href='https://businessofcriminallaw.substack.com/'>https://businessofcriminallaw.substack.com/</a></p>
<p> </p>
<p>Learn more about Paramify here: https://www.paramify.com/</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zsq8gy/The_Paramify_Podcast_JOSHUA_BARON_Done_real18t79o.mp3" length="67647579" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In today's episode, we sit down with seasoned criminal defense attorney, Joshua Baron, to delve into his journey of transitioning his law practice from being heavily ad-dependent to thriving on referrals.
When the COVID-19 pandemic hit and courtrooms shuttered, Joshua was faced with the daunting task of keeping his practice afloat amidst dwindling ad returns. His narrative of adaptation from spending over $30,000 monthly on ads to building a sustainable referral-based business model is nothing short of inspiring.
Get Joshua Baron's Book "The Business of Criminal Law: How to Build a Criminal Defense Practice You and Your Clients Will Love" here: https://www.amazon.com/dp/1521853576/ref=tsm_1_fb_lk
Joshua Baron's LinkedIn: https://www.linkedin.com/in/joshuabaron/
Joshua Baron's News Letter:https://businessofcriminallaw.substack.com/
 
Learn more about Paramify here: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4227</itunes:duration>
                <itunes:episode>10</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#9 - Discussing Information Security with Ryan Jamieson</title>
        <itunes:title>#9 - Discussing Information Security with Ryan Jamieson</itunes:title>
        <link>https://Paramify.podbean.com/e/9-discussing-information-security-with-ryan-jamieson/</link>
                    <comments>https://Paramify.podbean.com/e/9-discussing-information-security-with-ryan-jamieson/#comments</comments>        <pubDate>Fri, 20 Oct 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/4b997c2b-989d-3a21-b742-bd70599d86b5</guid>
                                    <description><![CDATA[<p>In this episode of The Paramify Podcast, Kenny Scott talks with Ryan Jamieson, founder of Knit Security, about moving beyond compliance to achieve robust security. They discuss the challenges posed by security questionnaires and share practical advice on how to build a solid security posture aligned with business operations. Ryan also sheds light on his approach at Knit Security to ensure a company's security measures are in tune with its core business processes. Tune in for an enlightening discussion on making security work in the real world.</p>
<p>Ryan Jamieson's LinkedIn: <a href='https://www.linkedin.com/in/ryanjamieson/'>https://www.linkedin.com/in/ryanjamieson/</a></p>
<p>Knit Security: <a href='https://www.knitsec.com/'>https://www.knitsec.com/</a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode of The Paramify Podcast, Kenny Scott talks with Ryan Jamieson, founder of Knit Security, about moving beyond compliance to achieve robust security. They discuss the challenges posed by security questionnaires and share practical advice on how to build a solid security posture aligned with business operations. Ryan also sheds light on his approach at Knit Security to ensure a company's security measures are in tune with its core business processes. Tune in for an enlightening discussion on making security work in the real world.</p>
<p>Ryan Jamieson's LinkedIn: <a href='https://www.linkedin.com/in/ryanjamieson/'>https://www.linkedin.com/in/ryanjamieson/</a></p>
<p>Knit Security: <a href='https://www.knitsec.com/'>https://www.knitsec.com/</a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ue8f97/THE_PARAMIFY_PODCAST_EPISODE_9_AUDIObhv4x.mp3" length="40863501" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of The Paramify Podcast, Kenny Scott talks with Ryan Jamieson, founder of Knit Security, about moving beyond compliance to achieve robust security. They discuss the challenges posed by security questionnaires and share practical advice on how to build a solid security posture aligned with business operations. Ryan also sheds light on his approach at Knit Security to ensure a company's security measures are in tune with its core business processes. Tune in for an enlightening discussion on making security work in the real world.
