For Employers

NTT DATA, Europe & LATAM, Branch in USA, Inc.

Data Privacy & Compliance Engineer - OneTrust

Posted 5 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Data Privacy & Compliance Engineer will configure and manage OneTrust modules for data discovery, governance, and privacy automation. They will also define data policies, enforce controls across cloud platforms, and manage incident response and regulatory compliance workflows.

Location: LATAM

NTT DATA is a team of more than 190,000 diverse professionals, operating in more than 50 countries throughout the world. The sectors where we have activities include: telecommunications, finance, industry, utilities, energy, public administration and health.

Our mission? Offer technological solutions, business, strategy, development and maintenance of applications, while being a benchmark in consulting. All thanks to the collaboration between teams, the human quality of our people and the fact that we do not conform to what is established, we always seek innovation that brings us closer to the future.

Our essence has led us to the forefront of technology, breaking paradigms and providing solutions that truly respond to the needs of each client. Our talent has led us to be one of the top 6 technology companies in the world.

Because #Greattech, needs #GreatPeople, like you

NTT DATA is looking for high-achieving team players that are quickly adaptable to new challenges and entrepreneurial ventures. We are looking for a Data Privacy & Compliance Engineer (One Trust) to work remotely from USA with our global client. 

Responsibilities: 

OneTrust · Data Discovery & Data Governance (core) 

  • Discovery and scanning: configuration of connectors to structured and unstructured sources (relational databases, data lakes and object storage, cloud warehouses, SaaS applications, file repositories and collaboration tools), scan scope definition, scheduling and performance tuning. 
  • Classification: use and customisation of out of the box classifiers, creation of custom classification rules and regular expressions, sensitivity and regulatory category assignment, and tuning to reduce false positives. 
  • Retention and minimisation: retention schedules, defensible deletion workflows, management of redundant, obsolete and trivial data, and reduction of the sensitive data footprint. 

OneTrust · Data Use Governance & Control Enforcement 

  • Data policy engine: definition of data policies from regulatory intelligence or from internal standards, continuous evaluation of the estate against those policies, and management of violations such as expired retention, unencrypted sensitive data, open access or data stored out of place. 
  • Control push down: configuration of policy push down to cloud data platforms so that column masking and row filtering are enforced natively by the engine, with verification of where each control has actually been applied. 
  • Orchestrated remediation: automated remediation actions such as deletion, quarantine, archival, redaction and access restriction, and routing of the remaining actions to platform owners through ITSM workflows with tracking to closure. 
  • Boundary of responsibility: ability to specify the required control and evidence its application while the technical enforcement remains with the platform teams, avoiding duplication of ownership between the compliance layer and the data platform. 
  • Audit of control effectiveness: reconciliation of policy intent against the controls actually in place, use of platform audit logs as evidence, and reporting of residual exposure. 

OneTrust · Privacy Automation & Rights 

  • Records of processing (RoPA): design of the processing activity model, templates, ownership and periodic attestation cycles. 
  • Assessments: configuration and rollout of PIA, DPIA, TIA and transfer impact assessments, including questionnaire design, risk libraries, approval workflows and mitigation tracking. 
  • Data subject rights (DSAR): intake portals, identity verification, request routing, automated search and fulfilment against connected systems, redaction, and SLA tracking by jurisdiction. 
  • Incident and breach management: intake, assessment of notifiability by jurisdiction, task orchestration and generation of regulatory documentation. 
  • Consent and preferences: consent and cookie compliance configuration, preference centres, and propagation of consent and purpose of use to downstream systems. 

Nice-to-Have:

  • Control frameworks: implementation of control libraries and cross mapping across ISO 27001, ISO 27701, SOC 2, NIST CSF and applicable local regulations. 
  • Policy and evidence: policy lifecycle management, continuous evidence collection, control testing, findings, exceptions and remediation plans, and audit readiness packages. 
  • Third party risk: vendor onboarding, questionnaire configuration by domain, risk scoring, continuous monitoring and reassessment triggers. 
  • AI governance (desirable): AI system, model and dataset inventory, risk assessment against the NIST AI RMF and the EU AI Act, and generation of conformity documentation. 

Tools & Technologies:

  • Medallion architecture: clear understanding of bronze, silver and gold responsibilities, and where virtualization complements or replaces physical persistence at each stage. 
  • Gold layer construction: dimensional and star-schema modelling, conformed dimensions, slowly changing dimensions, aggregates and business-rule implementation for consumption-ready models. 
  • Data products: definition of data contracts, ownership, quality expectations, SLAs and versioning; documentation and lifecycle of published assets. 
  • Working knowledge of Data Mesh and Lakehouse principles and of data governance practices (lineage, cataloguing, stewardship). 

Education & Certifications:

  • OneTrust platform certifications at expert level in the relevant modules (Privacy Automation, Data Discovery, Third Party Risk, Tech Risk and Compliance). 
  • IAPP CIPP/E or CIPP/US, CIPM, or CIPT. 
  • Informatica Cloud Data Governance and Catalog, Professional Certification (ICP). 
  • ISO 27001 Lead Implementer or Lead Auditor. 

 

Required Equipment: This role requires the use of a personal laptop. Candidates must be comfortable with company security software and device management tools being installed on their laptop as part of the onboarding process and for the duration of the engagement.

About NTT DATA

NTT DATA is a Top 5 global IT services provider with more than 190,000 professionals across 50+ countries. We combine industry expertise with capabilities in consulting, technology, AI, cloud, applications, infrastructure, and connectivity to help organizations innovate, optimize, and transform. Through responsible innovation, we deliver meaningful business outcomes, accelerate client success, and create a positive impact on society.

Equal Opportunity Employer

NTT DATA is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT DATA is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.

 

Equal Opportunity Employer

NTT DATA is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT DATA is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.

 

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Full Stack Engineer

Freelance India, United States Software Development

Sales Engineer

Full Time United States $85000 - $140K per year Software Development

Staff Software Engineer, Security Plaftorm

Full Time Argentina, Brazil, Chile +6 more Software Development

Software Developer

Full Time United States Software Development

SENIOR POWER BI DEVELOPER-(REMOTE)

Full Time United States $120K - $150K per year Software Development

Staff Data Engineer- Ohio or EST Time Zone

Full Time United States Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 216,779+ Jobs in Software Development

Answer easy questions

Answer easy questions

216,779+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified