Compliance & Information Security Leader
Samer Elsaady
Senior Manager, Compliance & Information Security at Conga
Two decades of building and scaling governance, risk, and compliance programs, turning complex regulatory frameworks into audit-ready, business-aligned operations.
About
Governance that moves the business forward
I'm a compliance and information security leader with deep experience across internal audit, IT audit, enterprise risk management (ERM), and corporate governance. I'm known for identifying cost-reduction opportunities by surfacing process inefficiencies while keeping business and IT strategy aligned.
My work spans organizational restructuring, process re-engineering, gap analysis, benchmarking, and digital transformation, developing and implementing governance and risk-management best practices that scale.
- โ Cross-framework control mapping & unified compliance programs
- โ External audit liaison: SOC 1/2, HITRUST, HIPAA, ISO 27001/27701, PCI DSS
- โ GRC platform design, automated evidence collection & continuous monitoring
- โ Third-party risk, privacy operations (DPIA, RoPA, retention & deletion)
Expertise
Core competencies
๐ Compliance Frameworks
๐ก๏ธ Risk & Governance
๐ GRC & Analytics Tools
Experience
Career history
Senior Manager, Compliance & Information Security
- Standardized cross-framework control mapping and awareness training, embedding compliance across Product, Engineering, IT, Cloud Ops, HR, and Legal.
- Primary liaison for SOC 1/2, HITRUST, HIPAA, ISO 27001-2022, 27701-2019, and PCI DSS audits; achieved zero critical findings and cut audit cycle time by 60%.
- Led GRC platform rollout with automated evidence collection and continuous monitoring, sharply reducing manual effort and raising audit readiness.
- SME for privacy operations (retention, deletion, DPIA, RoPA) and third-party risk reviews; strengthened client trust through sales-driven security inquiries.
Experienced Manager, Technology Audit
- Led IT audit and ITGC engagements: SOX compliance/readiness, ICFR, systems assurance (SAP, Oracle, NetSuite, Workday), network & database security, IAM, data privacy, and SDLC.
- Helped clients anticipate emerging risks and leverage technology to resolve business challenges as a trusted advisor.
Manager, Risk Advisory, Financial Services Office
- Led IT and integrated audits for Fortune 500 financial services clients across the South West region.
- Directed engagements spanning SDLC, application controls, cybersecurity, third-party risk, change management, data encryption, SOX, DB security, and IAM.
- Applied CAAT tools to enhance GRC and escalated emerging risks to executive stakeholders.
Audit & Risk Manager โ IT Audit Specialist
- Built and delivered the annual audit plan approved by the Audit & Risk Committee, preparing committee papers and managing the enterprise risk register.
- Led control self-assessments, process re-engineering within ERP, and special forensic investigations for senior management.
- Administered PENTANA Vision GRC software; applied ISO 27001 to the Oracle R12 ERP implementation and secured certification.
Senior Oracle / ERP Consultant
- Delivered full-cycle Oracle ERP implementations (R11i/R12) covering GL, AP, AR, FA, and Cash Management for telecom, energy, and government clients across the Middle East.
- First to apply CMMI to an ERP implementation in the region; led gap analysis, build, testing, migration, and rollout.
Credentials
Certifications, languages & education
Certifications
- โ COBIT 5 Implementation
- โ COBIT 5 Foundation
- โ The Role of Data in AI Auditing
- โ ISO 27001 / ISO 27701 (ISMS & Privacy frameworks)
- โ Excel: PivotTables in Depth ยท Grammar Foundations
Languages
Education
B.A.Sc., Accounting & Business / Management
Get in touch
Let's talk compliance, risk & security
Open to leadership conversations in GRC, information security, and IT audit. The fastest way to reach me is email or LinkedIn.