Ryan Jamieson's LinkedIn: https://www.linkedin.com/in/ryanjamieson/
Knit Security: https://www.knitsec.com/
Learn more about Paramify here: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2553</itunes:duration>
                <itunes:episode>9</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#8 - A Journey into Information Security with Derek Espiritu</title>
        <itunes:title>#8 - A Journey into Information Security with Derek Espiritu</itunes:title>
        <link>https://Paramify.podbean.com/e/8-a-journey-into-information-security-with-derek-espiritu/</link>
                    <comments>https://Paramify.podbean.com/e/8-a-journey-into-information-security-with-derek-espiritu/#comments</comments>        <pubDate>Fri, 06 Oct 2023 10:45:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/3e387ffd-22b8-3ab4-8261-99f6a09d5990</guid>
                                    <description><![CDATA[<p>Charting a successful trajectory in information security isn't a straightforward task, and who better to shed light on this journey than Derek Espiritu? In this insightful episode of The Paramify Podcast, hosts Kenny Scott and Keaton Olson explore Derek's path into the world of cybersecurity. Derek shares his experiences from working with renowned companies like Labelbox, Adobe, Anglepoint, and Symantec. From his early days in the industry to the milestones he achieved along the way, Derek's candid narrative provides a unique blend of inspiration and practical insights.</p>
<p>Want to delve even deeper into Derek's story? Join him at SAINTCON 2023 in Provo, Utah on October 24th at 11:30 am, where he'll further discuss "Breaking Into Cyber Security." Witness firsthand the expertise he garnered from years in the field and the major players he collaborated with. https://www.saintcon.org/speakers/</p>
<p>Derek's LinkedIn: https://www.linkedin.com/in/derek-espiritu-1011a7110/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Charting a successful trajectory in information security isn't a straightforward task, and who better to shed light on this journey than Derek Espiritu? In this insightful episode of The Paramify Podcast, hosts Kenny Scott and Keaton Olson explore Derek's path into the world of cybersecurity. Derek shares his experiences from working with renowned companies like Labelbox, Adobe, Anglepoint, and Symantec. From his early days in the industry to the milestones he achieved along the way, Derek's candid narrative provides a unique blend of inspiration and practical insights.</p>
<p>Want to delve even deeper into Derek's story? Join him at SAINTCON 2023 in Provo, Utah on October 24th at 11:30 am, where he'll further discuss "Breaking Into Cyber Security." Witness firsthand the expertise he garnered from years in the field and the major players he collaborated with. https://www.saintcon.org/speakers/</p>
<p>Derek's LinkedIn: https://www.linkedin.com/in/derek-espiritu-1011a7110/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/auxmqa/The_Paramify_Podcast_Derek_es_REAL_DONE_AUDIO_ath67.mp3" length="45190632" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Charting a successful trajectory in information security isn't a straightforward task, and who better to shed light on this journey than Derek Espiritu? In this insightful episode of The Paramify Podcast, hosts Kenny Scott and Keaton Olson explore Derek's path into the world of cybersecurity. Derek shares his experiences from working with renowned companies like Labelbox, Adobe, Anglepoint, and Symantec. From his early days in the industry to the milestones he achieved along the way, Derek's candid narrative provides a unique blend of inspiration and practical insights.
Want to delve even deeper into Derek's story? Join him at SAINTCON 2023 in Provo, Utah on October 24th at 11:30 am, where he'll further discuss "Breaking Into Cyber Security." Witness firsthand the expertise he garnered from years in the field and the major players he collaborated with. https://www.saintcon.org/speakers/
Derek's LinkedIn: https://www.linkedin.com/in/derek-espiritu-1011a7110/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2824</itunes:duration>
                <itunes:episode>8</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#7 - Discussing Information Security with Isaac Painter</title>
        <itunes:title>#7 - Discussing Information Security with Isaac Painter</itunes:title>
        <link>https://Paramify.podbean.com/e/7-discussing-information-security-with-isaac-painter/</link>
                    <comments>https://Paramify.podbean.com/e/7-discussing-information-security-with-isaac-painter/#comments</comments>        <pubDate>Fri, 22 Sep 2023 09:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/676c8b89-a327-3f57-bd58-e60d875ad73f</guid>
                                    <description><![CDATA[<p>Today, we were privileged to sit down with Isaac Painter. An established figure in information security, Isaac boasts an impressive trajectory that includes stints at industry giants like Adobe and Aumni. His deep-rooted expertise and insights from various roles provide a rich backdrop for an enlightening conversation.</p>
<p>Isaac Painters LinkedIn: <a href='https://www.linkedin.com/in/isaac-painter-3861ab15/'>https://www.linkedin.com/in/isaac-painter-3861ab15/ </a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, we were privileged to sit down with Isaac Painter. An established figure in information security, Isaac boasts an impressive trajectory that includes stints at industry giants like Adobe and Aumni. His deep-rooted expertise and insights from various roles provide a rich backdrop for an enlightening conversation.</p>
<p>Isaac Painters LinkedIn: <a href='https://www.linkedin.com/in/isaac-painter-3861ab15/'>https://www.linkedin.com/in/isaac-painter-3861ab15/ </a></p>
<p>Learn more about Paramify here: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fuuvct/The_PAramify_Podcast_episode_7_FULL_AUDIOb7dd3.mp3" length="42105258" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, we were privileged to sit down with Isaac Painter. An established figure in information security, Isaac boasts an impressive trajectory that includes stints at industry giants like Adobe and Aumni. His deep-rooted expertise and insights from various roles provide a rich backdrop for an enlightening conversation.
