The Old Way Is Dead: A Security Team's Manifesto for GRC Engineering

The role of a modern security team has undergone a transformation. What was once a function focused solely on the technical aspects of network defense has evolved into a strategic business partner that directly influences business growth, innovation, and organizational resilience. Today's security team operates at the intersection of technology, business strategy, and risk management, working closely with engineering, legal, and business leaders. This shift is a direct response to a threat landscape where cybersecurity risks are no longer isolated technical problems but critical business risks with real financial and reputational consequences.

For a long time, security teams were often perceived as the "department of no" viewed as a barrier to agility and a blocker to new initiatives. This reactive posture, born from a focus on "firefighting" and a legacy of manual processes, led to security being an afterthought, added on at the end of a project. However, the mandate of a modern security team is to be a business enabler. Instead of simply mitigating risk, a security team helps the organization take informed, "smart risks" that enable growth whilst maintaining an acceptable level of security. By implementing a robust security framework, a modern security team enables the business to innovate and move with speed and confidence.

The traditional approach to GRC (Governance, Risk, and Compliance) often reinforces this perception of security as a bottleneck. It relies on a retrospective model, after a product is developed, it's subjected to a lengthy, manual, and often tedious security review. This "check-the-box" methodology is not only time-consuming but also provides a false sense of security. It creates friction, slows down the development lifecycle, and ultimately makes security a blocker instead of a partner. In a fast-paced environment like Kiwi.com, where we constantly iterate and deploy, this model simply doesn't work.

What is GRC Engineering?

This is where the concept of GRC Engineering comes in. It's more than just a buzzword, it's a fundamental shift in how we approach security and compliance. GRC Engineering is the practice of applying software engineering principles like automation, continuous integration/continuous delivery (CI/CD), and "as-code" methodologies to security governance, risk management, and compliance processes.

At its core, it's about embedding security and compliance directly into the engineering workflow. Instead of being an external audit or a final checkpoint, security becomes a part of the development lifecycle, from design to deployment.

From Manual Audits to Automated Guardrails

The key to GRC Engineering is automation. We're moving from a world of manual spreadsheets, pointless questionnaires, and quarterly audits to a world of real-time visibility, automated checks, and continuous compliance.

  • We define our security policies and compliance requirements not as static documents but as executable code. These policies are integrated directly into our CI/CD pipelines. This means that every code commit, every new deployment, and every change is automatically checked against our security and compliance baselines. If something is out of compliance, the build fails, alerting the team to the issue immediately.

  • Instead of relying on periodic, manual risk assessments, we can use automation to continuously monitor our environment. Tools can automatically scan for vulnerabilities, misconfigurations, and other risks, providing real-time data to our security teams. This allows us to move from a reactive "firefighting" model to a proactive, data-driven risk management approach.

  • GRC Engineering enables us to continuously monitor our compliance posture. We can use dashboards and reports to get a real-time view of our security health, ensuring that we are always compliant with regulatory requirements and internal policies.

Building a Culture of Shared Responsibility

At Kiwi.com, our success is built on a foundation of agility and innovation. We believe that security should enable that agility. GRC Engineering is a natural fit for our engineering culture because it aligns with our core principles of automation, collaboration, and continuous improvement.

We're shifting the mindset from a centralized security team being solely responsible for security to one where security is a shared responsibility. By providing developers with automated tools and real-time feedback, we're empowering them to own security from the very beginning. It's about giving them the guardrails they need to innovate safely and securely, without having to wait for a security team's approval.

Our path to success

Our journey to GRC Engineering is guided by a few key principles:

  1. Start with the engineers:
    We focus on creating security tools and processes that are easy for our developers to use and integrate into their existing workflows.
  2. Automate everything:
    If a security task can be automated, it should be. This frees up the security team to focus on higher-value activities like threat intelligence and strategic planning.
  3. Build a feedback loop:
    We provide continuous feedback to our teams, helping them to quickly identify and fix security issues before they make it to production.
  4. Embrace collaboration:
    Security is not an isolated function. We work closely with our engineering, legal, and business teams to ensure that our GRC Engineering program is aligned with the company's goals and values.

GRC Engineering is more than just a trend, it's the future of security in the tech industry. It's about moving from a reactive, manual, and inefficient model to a proactive, automated, and scalable one.