Compliance & Information Security Leader

Samer Elsaady

Senior Manager, Compliance & Information Security at Conga

Two decades of building and scaling governance, risk, and compliance programs, turning complex regulatory frameworks into audit-ready, business-aligned operations.

๐Ÿ“ United States ๐Ÿ›ก๏ธ GRC & IT Audit ๐ŸŒ EN ยท AR ยท IT
Portrait of Samer Elsaady
20+
Years in audit & compliance
Zero
Critical findings across exams
60%
Audit cycle time reduced
10+
Compliance frameworks led

About

Governance that moves the business forward

I'm a compliance and information security leader with deep experience across internal audit, IT audit, enterprise risk management (ERM), and corporate governance. I'm known for identifying cost-reduction opportunities by surfacing process inefficiencies while keeping business and IT strategy aligned.

My work spans organizational restructuring, process re-engineering, gap analysis, benchmarking, and digital transformation, developing and implementing governance and risk-management best practices that scale.

  • โœ“ Cross-framework control mapping & unified compliance programs
  • โœ“ External audit liaison: SOC 1/2, HITRUST, HIPAA, ISO 27001/27701, PCI DSS
  • โœ“ GRC platform design, automated evidence collection & continuous monitoring
  • โœ“ Third-party risk, privacy operations (DPIA, RoPA, retention & deletion)

Expertise

Core competencies

๐Ÿ“‹ Compliance Frameworks

SOC 1/2SOXISO 27001 ISO 27701HITRUSTHIPAA PCI DSSGDPRCCPA NIST 800COSOCOBIT

๐Ÿ›ก๏ธ Risk & Governance

ISMSEnterprise Risk (ERM)IT Audit Internal ControlsICFRThird-Party Risk Privacy OpsDPIA / RoPAForensic Audit

๐Ÿ“Š GRC & Analytics Tools

Power BITableauACL Analytics IDEACAATsJira ConfluenceSlackPENTANA Vision

Experience

Career history

Jan 2021 to Present

Senior Manager, Compliance & Information Security

Conga ยท United States
  • Standardized cross-framework control mapping and awareness training, embedding compliance across Product, Engineering, IT, Cloud Ops, HR, and Legal.
  • Primary liaison for SOC 1/2, HITRUST, HIPAA, ISO 27001-2022, 27701-2019, and PCI DSS audits; achieved zero critical findings and cut audit cycle time by 60%.
  • Led GRC platform rollout with automated evidence collection and continuous monitoring, sharply reducing manual effort and raising audit readiness.
  • SME for privacy operations (retention, deletion, DPIA, RoPA) and third-party risk reviews; strengthened client trust through sales-driven security inquiries.
Dec 2018 to Nov 2020

Experienced Manager, Technology Audit

Grant Thornton LLP
  • Led IT audit and ITGC engagements: SOX compliance/readiness, ICFR, systems assurance (SAP, Oracle, NetSuite, Workday), network & database security, IAM, data privacy, and SDLC.
  • Helped clients anticipate emerging risks and leverage technology to resolve business challenges as a trusted advisor.
Sep 2017 to Oct 2018

Manager, Risk Advisory, Financial Services Office

EY (Ernst & Young)
  • Led IT and integrated audits for Fortune 500 financial services clients across the South West region.
  • Directed engagements spanning SDLC, application controls, cybersecurity, third-party risk, change management, data encryption, SOX, DB security, and IAM.
  • Applied CAAT tools to enhance GRC and escalated emerging risks to executive stakeholders.
2008 to 2017 ยท Doha, Qatar

Audit & Risk Manager โ†’ IT Audit Specialist

Qatar Financial Centre (QFC) Authority ยท 9 yrs 8 mos
  • Built and delivered the annual audit plan approved by the Audit & Risk Committee, preparing committee papers and managing the enterprise risk register.
  • Led control self-assessments, process re-engineering within ERP, and special forensic investigations for senior management.
  • Administered PENTANA Vision GRC software; applied ISO 27001 to the Oracle R12 ERP implementation and secured certification.
2002 to 2008

Senior Oracle / ERP Consultant

GIZA Systems ยท Computer & Systems Engineering Co.
  • Delivered full-cycle Oracle ERP implementations (R11i/R12) covering GL, AP, AR, FA, and Cash Management for telecom, energy, and government clients across the Middle East.
  • First to apply CMMI to an ERP implementation in the region; led gap analysis, build, testing, migration, and rollout.

Credentials

Certifications, languages & education

Certifications

  • โ˜… COBIT 5 Implementation
  • โ˜… COBIT 5 Foundation
  • โ˜… The Role of Data in AI Auditing
  • โ˜… ISO 27001 / ISO 27701 (ISMS & Privacy frameworks)
  • โ˜… Excel: PivotTables in Depth ยท Grammar Foundations

Languages

EnglishNative / Bilingual
ArabicNative / Bilingual
ItalianProfessional

Education

Helwan University, Cairo

B.A.Sc., Accounting & Business / Management

Get in touch

Let's talk compliance, risk & security

Open to leadership conversations in GRC, information security, and IT audit. The fastest way to reach me is email or LinkedIn.