OneTrust Subject Matter Expert (SME)
Job Summary
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long term project. Here are a few details.
Participate in client requirements discovery fit-gap and solution design workshops for OneTrust implementations or enhancements.
Provide functional and industry guidance across applicable OneTrust modules including TPRM Privacy TRC vendor assessments control and compliance management risk workflows evidence collection remediation and reporting.
Translate business risk regulatory security privacy and compliance requirements into clear OneTrust design recommendations process flows questionnaire structures control mappings data requirements and reporting needs.
Advise configuration and implementation teams during configuration sessions review proposed designs and validate that the solution supports the intended operating model and risk outcomes.
Serve as a trusted SME to client stakeholders across Technology Risk Information Security Privacy Procurement Legal Compliance business functions and third-party management.
Bring practical industry perspective on TPRM security assessments privacy and data protection processes regulatory expectations control validation issue management and audit-ready documentation.
Support prioritization of requirements design decisions open issues dependencies assumptions and risks; escalate material concerns through the appropriate governance channels.
Prepare or contribute to status reporting steering committee materials action logs decision logs RAID items and executive-level communications.
Identify enhancement opportunities across workflows questionnaires risk scoring assessment processes evidence management remediation tracking dashboards and operating procedures.
Review project deliverables for quality consistency traceability and alignment with approved requirements and design principles.
Support knowledge transfer user adoption process documentation training materials and transition to business-as-usual operations.
Proven project experience developing designing implementing or enhancing OneTrust-based solutions in at least one relevant module such as TPRM Privacy TRC or related GRC capabilities.
Demonstrated ability to work in an advisory capacity with clients and delivery teams rather than serving solely as a system configurator or administrator.
Experience participating in requirements gathering process mapping fit-gap analysis solution design configuration review testing support deployment readiness or post-implementation enhancement activities.
Strong understanding of GRC technology and the relationship between business processes risk frameworks controls assessments evidence issues remediation and reporting.
Experience supporting TPRM or related risk processes including third-party onboarding inherent risk assessment due diligence security and privacy questionnaires evidence review ongoing monitoring issue tracking and remediation closure.
Ability to lead or actively contribute to configuration and design sessions ask structured discovery questions challenge requirements constructively and articulate design trade-offs.
Ability to provide concise accurate status reporting and communicate decisions risks dependencies and recommendations to both technical and executive audiences.
Strong analytical documentation stakeholder management facilitation and problem-solving skills.
Ability to manage multiple workstreams deadlines client stakeholders and competing priorities in a consulting or project delivery environment.
Bachelors degree in computer science Information Technology Cybersecurity Information Systems Business or a related discipline; equivalent relevant experience may be considered.
Minimum of 5 years of experience in GRC technology Technology Risk Information Security Privacy Compliance TPRM or a closely related field.
Demonstrated OneTrust experience supporting client or enterprise projects with depth in at least one of TPRM Privacy TRC or a related OneTrust capability.
Experience working with cross-functional stakeholders including risk compliance information security privacy procurement technology business teams and external vendors.
Strong written and verbal communication skills including experience producing project updates requirements documentation design decisions risk summaries and executive-ready materials.
Ability to work independently operate in ambiguous environments and provide structured recommendations grounded in business and risk objectives.
OneTrust certification or formal OneTrust training particularly in Vendor Risk Management Privacy TRC or related modules.
Experience with multiple OneTrust modules or integrated GRC platforms such as ServiceNow GRC RSA Archer etc.
Experience with industry frameworks and standards such as ISO 27001 SOC 1/SOC 2 PCI DSS NIST data privacy requirements third-party risk regulations or financial services risk requirements.
Experience advising on risk scoring models control libraries assessment questionnaires workflow design exception management evidence collection audit trails dashboards and management reporting.
Experience supporting global or geographically distributed stakeholders and projects across multiple regulatory environments.
Experience in process improvement workflow automation operating model design or identifying opportunities to improve efficiency SLA performance auditability and user experience.
ISO 27001 Lead Auditor CISA CRISC CISSP CIPM or other relevant professional certification.
Consulting experience involving workshop facilitation executive communication quality reviews and delivery governance.
Required Skills:
Functional or Functional experience in HCM Cloud Payroll for US. Experience in US payroll will be added advantage Experience in Payroll processing and Fast Formulas Ability to troubleshoot the issues raised by client Ability to decode the functional design to resolve the issue Ability to work on enhancements by gathering requirements from the client Ability to create or update functional design documents Ability to create test plan and test scripts for upgrades and patches
Required Education:
BE / / MCA / . in Computer Science or equivalent degree from an accredited university.