Isaac Painters LinkedIn: https://www.linkedin.com/in/isaac-painter-3861ab15/ 
Learn more about Paramify here: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2631</itunes:duration>
                <itunes:episode>7</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#6 - Discussing the Future of Sales with Next LvL AI</title>
        <itunes:title>#6 - Discussing the Future of Sales with Next LvL AI</itunes:title>
        <link>https://Paramify.podbean.com/e/6-discussing-the-future-of-sales-with-next-lvl-ai/</link>
                    <comments>https://Paramify.podbean.com/e/6-discussing-the-future-of-sales-with-next-lvl-ai/#comments</comments>        <pubDate>Fri, 08 Sep 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/3d1a86df-010c-39fb-81d6-3f7233b1a8c8</guid>
                                    <description><![CDATA[<p>Today we are joined by our good friends Tanner Green, and Dan Robinson of Next Lvl AI. We talk about everything from changing the cringe nature of LinkedIn through an AI bot to the theoretical possibilities of AI.</p>
<p>Tanner Green is the visionary founder and CEO of Next LvL Ai. Next LvL AI has merged AI's brilliance with sales to optimize representative interactions. Beyond technological prowess, he showcased his commitment to personal growth at Catalyst Life Coaching, guiding many through their life challenges. His stint as a software engineer at Domino Data Lab saw him significantly amplify search speeds and forge a partnership with Nvidia. Not one to rest on his laurels, Tanner dabbled in cryptocurrency with CryptoClock, capturing RevRoad's interest. His academic achievements at BYU are underscored by leading UAV projects and captaining the Mars Rover Team to global recognition. With foundational learning from Utah Valley University, Tanner is a blend of tech savviness and leadership. Tanner Green's LinkedIn: <a href='https://www.linkedin.com/in/tanner-green-213a62137/'>https://www.linkedin.com/in/tanner-green-213a62137/ </a></p>
<p>Daniel Robinson is not only an adept software engineer but also the dynamic Co-founder of Next LvL Ai, a pioneering venture sculpting the future of AI-driven solutions. Before embarking on this journey, Daniel wore several prestigious hats, from being the Founding Engineer at DAOhub to delving deep into e-commerce as a Full Stack Engineer for Shopswap. His stint with Fragmints NFT showcases his adaptability, maneuvering through the dynamic world of non-fungible tokens. Daniel kickstarted his professional odyssey with Current Technologies, refining his skills and setting the stage for his future endeavors. Beyond his tech expertise, Daniel boasts a solid academic foundation in Finance from the Jon M. Huntsman School of Business at Utah State University, revealing a rare blend of financial acumen and technological prowess. Daniel Robinson's LinkedIn: <a href='https://www.linkedin.com/in/danielrobinson94/'>https://www.linkedin.com/in/danielrobinson94/ </a></p>
<p>Next LvL AI is revolutionizing the sales ecosystem with its groundbreaking flowchart software. Expertly crafted to integrate effortlessly with CRMs, sales methodologies, and complex workflows, this platform aims to illuminate and optimize the sales journey. Users can anticipate clarity in their sales processes, giving them real-time insights into each deal's progression, and unlocking strategies to enhance efficiency and revenue growth. One standout feature is its ability to foster accountability among sales reps without imposing undue pressure, making it simpler for them to manage tasks and finalize deals. Furthermore, sales consistency is no longer a distant dream; with automatic CRM updates facilitated by Next LvL AI, the era of unreliable data is consigned to the past. For businesses seeking to elevate their sales game, Next LvL AI stands out as the premier choice.</p>
<p>Next LvL AI's Website: <a href='https://www.nextlvlai.com/'>https://www.nextlvlai.com/ </a></p>
<p>Next LvL AI's LinkedIn: <a href='https://www.linkedin.com/company/next-lvl-ai/'>https://www.linkedin.com/company/next-lvl-ai/ </a></p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today we are joined by our good friends Tanner Green, and Dan Robinson of Next Lvl AI. We talk about everything from changing the cringe nature of LinkedIn through an AI bot to the theoretical possibilities of AI.</p>
<p>Tanner Green is the visionary founder and CEO of Next LvL Ai. Next LvL AI has merged AI's brilliance with sales to optimize representative interactions. Beyond technological prowess, he showcased his commitment to personal growth at Catalyst Life Coaching, guiding many through their life challenges. His stint as a software engineer at Domino Data Lab saw him significantly amplify search speeds and forge a partnership with Nvidia. Not one to rest on his laurels, Tanner dabbled in cryptocurrency with CryptoClock, capturing RevRoad's interest. His academic achievements at BYU are underscored by leading UAV projects and captaining the Mars Rover Team to global recognition. With foundational learning from Utah Valley University, Tanner is a blend of tech savviness and leadership. Tanner Green's LinkedIn: <a href='https://www.linkedin.com/in/tanner-green-213a62137/'>https://www.linkedin.com/in/tanner-green-213a62137/ </a></p>
<p>Daniel Robinson is not only an adept software engineer but also the dynamic Co-founder of Next LvL Ai, a pioneering venture sculpting the future of AI-driven solutions. Before embarking on this journey, Daniel wore several prestigious hats, from being the Founding Engineer at DAOhub to delving deep into e-commerce as a Full Stack Engineer for Shopswap. His stint with Fragmints NFT showcases his adaptability, maneuvering through the dynamic world of non-fungible tokens. Daniel kickstarted his professional odyssey with Current Technologies, refining his skills and setting the stage for his future endeavors. Beyond his tech expertise, Daniel boasts a solid academic foundation in Finance from the Jon M. Huntsman School of Business at Utah State University, revealing a rare blend of financial acumen and technological prowess. Daniel Robinson's LinkedIn: <a href='https://www.linkedin.com/in/danielrobinson94/'>https://www.linkedin.com/in/danielrobinson94/ </a></p>
<p>Next LvL AI is revolutionizing the sales ecosystem with its groundbreaking flowchart software. Expertly crafted to integrate effortlessly with CRMs, sales methodologies, and complex workflows, this platform aims to illuminate and optimize the sales journey. Users can anticipate clarity in their sales processes, giving them real-time insights into each deal's progression, and unlocking strategies to enhance efficiency and revenue growth. One standout feature is its ability to foster accountability among sales reps without imposing undue pressure, making it simpler for them to manage tasks and finalize deals. Furthermore, sales consistency is no longer a distant dream; with automatic CRM updates facilitated by Next LvL AI, the era of unreliable data is consigned to the past. For businesses seeking to elevate their sales game, Next LvL AI stands out as the premier choice.</p>
<p>Next LvL AI's Website: <a href='https://www.nextlvlai.com/'>https://www.nextlvlai.com/ </a></p>
<p>Next LvL AI's LinkedIn: <a href='https://www.linkedin.com/company/next-lvl-ai/'>https://www.linkedin.com/company/next-lvl-ai/ </a></p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qxxr83/THE_PARAMIFY_PODCAST_EPISODE_6_AUDIO8zf17.mp3" length="44079279" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today we are joined by our good friends Tanner Green, and Dan Robinson of Next Lvl AI. We talk about everything from changing the cringe nature of LinkedIn through an AI bot to the theoretical possibilities of AI.
