The Paramify Podcast

Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity

55 min · 2 de mar de 2026
portada del episodio Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity

Descripción

In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption. Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down. They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper. Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai. Links: Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoff Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott DTEX.ai: https://www.dtex.ai/ Paramify: https://www.paramify.com/ In this episode, you’ll hear: - Why usable security is better security - How secure AI can help small teams move faster - Why trust centers are becoming more important - How accessibility gaps can create real security risk - Why servant leadership matters in cybersecurity - Why FedRAMP 20x is shifting the focus back to risk Chapters: 0:00 Secure AI, lean teams, and why the right tools matter 1:12 Intro to Justin Merhoff 2:08 How Justin got started in cybersecurity 8:31 Army stories, leadership, and early security lessons 16:06 Moving from the military into corporate security 19:17 Why security should enable the business 20:45 The future of trust centers 25:20 Secure AI, small teams, and reducing compliance burnout 29:32 Why FedRAMP 20x is a needed change 36:31 Cyber leadership, adaptability, and how people break into security 44:13 Why accessibility is a cybersecurity issue 51:18 What Justin was doing at the time and how Rhymetec helps clients 54:35 Outro This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y forma parte de la comunidad de The Paramify Podcast!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

58 episodios

episode FedRAMP 20x, CMMC, and the Future of GRC with Matt Bruggeman artwork

FedRAMP 20x, CMMC, and the Future of GRC with Matt Bruggeman

"For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂  In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC. Chapters: 00:00 The State of CMMC in 2026 01:00 Intro and Meet Matt Bruggeman 02:52 Matt's Unconventional Path to GRC 06:11 About A-LIGN and the Ascend Platform 08:14 CMMC Today: What's Working and What Needs to Change 09:19 Phase 1 vs Phase 2 and the November 10th Deadline 11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan? 15:46 FedRAMP 20X: Hype vs Reality 19:01 Why FedRAMP Was Broken from the Start 23:28 How to Think About Rev 5 vs 20X for Your Business 27:52 FedRAMP Equivalency Explained 31:36 The Technical Reality of a CMMC Assessment 35:27 Compliance Doesn't Have to Be Boring 37:30 How to Get Into the GRC Space 40:19 Where to Find Matt and A-LIGN Connect with our guest: Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/ A-LIGN: https://www.a-lign.com A-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/ Paramify: Website: https://www.paramify.com LinkedIn: https://www.linkedin.com/company/80788473/ Hosts: Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/ Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/

Ayer42 min
episode AI, FedRAMP and the "Dark Matter" of Data with Bhanu Jagasia and Vincent Tham artwork

AI, FedRAMP and the "Dark Matter" of Data with Bhanu Jagasia and Vincent Tham

Is legacy compliance actually dead?  In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence. We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation? Connect with BladeStack: LinkedIn: bladestack.io Bhanu Jagasia: linkedin.com/in/bhanujagasia Vincent Tham: linkedin.com/in/vincenttham Website: bladestack.io Connect with Paramify: LinkedIn: linkedin.com/company/paramify Kenny Scott: linkedin.com/in/kenny-g-scott Mike Schreiner: linkedin.com/in/mikecschreiner Website: paramify.com 0:00 Intro & Evidence Automation 1:27 Welcome to the Paramify Podcast 3:00 How Bladestack Got Started 6:29 Evidence Automation & the "Dark Matter" of Data 12:31 Why Expertise Still Matters in FedRAMP 14:37 Bladestack's Tech-First Approach to Compliance 18:40 AI Hype vs Reality in FedRAMP 22:52 Understanding What LLMs Actually Are 26:34 The Problem with Legacy SSPs 28:06 Why FedRAMP 20X Changes Everything 36:40 The Legacy FedRAMP Process Was Broken 40:32 How Bladestack Leverages AI Internally 43:19 Branding in an AI-Commoditized World 46:31 AI's Impact on the Threat Landscape 49:53 The Future of Compliance 54:00 Where to Find Bladestack

18 de may de 202655 min
episode GRC Engineering, FedRAMP 20x, and AI with Ethan Troy artwork

GRC Engineering, FedRAMP 20x, and AI with Ethan Troy

"Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop. He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was. His job interview at TRM Labs? They made him build an AI agent. And yes, this is the first Paramify Podcast Isaac is on. We got into: → Why now is the best time to learn something new  → Why 85% of a good GRC agent is deterministic code, not AI  → How to actually build agents (dog food your own stuff, stop one-shotting)  → Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x  → Why domain expertise is what separates good AI output from great AI output FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf Learn more about Ethan Troy: https://www.linkedin.com/in/ethantroy/?skipRedirect=true Learn more about TRM Labs:  https://www.trmlabs.com/ Learn more about Kenny Scott:  https://www.linkedin.com/in/kenny-g-scott/ Learn more about Isaac Teuscher:  https://www.linkedin.com/in/isaacteuscher/ Learn more about Paramify: https://www.paramify.com/ Chapters: 00:58 - Introductions & GRC Engineering 02:12 - From Nursing to Cybersecurity 05:18 - The Problem with Legacy GRC Tools 12:13 - FedRAMP 2.0: The End of SSPs? 16:48 - The FedRAMP Marketplace Metaphor 24:38 - Outcome-Based vs. Hourly Consulting 31:51 - Automating Evidence Collection 37:16 - AI & Real-Time Incident Response 45:10 - Secure Configuration Guides 52:43 - Building an AI-First Culture 58:51 - Principles for AI Agents in GRC 01:05:03 - The 85/15 Rule for AI Logic

12 de may de 20261 h 6 min
episode Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity artwork

Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity

In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption. Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down. They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper. Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai. Links: Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoff Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott DTEX.ai: https://www.dtex.ai/ Paramify: https://www.paramify.com/ In this episode, you’ll hear: - Why usable security is better security - How secure AI can help small teams move faster - Why trust centers are becoming more important - How accessibility gaps can create real security risk - Why servant leadership matters in cybersecurity - Why FedRAMP 20x is shifting the focus back to risk Chapters: 0:00 Secure AI, lean teams, and why the right tools matter 1:12 Intro to Justin Merhoff 2:08 How Justin got started in cybersecurity 8:31 Army stories, leadership, and early security lessons 16:06 Moving from the military into corporate security 19:17 Why security should enable the business 20:45 The future of trust centers 25:20 Secure AI, small teams, and reducing compliance burnout 29:32 Why FedRAMP 20x is a needed change 36:31 Cyber leadership, adaptability, and how people break into security 44:13 Why accessibility is a cybersecurity issue 51:18 What Justin was doing at the time and how Rhymetec helps clients 54:35 Outro This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.

2 de mar de 202655 min