Negotiable
Outside
Remote
USA
Summary: The role of OneTrust Program Manager involves overseeing privacy program management, enterprise tech program management, and OneTrust management skills. The ideal candidate will possess a blend of regulatory knowledge, technical expertise, and change leadership, particularly in Consent and Preference Management (CPM) solutions. The position requires strong communication and stakeholder management skills to align various teams and ensure compliance with privacy regulations. The focus is on driving adoption and managing risks while implementing OneTrust solutions effectively.
Key Responsibilities:
- Develop and manage privacy program roadmaps across business units and digital assets.
- Align privacy, marketing, legal, IT, and product teams through effective stakeholder management.
- Drive change management initiatives across internal teams and customer-facing processes.
- Identify regulatory, reputational, and technical risks and develop mitigation plans.
- Manage implementation partners and OneTrust licensing for budget and vendor management.
- Ensure compliance through audit and reporting mechanisms, including dashboards and regulatory reporting.
- Translate legal requirements into operational consent rules for effective governance.
- Design user-friendly preference centers to enhance end-user advocacy.
Key Skills:
- Expertise in privacy regulations such as GDPR, CCPA/CPRA, HIPAA, and LGPD.
- Knowledge of consent and preference management concepts.
- Understanding of marketing and digital compliance rules.
- Experience with OneTrust platform, including Consent & Preference Management module.
- Technical acumen in REST APIs, tag management systems, and cloud environments.
- Proficiency in data governance alignment and audit/reporting processes.
- Strong cross-functional communication and negotiation skills.
- Ability to manage risks and drive change across various teams.
Salary (Rate): undetermined
City: undetermined
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: Other
About the Client
Our client is a financially strong insurance and financial services provider, built on the
philosophy of people helping people, meeting the needs of middle-market consumers and the
businesses that serve them since day one. With a culture rooted and focused on creating a
more equitable society and financial system, they are deeply committed to giving back to our
communities and improving the lives of those we serve today and tomorrow.
Job Description
We are looking for a program manager who combines privacy program experience (legal +
compliance), enterprise tech program management, and onetrust management skills.
They should have experience in the Consent and Preference Management (CPM) solution
OneTrust and the skills for program management a good blend of regulatory knowledge,
technical depth, and change leadership.
The key skills and experience required are
Domain & Regulatory Knowledge
Privacy Regulations Expertise: GDPR, CCPA/CPRA, HIPAA, LGPD, and other global/local
privacy laws.
Consent & Preference Management Concepts: Knowledge of how consent collection,
withdrawal, and preference updates must be handled.
Marketing & Digital Compliance: Understanding of rules around cookies,
email/SMS/telemarketing opt-in/opt-out, and cross-border data transfers.
Insurance & Financial Services Context (if applicable): Industry-specific compliance
(NAIC, EIOPA, IRDAI, etc.).
Program & Project Management Skills
Roadmap Development: Phasing rollouts across business units, geographies, and digital
assets.
Stakeholder Management: Aligning privacy, marketing, legal, IT, and product teams.
Change Management: Driving adoption across internal teams, field agents, and
customer-facing processes.
Risk Management: Identifying risks (regulatory, reputational, technical) and mitigation
planning.
Budget & Vendor Management: Managing implementation partners and OneTrust
licensing.
Technical & Solution Skills
OneTrust Platform Knowledge:
o Consent & Preference Management module
o Cookie Consent (Web & Mobile SDKs)
o Integration capabilities (APIs, SDKs, identity management)
System Integration:
o CRM (Salesforce, MS Dynamics)
o Marketing Automation (Adobe, HubSpot, SFMC)
o Identity & Access Management (Okta, Ping, Azure AD)
Data Flow Mapping: Capturing how consent flows between systems.
Technical Acumen: Understanding REST APIs, tag management systems, and cloud
environments.
Governance & Data Skills
Data Governance Alignment: Linking consent metadata with enterprise data catalog and
master data.
Audit & Reporting: Ensuring compliance dashboards, regulatory reporting, and audit
trails are set up.
Policy Translation: Turning legal requirements into operational consent rules.
Leadership & Soft Skills
Cross-functional Communication: Bridging legal, compliance, marketing, IT, and business
units.
Negotiation & Conflict Resolution: Handling tension between customer experience and
compliance.
End-user Advocacy: Designing preference centers that are user-friendly.