Tanner Green is the visionary founder and CEO of Next LvL Ai. Next LvL AI has merged AI's brilliance with sales to optimize representative interactions. Beyond technological prowess, he showcased his commitment to personal growth at Catalyst Life Coaching, guiding many through their life challenges. His stint as a software engineer at Domino Data Lab saw him significantly amplify search speeds and forge a partnership with Nvidia. Not one to rest on his laurels, Tanner dabbled in cryptocurrency with CryptoClock, capturing RevRoad's interest. His academic achievements at BYU are underscored by leading UAV projects and captaining the Mars Rover Team to global recognition. With foundational learning from Utah Valley University, Tanner is a blend of tech savviness and leadership. Tanner Green's LinkedIn: https://www.linkedin.com/in/tanner-green-213a62137/ 
Daniel Robinson is not only an adept software engineer but also the dynamic Co-founder of Next LvL Ai, a pioneering venture sculpting the future of AI-driven solutions. Before embarking on this journey, Daniel wore several prestigious hats, from being the Founding Engineer at DAOhub to delving deep into e-commerce as a Full Stack Engineer for Shopswap. His stint with Fragmints NFT showcases his adaptability, maneuvering through the dynamic world of non-fungible tokens. Daniel kickstarted his professional odyssey with Current Technologies, refining his skills and setting the stage for his future endeavors. Beyond his tech expertise, Daniel boasts a solid academic foundation in Finance from the Jon M. Huntsman School of Business at Utah State University, revealing a rare blend of financial acumen and technological prowess. Daniel Robinson's LinkedIn: https://www.linkedin.com/in/danielrobinson94/ 
Next LvL AI is revolutionizing the sales ecosystem with its groundbreaking flowchart software. Expertly crafted to integrate effortlessly with CRMs, sales methodologies, and complex workflows, this platform aims to illuminate and optimize the sales journey. Users can anticipate clarity in their sales processes, giving them real-time insights into each deal's progression, and unlocking strategies to enhance efficiency and revenue growth. One standout feature is its ability to foster accountability among sales reps without imposing undue pressure, making it simpler for them to manage tasks and finalize deals. Furthermore, sales consistency is no longer a distant dream; with automatic CRM updates facilitated by Next LvL AI, the era of unreliable data is consigned to the past. For businesses seeking to elevate their sales game, Next LvL AI stands out as the premier choice.
Next LvL AI's Website: https://www.nextlvlai.com/ 
Next LvL AI's LinkedIn: https://www.linkedin.com/company/next-lvl-ai/ 
Learn more about Paramify: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2754</itunes:duration>
                <itunes:episode>6</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#5 - Exploring FedRAMP Rev 5 With Christian Hansen</title>
        <itunes:title>#5 - Exploring FedRAMP Rev 5 With Christian Hansen</itunes:title>
        <link>https://Paramify.podbean.com/e/5-exploring-fedramp-rev-5-with-christian-hansen/</link>
                    <comments>https://Paramify.podbean.com/e/5-exploring-fedramp-rev-5-with-christian-hansen/#comments</comments>        <pubDate>Fri, 25 Aug 2023 11:07:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/5b15ace6-a277-3584-8198-643518b3b91e</guid>
                                    <description><![CDATA[<p>In this episode, we host Christian Hansen of Moss Adams. Christian delves into his foundational years in cybersecurity and traces his professional trajectory that led him to his current role. As an expert on FedRAMP, he provides an in-depth analysis of the recent changes introduced with FedRAMP Rev 5. Join us for an informative session with a leading expert in the field.</p>
<p>Christian Hansen's LinkedIn: <a href='https://www.linkedin.com/in/christian-hansen-3570b98/'>https://www.linkedin.com/in/christian-hansen-3570b98/</a></p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, we host Christian Hansen of Moss Adams. Christian delves into his foundational years in cybersecurity and traces his professional trajectory that led him to his current role. As an expert on FedRAMP, he provides an in-depth analysis of the recent changes introduced with FedRAMP Rev 5. Join us for an informative session with a leading expert in the field.</p>
<p>Christian Hansen's LinkedIn: <a href='https://www.linkedin.com/in/christian-hansen-3570b98/'>https://www.linkedin.com/in/christian-hansen-3570b98/</a></p>
<p>Learn more about Paramify: <a href='https://www.paramify.com/'>https://www.paramify.com/</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vdyz7q/The_Paramify_Podcast_Episode_5_Audio_a91z7.mp3" length="78572945" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, we host Christian Hansen of Moss Adams. Christian delves into his foundational years in cybersecurity and traces his professional trajectory that led him to his current role. As an expert on FedRAMP, he provides an in-depth analysis of the recent changes introduced with FedRAMP Rev 5. Join us for an informative session with a leading expert in the field.
