Position Overview
We are seeking an experienced OneTrust Cookie & Privacy Management Architect to lead the architecture, implementation, and management of enterprise-wide privacy, consent, and data governance solutions leveraging the OneTrust platform.
The ideal candidate will have extensive hands-on experience with OneTrust, strong knowledge of global privacy regulations, and a proven track record of leading large-scale privacy transformation initiatives. This role requires a combination of technical architecture, privacy governance, regulatory expertise, integration leadership, and stakeholder management.
Mandatory Certification: Certified Information Privacy Manager (CIPM) – IAPP
Key Responsibilities
OneTrust Architecture & Implementation
- Lead the architecture, design, implementation, and ongoing enhancement of enterprise-wide OneTrust Privacy Management solutions.
- Configure, manage, and optimize OneTrust modules, including:
- Cookie Consent & Preference Management
- Privacy Rights Automation (DSAR/DSR)
- Data Mapping
- Data Discovery
- Privacy Impact Assessments (PIA)
- Data Protection Impact Assessments (DPIA)
- Consent & Preference Management
- Third-Party Risk Management
- Incident & Breach Management
- Define enterprise privacy architecture, governance frameworks, standards, and operating models aligned with business and regulatory requirements.
- Lead solution design, architecture reviews, governance reviews, and technical approvals.
Cookie Compliance & Consent Management
- Design and implement enterprise cookie consent and preference-management solutions across global websites and digital properties.
- Manage cookie inventories, classification, categorization, scanning, and remediation processes.
- Configure geolocation-based consent models and multilingual privacy notices.
- Establish and maintain consent frameworks aligned with applicable privacy regulations.
- Ensure solutions support compliance with GDPR, ePrivacy Directive, CCPA/CPRA, LGPD, and other applicable global privacy regulations.
- Partner with digital, marketing, legal, security, and technology teams to implement privacy-compliant web experiences.
Privacy Governance & Compliance
- Establish and promote Privacy-by-Design principles across business and technology initiatives.
- Lead Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk evaluations.
- Define, implement, and maintain Records of Processing Activities (RoPA).
- Develop privacy governance frameworks, policies, standards, procedures, and operating models.
- Collaborate closely with Legal, Compliance, Information Security, Data Governance, Risk, and Technology teams to ensure regulatory compliance.
- Translate regulatory requirements into practical technical and operational controls.
Integration & Technical Leadership
- Architect and oversee integrations between OneTrust and enterprise platforms, including:
- ServiceNow
- Salesforce
- Microsoft Azure
- Custom enterprise applications
- Design and implement APIs, workflows, automation, and data integrations supporting privacy operations.
- Define integration architecture, data flows, security requirements, and technical standards.
- Provide technical leadership and mentorship to implementation and engineering teams.
- Troubleshoot complex OneTrust configuration, integration, and privacy-management challenges.
Stakeholder & Program Leadership
- Act as a senior technical and privacy subject-matter expert for enterprise stakeholders.
- Partner with business leaders, privacy officers, legal teams, compliance teams, security teams, data governance teams, and technology organizations.
- Lead workshops, requirements gathering, solution design sessions, architecture reviews, and governance meetings.
- Translate complex privacy and technical requirements into clear business and implementation strategies.
- Provide guidance and mentorship to OneTrust implementation teams and other technical resources.
Required Qualifications
- 15+ years of professional experience in Privacy, Data Governance, Compliance, Risk Management, Information Governance, or Enterprise Architecture.
- 9+ years of hands-on experience implementing, configuring, architecting, and managing OneTrust solutions.
- Proven experience leading enterprise-scale privacy, consent management, and data governance programs.
- Strong hands-on experience with OneTrust modules related to:
- Cookie Consent Management
- Preference & Consent Management
- DSAR/DSR Automation
- Data Mapping
- Data Discovery
- PIA/DPIA
- RoPA
- Third-Party Risk
- Incident & Breach Management
- Deep understanding of global privacy regulations, including:
- GDPR
- ePrivacy Directive
- CCPA/CPRA
- LGPD
- PIPEDA
- Other applicable global privacy regulations
- Strong experience designing and implementing cookie management, consent frameworks, cookie inventories, and preference centers.
- Experience developing enterprise privacy governance frameworks, operating models, policies, and standards.
- Strong understanding of Privacy-by-Design principles and privacy risk management.
- Experience architecting integrations between OneTrust and enterprise applications using APIs, workflows, and automation.
- Strong stakeholder management, communication, leadership, and presentation skills.
Mandatory Certification
- Certified Information Privacy Manager (CIPM) – IAPP — Required