Software Development Senior Specialist
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us.
We are currently seeking a Software Development Senior Specialist to join our team in GDL, Jalisco (MX-JAL), Mexico (MX).
Role Summary
Specialist in implementing and operating the OneTrust platform as the policy and evidence layer of an enterprise data governance programme. Responsible for discovering and classifying sensitive data across the estate, maintaining the data map and records of processing, automating privacy and compliance workflows, driving the application of data controls on the underlying platforms, and demonstrating control effectiveness to auditors and regulators. Works at the intersection of data engineering, security and legal or compliance functions, translating regulatory obligations into configured workflows, controls and reporting. Experience in enterprise or highly regulated environments such as financial services, public sector or international organisations.
Required Technical Skills
OneTrust
- Data Discovery & Data Governance (core)
- Discovery and scanning: configuration of connectors to structured and unstructured sources (relational databases, data lakes and object storage, cloud warehouses, SaaS applications, file repositories and collaboration tools), scan scope definition, scheduling and performance tuning.
- Classification: use and customisation of out of the box classifiers, creation of custom classification rules and regular expressions, sensitivity and regulatory category assignment, and tuning to reduce false positives.
- Retention and minimisation: retention schedules, defensible deletion workflows, management of redundant, obsolete and trivial data, and reduction of the sensitive data footprint.
OneTrust
- Data Use Governance & Control Enforcement
- Data policy engine: definition of data policies from regulatory intelligence or from internal standards, continuous evaluation of the estate against those policies, and management of violations such as expired retention, unencrypted sensitive data, open access or data stored out of place.
- Control push down: configuration of policy push down to cloud data platforms so that column masking and row filtering are enforced natively by the engine, with verification of where each control has actually been applied.
- Orchestrated remediation: automated remediation actions such as deletion, quarantine, archival, redaction and access restriction, and routing of the remaining actions to platform owners through ITSM workflows with tracking to closure.
- Boundary of responsibility: ability to specify the required control and evidence its application while the technical enforcement remains with the platform teams, avoiding duplication of ownership between the compliance layer and the data platform.
- Audit of control effectiveness: reconciliation of policy intent against the controls actually in place, use of platform audit logs as evidence, and reporting of residual exposure.
OneTrust
- Privacy Automation & Rights
- Records of processing (RoPA): design of the processing activity model, templates, ownership and periodic attestation cycles.
- Assessments: configuration and rollout of PIA, DPIA, TIA and transfer impact assessments, including questionnaire design, risk libraries, approval workflows and mitigation tracking.
- Data subject rights (DSAR): intake portals, identity verification, request routing, automated search and fulfilment against connected systems, redaction, and SLA tracking by jurisdiction.
- Incident and breach management: intake, assessment of notifiability by jurisdiction, task orchestration and generation of regulatory documentation.
- Consent and preferences: consent and cookie compliance configuration, preference centres, and propagation of consent and purpose of use to downstream systems.
OneTrust
- Risk & Compliance
- Control frameworks: implementation of control libraries and cross mapping across ISO 27001, ISO 27701, SOC 2, NIST CSF and applicable local regulations.
- Policy and evidence: policy lifecycle management, continuous evidence collection, control testing, findings, exceptions and remediation plans, and audit readiness packages.
- Third party risk: vendor onboarding, questionnaire configuration by domain, risk scoring, continuous monitoring and reassessment triggers.
- AI governance (desirable): AI system, model and dataset inventory, risk assessment against the NIST AI RMF and the EU AI Act, and generation of conformity documentation.
Platform Implementation & Administration
- Tenant configuration, organisational hierarchy, roles, permissions and segregation of duties, and SSO integration with SAML, Okta or Entra ID.