Christian Hansen's LinkedIn: https://www.linkedin.com/in/christian-hansen-3570b98/
Learn more about Paramify: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3271</itunes:duration>
                <itunes:episode>5</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#4 - Becoming a CISO with Debra Baker</title>
        <itunes:title>#4 - Becoming a CISO with Debra Baker</itunes:title>
        <link>https://Paramify.podbean.com/e/4-becoming-a-ciso-with-debra-baker/</link>
                    <comments>https://Paramify.podbean.com/e/4-becoming-a-ciso-with-debra-baker/#comments</comments>        <pubDate>Fri, 11 Aug 2023 11:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/90cfc1a4-32bd-35d7-a6e7-5adf7e317aff</guid>
                                    <description><![CDATA[<p>Today Kenny talks to Debra Baker. Debra Baker is a passionate Cybersecurity Professional with over 20 years experience in multi-faceted, complex, fast-paced environments in the public and private sectors. Debra excels in Risk Management and Compliance with proven leadership experience on issues concerning information security. In her most recent role, she was the Director of Information Security (CISO) at RedSeal, Inc. She built the SOC2 program and within 6 months achieved SOC2 compliance for RedSeal's SaaS product Stratus. She built the information security program at RedSeal and managed all GRC (CC, FIPS, SOC2, FedRAMP, and GDPR) as well as third-party vendor risk assessments, wrote the security policies, and managed the information security awareness program. She is a critical thinker, connector, innovator, and an effective translator between technical and non-technical entities in Cybersecurity.</p>
<p>LEARN MORE about Debra Baker:</p>
<p><a href='https://trustedciso.com/'>https://trustedciso.com/ </a></p>
<p><a href='https://www.linkedin.com/in/debrabakernc/'>https://www.linkedin.com/in/debrabakernc/</a></p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today Kenny talks to Debra Baker. Debra Baker is a passionate Cybersecurity Professional with over 20 years experience in multi-faceted, complex, fast-paced environments in the public and private sectors. Debra excels in Risk Management and Compliance with proven leadership experience on issues concerning information security. In her most recent role, she was the Director of Information Security (CISO) at RedSeal, Inc. She built the SOC2 program and within 6 months achieved SOC2 compliance for RedSeal's SaaS product Stratus. She built the information security program at RedSeal and managed all GRC (CC, FIPS, SOC2, FedRAMP, and GDPR) as well as third-party vendor risk assessments, wrote the security policies, and managed the information security awareness program. She is a critical thinker, connector, innovator, and an effective translator between technical and non-technical entities in Cybersecurity.</p>
<p>LEARN MORE about Debra Baker:</p>
<p><a href='https://trustedciso.com/'>https://trustedciso.com/ </a></p>
<p><a href='https://www.linkedin.com/in/debrabakernc/'>https://www.linkedin.com/in/debrabakernc/</a></p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/36zmnq/EPISODE_4_DEBRA_AUDIO_6k4wh.mp3" length="54819434" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today Kenny talks to Debra Baker. Debra Baker is a passionate Cybersecurity Professional with over 20 years experience in multi-faceted, complex, fast-paced environments in the public and private sectors. Debra excels in Risk Management and Compliance with proven leadership experience on issues concerning information security. In her most recent role, she was the Director of Information Security (CISO) at RedSeal, Inc. She built the SOC2 program and within 6 months achieved SOC2 compliance for RedSeal's SaaS product Stratus. She built the information security program at RedSeal and managed all GRC (CC, FIPS, SOC2, FedRAMP, and GDPR) as well as third-party vendor risk assessments, wrote the security policies, and managed the information security awareness program. She is a critical thinker, connector, innovator, and an effective translator between technical and non-technical entities in Cybersecurity.
