Data Privacy & Compliance Engineer - OneTrust

Posted 5 Hours Ago
Be an Early Applicant
11 Locations
Remote
Entry level
Big Data • Cloud • Information Technology • Analytics • Consulting
The Role
Configure and administer OneTrust for data discovery, classification, governance, retention, policy enforcement, privacy automation, assessments, DSARs, consent, and breach management. Build remediation workflows, audit control effectiveness, and support compliance frameworks, third-party risk, and AI governance. Apply data architecture and governance practices including medallion architecture, dimensional modeling, data products, Data Mesh, Lakehouse, lineage, cataloging, and stewardship. Expert OneTrust and industry certifications are listed.
Summary Generated by Built In

Location: LATAM

NTT DATA is a team of more than 190,000 diverse professionals, operating in more than 50 countries throughout the world. The sectors where we have activities include: telecommunications, finance, industry, utilities, energy, public administration and health.

Our mission? Offer technological solutions, business, strategy, development and maintenance of applications, while being a benchmark in consulting. All thanks to the collaboration between teams, the human quality of our people and the fact that we do not conform to what is established, we always seek innovation that brings us closer to the future.

Our essence has led us to the forefront of technology, breaking paradigms and providing solutions that truly respond to the needs of each client. Our talent has led us to be one of the top 6 technology companies in the world.

Because #Greattech, needs #GreatPeople, like you

NTT DATA is looking for high-achieving team players that are quickly adaptable to new challenges and entrepreneurial ventures. We are looking for a Data Privacy & Compliance Engineer (One Trust) to work remotely from USA with our global client. 

Responsibilities: 

OneTrust · Data Discovery & Data Governance (core) 

  • Discovery and scanning: configuration of connectors to structured and unstructured sources (relational databases, data lakes and object storage, cloud warehouses, SaaS applications, file repositories and collaboration tools), scan scope definition, scheduling and performance tuning. 
  • Classification: use and customisation of out of the box classifiers, creation of custom classification rules and regular expressions, sensitivity and regulatory category assignment, and tuning to reduce false positives. 
  • Retention and minimisation: retention schedules, defensible deletion workflows, management of redundant, obsolete and trivial data, and reduction of the sensitive data footprint. 

OneTrust · Data Use Governance & Control Enforcement 

  • Data policy engine: definition of data policies from regulatory intelligence or from internal standards, continuous evaluation of the estate against those policies, and management of violations such as expired retention, unencrypted sensitive data, open access or data stored out of place. 
  • Control push down: configuration of policy push down to cloud data platforms so that column masking and row filtering are enforced natively by the engine, with verification of where each control has actually been applied. 
  • Orchestrated remediation: automated remediation actions such as deletion, quarantine, archival, redaction and access restriction, and routing of the remaining actions to platform owners through ITSM workflows with tracking to closure. 
  • Boundary of responsibility: ability to specify the required control and evidence its application while the technical enforcement remains with the platform teams, avoiding duplication of ownership between the compliance layer and the data platform. 
  • Audit of control effectiveness: reconciliation of policy intent against the controls actually in place, use of platform audit logs as evidence, and reporting of residual exposure. 

OneTrust · Privacy Automation & Rights 

  • Records of processing (RoPA): design of the processing activity model, templates, ownership and periodic attestation cycles. 
  • Assessments: configuration and rollout of PIA, DPIA, TIA and transfer impact assessments, including questionnaire design, risk libraries, approval workflows and mitigation tracking. 
  • Data subject rights (DSAR): intake portals, identity verification, request routing, automated search and fulfilment against connected systems, redaction, and SLA tracking by jurisdiction. 
  • Incident and breach management: intake, assessment of notifiability by jurisdiction, task orchestration and generation of regulatory documentation. 
  • Consent and preferences: consent and cookie compliance configuration, preference centres, and propagation of consent and purpose of use to downstream systems. 

Nice-to-Have:

  • Control frameworks: implementation of control libraries and cross mapping across ISO 27001, ISO 27701, SOC 2, NIST CSF and applicable local regulations. 
  • Policy and evidence: policy lifecycle management, continuous evidence collection, control testing, findings, exceptions and remediation plans, and audit readiness packages. 
  • Third party risk: vendor onboarding, questionnaire configuration by domain, risk scoring, continuous monitoring and reassessment triggers. 
  • AI governance (desirable): AI system, model and dataset inventory, risk assessment against the NIST AI RMF and the EU AI Act, and generation of conformity documentation. 

Tools & Technologies:

  • Medallion architecture: clear understanding of bronze, silver and gold responsibilities, and where virtualization complements or replaces physical persistence at each stage. 
  • Gold layer construction: dimensional and star-schema modelling, conformed dimensions, slowly changing dimensions, aggregates and business-rule implementation for consumption-ready models. 
  • Data products: definition of data contracts, ownership, quality expectations, SLAs and versioning; documentation and lifecycle of published assets. 
  • Working knowledge of Data Mesh and Lakehouse principles and of data governance practices (lineage, cataloguing, stewardship). 

Education & Certifications:

  • OneTrust platform certifications at expert level in the relevant modules (Privacy Automation, Data Discovery, Third Party Risk, Tech Risk and Compliance). 
  • IAPP CIPP/E or CIPP/US, CIPM, or CIPT. 
  • Informatica Cloud Data Governance and Catalog, Professional Certification (ICP). 
  • ISO 27001 Lead Implementer or Lead Auditor. 

Required Equipment: This role requires the use of a personal laptop. Candidates must be comfortable with company security software and device management tools being installed on their laptop as part of the onboarding process and for the duration of the engagement.

About NTT DATA

NTT DATA is a Top 5 global IT services provider with more than 190,000 professionals across 50+ countries. We combine industry expertise with capabilities in consulting, technology, AI, cloud, applications, infrastructure, and connectivity to help organizations innovate, optimize, and transform. Through responsible innovation, we deliver meaningful business outcomes, accelerate client success, and create a positive impact on society.

Equal Opportunity Employer

NTT DATA is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT DATA is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.


Equal Opportunity Employer

NTT DATA is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT DATA is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.


Skills Required

  • Expert-level OneTrust platform certifications in relevant modules, including Privacy Automation, Data Discovery, Third Party Risk, and Tech Risk and Compliance
  • One of the following IAPP certifications: CIPP/E, CIPP/US, CIPM, or CIPT
  • Informatica Cloud Data Governance and Catalog Professional Certification
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • Personal laptop and comfort with company security software and device management tools installed for the engagement
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Tokyo
24,200 Employees

What We Do

NTT DATA Services is a recognized leader in IT and business services including cloud, data and applications. A division of NTT DATA headquartered in Texas, the company leverages consulting and deep industry expertise to help clients accelerate and sustain value throughout their digital journeys. NTT DATA – a part of NTT Group – is a trusted global innovator of IT and business services headquartered in Tokyo. We help clients transform through consulting, industry solutions, business process services, digital & IT modernization and managed services in over 50 countries.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Support Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly
Remote or Hybrid
2 Locations
289097 Employees

Engine Logo Engine

Salesforce Administrator

Consumer Web • Software • Travel
Easy Apply
Remote
10 Locations
1000 Employees

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account