Software Development Senior Specialist
Apply now »Date: Aug 27, 2026
Location: GDL, JAL, MX
Company: NTT DATA Services
Req ID: 387113
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Software Development Senior Specialist to join our team in GDL, Jalisco (MX-JAL), Mexico (MX).
ROLE SUMMARY
Specialist in implementing and operating the OneTrust platform as the policy and evidence layer of an enterprise data governance programme. Responsible for discovering and classifying sensitive data across the estate, maintaining the data map and records of processing, automating privacy and compliance workflows, driving the application of data controls on the underlying platforms, and demonstrating control effectiveness to auditors and regulators. Works at the intersection of data engineering, security and legal or compliance functions, translating regulatory obligations into configured workflows, controls and reporting. Experience in enterprise or highly regulated environments such as financial services, public sector or international organisations.
REQUIRED TECHNICAL SKILLS
OneTrust · Data Discovery & Data Governance (core)
• Discovery and scanning: configuration of connectors to structured and unstructured sources (relational databases, data lakes and object storage, cloud warehouses, SaaS applications, file repositories and collaboration tools), scan scope definition, scheduling and performance tuning.
• Classification: use and customisation of out of the box classifiers, creation of custom classification rules and regular expressions, sensitivity and regulatory category assignment, and tuning to reduce false positives.
• Retention and minimisation: retention schedules, defensible deletion workflows, management of redundant, obsolete and trivial data, and reduction of the sensitive data footprint.
OneTrust · Data Use Governance & Control Enforcement
• Data policy engine: definition of data policies from regulatory intelligence or from internal standards, continuous evaluation of the estate against those policies, and management of violations such as expired retention, unencrypted sensitive data, open access or data stored out of place.
• Control push down: configuration of policy push down to cloud data platforms so that column masking and row filtering are enforced natively by the engine, with verification of where each control has actually been applied.
• Orchestrated remediation: automated remediation actions such as deletion, quarantine, archival, redaction and access restriction, and routing of the remaining actions to platform owners through ITSM workflows with tracking to closure.
• Boundary of responsibility: ability to specify the required control and evidence its application while the technical enforcement remains with the platform teams, avoiding duplication of ownership between the compliance layer and the data platform.
• Audit of control effectiveness: reconciliation of policy intent against the controls actually in place, use of platform audit logs as evidence, and reporting of residual exposure.
OneTrust · Privacy Automation & Rights
• Records of processing (RoPA): design of the processing activity model, templates, ownership and periodic attestation cycles.
• Assessments: configuration and rollout of PIA, DPIA, TIA and transfer impact assessments, including questionnaire design, risk libraries, approval workflows and mitigation tracking.
• Data subject rights (DSAR): intake portals, identity verification, request routing, automated search and fulfilment against connected systems, redaction, and SLA tracking by jurisdiction.
• Incident and breach management: intake, assessment of notifiability by jurisdiction, task orchestration and generation of regulatory documentation.
• Consent and preferences: consent and cookie compliance configuration, preference centres, and propagation of consent and purpose of use to downstream systems.
OneTrust · Risk & Compliance
• Control frameworks: implementation of control libraries and cross mapping across ISO 27001, ISO 27701, SOC 2, NIST CSF and applicable local regulations.
• Policy and evidence: policy lifecycle management, continuous evidence collection, control testing, findings, exceptions and remediation plans, and audit readiness packages.
• Third party risk: vendor onboarding, questionnaire configuration by domain, risk scoring, continuous monitoring and reassessment triggers.
• AI governance (desirable): AI system, model and dataset inventory, risk assessment against the NIST AI RMF and the EU AI Act, and generation of conformity documentation.
Platform Implementation & Administration
• Tenant configuration, organisational hierarchy, roles, permissions and segregation of duties, and SSO integration with SAML, Okta or Entra ID.
• Environment management, promotion of configuration between environments, platform upgrades and regression validation.
• Use of the OneTrust REST APIs and webhooks for automation, bulk operations and integration with the broader ecosystem.
Integrations & Interoperability
• OneTrust and Informatica (metadata exchange): integration with Informatica catalogs to consume business glossary, data domains, technical metadata and lineage in order to enrich the OneTrust data map, and to publish classification and sensitivity results back as governed asset attributes. Implemented through available connectors or, where none applies, through REST APIs and metadata exchange pipelines.
• AWS as an enforcement target: scanning of S3, Redshift, RDS and Oracle workloads, evaluation of encryption, retention and access posture, and coordination of remediation with IAM, S3 bucket policies, Lake Formation and KMS as the technical control points.
• Denodo and virtualization layers (metadata level): alignment of classification and sensitivity metadata with the semantic layer, understanding that row and column level security, roles and masking are enforced by the virtualization platform itself.
• Operational tooling: integration with ITSM and collaboration tools such as ServiceNow, Jira, Slack or Teams for task routing and escalation, and with identity providers for user and role provisioning.
• Alignment of glossary, data domains and ownership between the catalog and the privacy inventory, so that a single definition of a sensitive data element serves both governance and compliance.
Data Security & Compliance Foundations
• Working knowledge of GDPR, CCPA and CPRA, LGPD and other applicable privacy regimes, plus sector specific obligations where relevant.
• Security and compliance frameworks: ISO 27001 and ISO 27701, SOC 2, NIST CSF, and the principles of privacy by design and data minimisation.
• Data protection techniques: classification schemes, masking, tokenisation, encryption at rest and in transit, and role based and attribute based access control, with the ability to specify them precisely even when execution sits with the platform teams.
• SQL and basic Python or scripting for validation, reconciliation and automation of bulk platform operations.
Complementary Tooling (desirable)
• Informatica catalogs: Cloud Data Governance and Catalog (CDGC), Enterprise Data Catalog or KEY RESPONSIBILITIES
• Implement and configure OneTrust modules according to the client privacy and compliance programme, from tenant setup through to production rollout.
• Onboard data sources into discovery, define scan scope and cadence, tune classification, and maintain coverage of the estate as new systems are added.
• Build and maintain the data map and records of processing, keeping them synchronised with discovery results and with the enterprise catalog.
• Configure the data policy engine, monitor policy violations, and drive remediation to closure either through automated actions or through the platform owners.
• Coordinate the application of data controls on the underlying platforms, specifying the required masking, filtering, encryption or access restriction and evidencing that it has been applied.
• Configure and operate assessment, DSAR, incident and consent workflows, and monitor compliance with regulatory response times.
• Implement control frameworks and evidence collection, and prepare audit and certification packages for internal and external reviewers.
• Design and build integrations with the surrounding ecosystem, with particular attention to the Informatica catalog, ensuring consistent classification, glossary and ownership across both platforms.
• Translate regulatory and policy requirements into platform configuration, and document the rationale so that every decision is auditable.
• Produce compliance and risk posture reporting for operational teams and for executive stakeholders.
• Provide L2 and L3 support for the platform: scan and integration failures, workflow issues, permission problems, and root cause analysis with preventive actions.
WAYS OF WORKING
• Working proficiency in English and Spanish (written and spoken).
CERTIFICATIONS (DESIRABLE)
• OneTrust platform certifications at expert level in the relevant modules (Privacy Automation, Data Discovery, Third Party Risk, Tech Risk and Compliance).
• IAPP CIPP/E or CIPP/US, CIPM, or CIPT.
• Informatica Cloud Data Governance and Catalog, Professional Certification (ICP).
• ISO 27001 Lead Implementer or Lead Auditor.
About NTT DATA
NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.
NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.
Job Segment:
Cloud, Developer, Testing, ERP, Database, Technology