LEARN MORE about Debra Baker:
https://trustedciso.com/ 
https://www.linkedin.com/in/debrabakernc/
 
LEARN MORE about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2283</itunes:duration>
                <itunes:episode>4</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#3 - Kenny’s Backstory Pt. 2</title>
        <itunes:title>#3 - Kenny’s Backstory Pt. 2</itunes:title>
        <link>https://Paramify.podbean.com/e/3-kenny-s-backstory-pt2/</link>
                    <comments>https://Paramify.podbean.com/e/3-kenny-s-backstory-pt2/#comments</comments>        <pubDate>Fri, 28 Jul 2023 11:17:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/fcbd1339-1a4b-3d46-a485-5bd229d3d05c</guid>
                                    <description><![CDATA[<p>Today, Keaton &amp; Adam talk to Kenny about his interesting past, from being a pioneer for the Adobe Common Controls Framework to starting a hedge fund, and what ultimately led Kenny to start Paramify.</p>
<p>Learn more about Paramify on our website: www.paramify.com</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, Keaton &amp; Adam talk to Kenny about his interesting past, from being a pioneer for the Adobe Common Controls Framework to starting a hedge fund, and what ultimately led Kenny to start Paramify.</p>
<p>Learn more about Paramify on our website: www.paramify.com</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vq7ftb/EPISODE_3_AUDIOb4tis.mp3" length="51842111" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, Keaton &amp; Adam talk to Kenny about his interesting past, from being a pioneer for the Adobe Common Controls Framework to starting a hedge fund, and what ultimately led Kenny to start Paramify.
Learn more about Paramify on our website: www.paramify.com]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2159</itunes:duration>
                <itunes:episode>3</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#2 - Using AI Securely with Walter Haydock</title>
        <itunes:title>#2 - Using AI Securely with Walter Haydock</itunes:title>
        <link>https://Paramify.podbean.com/e/2-using-ai-securely-with-walter-haydock/</link>
                    <comments>https://Paramify.podbean.com/e/2-using-ai-securely-with-walter-haydock/#comments</comments>        <pubDate>Fri, 14 Jul 2023 09:00:00 -0600</pubDate>
        <guid isPermaLink="false">Paramify.podbean.com/b343c734-d73c-3ce6-b171-5ad78240b14f</guid>
                                    <description><![CDATA[<p>Walter Haydock is a dynamic and multifaceted professional specializing in the intersection of cybersecurity and artificial intelligence. As the founder and CEO of StackAware, Walter leverages industry-standard frameworks, his own extensive experience, and responsible use of AI tools to help businesses manage AI-related cybersecurity, privacy, and compliance risks. Through StackAware, businesses can harness the power of new technologies by building effective and repeatable AI risk management programs.</p>
<p>Additionally, in his role as a Cybersecurity Author, Consultant, and Ghostwriter for Deploy Securely, Walter utilizes his expertise to transform cybersecurity CEOs into thought leaders within the industry. His approach includes driving inbound leads through consistent LinkedIn posting, nurturing them with expertly written long-form content, and converting prospects into customers by demonstrating value. His broad set of skills includes data privacy, AI, cybersecurity, regulatory compliance, product development, enterprise software, and cross-functional team leadership.</p>
<p>With his entrepreneurial spirit and a strong commitment to cybersecurity and AI, Walter continues to be a vital resource for businesses navigating the complexities of today's technological landscape.</p>
<p>Learn more about Walter Haydock and his businesses through the links below:</p>
<a href='https://maven.com/harness-ai/ai-security'>AI security course</a>
 
<a href='http://haydock.substack.com/'>Deploy Securely blog</a>
 
<a href='https://vulnerability.management/'>StackAware's free quantitative vulnerability management email course</a>
<p> </p>
<p>Walter Haydock's LinkedIn: <a href='https://www.linkedin.com/in/walter-haydock/'>https://www.linkedin.com/in/walter-haydock/</a></p>
<p> </p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Walter Haydock is a dynamic and multifaceted professional specializing in the intersection of cybersecurity and artificial intelligence. As the founder and CEO of StackAware, Walter leverages industry-standard frameworks, his own extensive experience, and responsible use of AI tools to help businesses manage AI-related cybersecurity, privacy, and compliance risks. Through StackAware, businesses can harness the power of new technologies by building effective and repeatable AI risk management programs.</p>
