Job Description
Role Title: OneTrust Third-Party Risk Management (TPRM) Implementation Specialist
Department / Seat Name: TAC
Reports To (LMA): TBD
Type: Contractor/1099
Pay Range: $100-$125/hr
—
Role Summary
The OneTrust Third-Party Risk Management (TPRM) Implementation Specialist is responsible for leading the implementation, configuration, customization, and integration of OneTrust's Third-Party Risk Management (TPRM) and Vendor Risk Management (VRM) solutions for enterprise clients.
This role serves as the technical implementation lead throughout the project lifecycle, partnering with client stakeholders, project managers, security consultants, procurement teams, privacy teams, and IT organizations to deliver scalable vendor risk management programs aligned with business objectives and regulatory requirements.
The ideal candidate combines deep OneTrust platform expertise with strong technical integration experience, governance and risk knowledge, and exceptional client-facing consulting skills.
Core Responsibilities
● Lead end-to-end implementation of OneTrust Third-Party Risk Management (TPRM) and Vendor Risk Management (VRM) solutions from project kickoff through production deployment.
● Design, configure, and optimize OneTrust workflows, including vendor onboarding, risk assessments, approval processes, automation, dashboards, and reporting. ● Develop and maintain integrations between OneTrust and enterprise applications using APIs, OAuth, webhooks, and integration tools (e.g., ServiceNow, SAP Ariba, Coupa, ERP, and GRC platforms).
● Partner with clients to gather requirements, conduct solution design workshops, recommend best practices, and translate business needs into scalable technical solutions.
● Manage implementation quality by leading solution testing, user acceptance testing (UAT), production deployments, issue resolution, and post-go-live support. ● Create and maintain implementation documentation, including solution designs, configuration guides, integration documentation, test plans, and administrator training materials.
● Ensure implemented solutions align with governance, risk, privacy, and compliance requirements, including third-party risk management, GDPR, CCPA, ISO 27001, SOC 2, NIST, PCI DSS, and other applicable frameworks.
Measurables
These are tracked weekly or monthly via the Scorecard
Required Qualifications
● Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Information Security, Engineering, Business, or equivalent professional experience. ● 3+ years of enterprise software implementation, consulting, or solution delivery experience.
● 2+ years of hands-on OneTrust implementation experience.
● Experience implementing OneTrust Third-Party Risk Management (TPRM) and/or Vendor Risk Management (VRM).
● Experience leading client-facing implementation projects from discovery through production deployment.
● Strong understanding of Governance, Risk, and Compliance (GRC) principles. ● Excellent communication, presentation, and documentation skills.
● Ability to manage multiple client engagements simultaneously.
Preferred Qualifications
● OneTrust Professional Certification.
● OneTrust Third-Party Management Certification.
● OneTrust Vendor Risk Management certification or equivalent implementation credentials.
● CISA, CRISC, CISSP, CIPP/US, CIPP/E, CIPM, or similar industry certifications. ● Experience working for a consulting firm, systems integrator, or OneTrust Professional Services organization.
Technical Skills
Experience with:
● OneTrust Third-Party Risk Management (TPRM)
● Vendor Risk Management (VRM)
● OneTrust Integration Manager
● REST APIs
● OAuth 2.0
● JSON
● Webhooks
● SAML / SSO
● Azure AD / Entra ID
● Okta
Integration experience with one or more of the following:
● ServiceNow
● SAP Ariba
● Coupa
● ERP platforms
● SecurityScorecard
● BitSight
● Procurement systems
● Identity providers
● GRC platforms
Success Measures
Success in this role will be measured by:
● Successful implementation of OneTrust projects on time and within scope. ● High customer satisfaction throughout implementation engagements. ● Successful integrations with client enterprise systems.
● Increased automation of vendor risk management processes.
● Quality implementation documentation and knowledge transfer.
● Strong client adoption of implemented workflows.
● Minimal post-production support issues.
Non-Negotiables
● Hands-on experience implementing OneTrust Third-Party Risk Management (TPRM) or Vendor Risk Management (VRM) solutions.
● Demonstrated experience integrating OneTrust with enterprise applications using APIs, OAuth, webhooks, or similar technologies.
● Experience leading client-facing implementation or consulting projects. ● Strong understanding of third-party risk management and governance principles. ● Excellent written and verbal communication skills.
● Ability to independently troubleshoot complex implementation and integration issues. ● Authorization to work in the United States (if applicable).
Ideal Candidate
The successful candidate is an experienced implementation consultant who understands both the technical capabilities of the OneTrust platform and the business processes behind vendor risk management. They are comfortable leading client workshops, designing scalable solutions, integrating enterprise applications, and delivering successful implementations from discovery through production deployment.
They possess a consultative mindset, communicate effectively with both business and technical stakeholders, and are passionate about helping organizations strengthen their governance, risk, compliance, and third-party risk management programs.
Preferred Candidate Background
Candidates from the following types of organizations are strongly preferred:
● OneTrust Professional Services
● Deloitte
● EY
● KPMG
● PwC
● Accenture
● Protiviti
● Optiv
● GuidePoint Security
● Other Governance, Risk, Compliance (GRC), Privacy, or Cybersecurity consulting organizations
Candidates should demonstrate enterprise implementation experience rather than simply administering or using the OneTrust platform.
Skills Required
- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Information Security, Engineering, Business, or equivalent experience.
- 3+ years enterprise software implementation, consulting, or solution delivery experience.
- 2+ years hands-on OneTrust implementation experience.
- Experience implementing OneTrust Third-Party Risk Management (TPRM) or Vendor Risk Management (VRM).
- Hands-on experience integrating OneTrust with enterprise applications using REST APIs, OAuth, webhooks, or similar technologies.
- Experience with SAML/SSO and identity providers (Azure AD/Entra ID, Okta).
- Experience integrating with enterprise systems such as ServiceNow, SAP Ariba, Coupa, ERP platforms, or GRC platforms.
- Strong understanding of Governance, Risk, and Compliance (GRC) principles and relevant frameworks (GDPR, CCPA, ISO 27001, SOC 2, NIST, PCI DSS).
- Proven experience leading client-facing implementation projects from discovery through production deployment.
- Excellent communication, presentation, documentation, and training skills.
- Ability to manage multiple client engagements simultaneously and troubleshoot complex implementation issues independently.
- Authorization to work in the United States (if applicable).
- OneTrust Professional, Third-Party Management, or Vendor Risk Management certification.
- Industry certifications such as CISA, CRISC, CISSP, CIPP/US, CIPP/E, or CIPM.
- Experience working at consulting firms, systems integrators, or OneTrust Professional Services.
What We Do
RSI Security is a cybersecurity-focused technology company that helps private and public sector organizations in highly regulated industries effectively manage risk. RSI Security provides cyber engineering, assessment, advisory services, and technical testing to amp up clients' security posture while mitigating business risk. We have experts for every cybersecurity and compliance need– PCIDSS, CMMC and NIST, MSSP, IT Security, HITRUST, HIPAA / HITECH, CCPA, GDPR, threat detection, security awareness training, and much more. Our team members come from diverse backgrounds and specialties. Our team members include published authors, open-source developers, industry researchers, and conference presenters. For more information, visit rsisecurity.com









