About Laidon
Laidon, a Certified SAP Partner, operates globally with offices in the US, Japan, and Vietnam, and sales presence in Australia, Germany, England, and Singapore.
Laidon developed SimpleMDG (simplemdg.com), a powerful master data governance solution on SAP BTP that fortifies master data foundations, enhances operational excellence, ensures compliance, and drives innovation at scale.
With over 100 out-of-the-box S/4HANA data objects and workflows, SimpleMDG supports powerful governance while eliminating the need for slow, complex, and expensive customizations. SimpleMDG is the master data governance and management platform for enterprises running SAP.
Role Summary
We are seeking a Compliance Specialist to lead and operationalize our governance, risk, and compliance programs across ISO 27001, FedRAMP, GDPR, SOC 2, and related frameworks. This role owns end-to-end compliance execution, audit readiness, control effectiveness, and cross-functional remediation to ensure we meet regulatory and customer requirements.
Key Responsibilities
1. Compliance & Risk Management
- Lead the company's compliance and governance programs, with end-to-end accountability for execution, readiness, and outcomes.
- Develop and execute compliance roadmaps, annual plans, and control maturity initiatives.
- Coordinate internal stakeholders, auditors, consultants, assessors, and customers throughout audit and certification cycles.
- Maintain policies, procedures, standards, records, and governance documentation.
- Ensure all compliance evidence and documentation are accurate, current, and audit-ready.
- Monitor adherence to regulatory obligations, contractual commitments, and internal controls.
- Identify operational/control gaps and risks, then drive remediation to closure with accountable owners and deadlines.
- Manage program timelines, dependencies, deliverables, and risk escalations.
- Support customer security/compliance due diligence, questionnaires, and audit-readiness discussions.
- Prepare executive-level compliance reporting, status updates, and risk summaries.
- Maintain organization-wide audit readiness and coordinate pre-audit/internal readiness reviews.
2. Framework Implementation & Audit Readiness
- Implement and maintain controls for ISO 27001, SOC 2, GDPR, and FedRAMP-aligned requirements.
- Perform control mapping across multiple frameworks to reduce duplication and improve operational efficiency.
- Partner with Security, Engineering, DevOps, Legal, and HR to operationalize controls in day-to-day workflows.
- Manage external audits and assessments from planning through closure of findings.
- Define and track compliance KPIs/KRIs and continuously improve control effectiveness.
3. Governance & Continuous Improvement
- Establish compliance governance cadence (working groups, steering updates, leadership reporting).
- Maintain risk register, exceptions process, and policy lifecycle management.
- Drive security awareness and compliance training initiatives relevant to regulatory obligations.
- Build repeatable compliance processes that scale with company growth and customer expectations.
Your Skills and Experience
Required Qualifications
- 5+ years of experience in Compliance, GRC, Risk Management, or Information Security compliance roles.
- Hands-on experience implementing and maintaining at least two of the following: ISO 27001, SOC 2, GDPR, FedRAMP.
- Strong knowledge of control frameworks, audit lifecycle, evidence collection, and remediation management.
- Experience working cross-functionally with technical and non-technical teams.
- Strong project/program management skills with proven ability to manage multiple audits and deadlines.
- Excellent written and verbal communication, including executive reporting and customer-facing responses.
Preferred Qualifications
- Experience in cloud/SaaS environments (AWS/Azure/GCP).
- Familiarity with NIST 800-53, NIST CSF, CIS Controls, and privacy-by-design principles.
- Experience with compliance tooling (e.g., Drata, Vanta, Secureframe, Jira, Confluence, GRC platforms).
- Professional certifications such as CISA, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor, CISSP, or equivalent.