<p>Additionally, in his role as a Cybersecurity Author, Consultant, and Ghostwriter for Deploy Securely, Walter utilizes his expertise to transform cybersecurity CEOs into thought leaders within the industry. His approach includes driving inbound leads through consistent LinkedIn posting, nurturing them with expertly written long-form content, and converting prospects into customers by demonstrating value. His broad set of skills includes data privacy, AI, cybersecurity, regulatory compliance, product development, enterprise software, and cross-functional team leadership.</p>
<p>With his entrepreneurial spirit and a strong commitment to cybersecurity and AI, Walter continues to be a vital resource for businesses navigating the complexities of today's technological landscape.</p>
<p>Learn more about Walter Haydock and his businesses through the links below:</p>
<a href='https://maven.com/harness-ai/ai-security'>AI security course</a>
 
<a href='http://haydock.substack.com/'>Deploy Securely blog</a>
 
<a href='https://vulnerability.management/'>StackAware's free quantitative vulnerability management email course</a>
<p> </p>
<p>Walter Haydock's LinkedIn: <a href='https://www.linkedin.com/in/walter-haydock/'>https://www.linkedin.com/in/walter-haydock/</a></p>
<p> </p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8evswi/The_Paramify_Podcast_Episode_2_FULL_Walter_Haydock_AUDIO_buhxe.mp3" length="62461213" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Walter Haydock is a dynamic and multifaceted professional specializing in the intersection of cybersecurity and artificial intelligence. As the founder and CEO of StackAware, Walter leverages industry-standard frameworks, his own extensive experience, and responsible use of AI tools to help businesses manage AI-related cybersecurity, privacy, and compliance risks. Through StackAware, businesses can harness the power of new technologies by building effective and repeatable AI risk management programs.
Additionally, in his role as a Cybersecurity Author, Consultant, and Ghostwriter for Deploy Securely, Walter utilizes his expertise to transform cybersecurity CEOs into thought leaders within the industry. His approach includes driving inbound leads through consistent LinkedIn posting, nurturing them with expertly written long-form content, and converting prospects into customers by demonstrating value. His broad set of skills includes data privacy, AI, cybersecurity, regulatory compliance, product development, enterprise software, and cross-functional team leadership.
With his entrepreneurial spirit and a strong commitment to cybersecurity and AI, Walter continues to be a vital resource for businesses navigating the complexities of today's technological landscape.
Learn more about Walter Haydock and his businesses through the links below:
AI security course
 
Deploy Securely blog
 
StackAware's free quantitative vulnerability management email course
 
Walter Haydock's LinkedIn: https://www.linkedin.com/in/walter-haydock/
 
 
LEARN MORE about Paramify here: https://www.paramify.com/
 ]]></itunes:summary>
        <itunes:author>Paramify</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2602</itunes:duration>
                <itunes:episode>2</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#1 - Kenny’s Backstory</title>
        <itunes:title>#1 - Kenny’s Backstory</itunes:title>
        <link>https://Paramify.podbean.com/e/1-kenny-s-backstory/</link>
                    <comments>https://Paramify.podbean.com/e/1-kenny-s-backstory/#comments</comments>        <pubDate>Thu, 06 Jul 2023 09:54:38 -0600</pubDate>
        <guid isPermaLink="false">marketing68.podbean.com/d0c674ef-f0bf-314f-8da4-82c29f847a96</guid>
                                    <description><![CDATA[<p>Welcome to the genesis of The Paramify Podcast. Today, we uncover the beginning of Kenny's journey that culminated in the creation of Paramify.</p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Welcome to the genesis of The Paramify Podcast. Today, we uncover the beginning of Kenny's journey that culminated in the creation of Paramify.</p>
<p> </p>
<p>LEARN MORE about Paramify here: https://www.paramify.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6v2jym/hopefully_this_is_right_lolaps7g.mp3" length="32046402" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Welcome to the genesis of The Paramify Podcast. Today, we uncover the beginning of Kenny's journey that culminated in the creation of Paramify.
 
LEARN MORE about Paramify here: https://www.paramify.com/]]></itunes:summary>
        <itunes:author>marketing68</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1997</itunes:duration>
                <itunes:episode>1</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog16727912/YouTube_Cover_3__t6mtmg.png" />    </item>
</channel>
</rss>
