We are looking for a hands-on OneTrust Architect / SME to design, configure and drive adoption of the OneTrust platform for Third-Party Risk Management (TPRM) within a leading Swiss enterprise environment.
This is a dual-facing role. The right person must be equally comfortable deep in platform configuration, workflows, risk models, inherent / residual risk scoring, integrations and in front of senior business stakeholders, translating risk, compliance and procurement requirements into a working, governed TPRM operating model.
The ideal candidate has led at least one end-to-end OneTrust TPRM implementation and can act as the technical and functional anchor for the program.
Key Responsibilities
Platform Architecture & Configuration
Design and configure OneTrust TPRM modules: vendor inventory, risk assessments, inherent/residual risk scoring models, due diligence questionnaires, contract and renewal workflows, and remediation/issue management.
Configure automated workflows, approval chains, notifications and SLA triggers aligned to the client’s third-party risk lifecycle (onboarding, assessment, monitoring, offboarding).
Own integration design between OneTrust and adjacent systems (e.g. SAP Ariba, GRC tools, CLM, SSO / IAM, ticketing systems) via APIs and connectors.
Configure and maintain risk taxonomies, scoring logic, inherent risk tiering and control libraries in line with the client’s risk appetite framework.
Define and maintain role-based access control (RBAC), data segregation and audit trail configuration within the platform.
Business & Stakeholder Engagement
Act as the primary liaison between Risk, Compliance, Procurement, Legal, Security and business stakeholders to gather and translate requirements into OneTrust configuration.
Run workshops to map current-state TPRM processes and design future-state workflows within OneTrust.
Present platform capabilities, roadmap and configuration trade-offs to senior stakeholders and steering committees.
Support change management and training for business users, vendor managers and risk/compliance teams adopting the platform.
TPRM Program Delivery
Drive the TPRM implementation roadmap in coordination with program / delivery leadership including scoping, sequencing modules, managing dependencies.
Define and track KPIs / metrics for TPRM maturity: assessment cycle time, overdue reviews, risk remediation SLAs, vendor coverage.
Ensure alignment with relevant regulatory frameworks (FINMA, DORA, GDPR, NIST, ISO 27001, SIG / SIG-Lite) as applicable to the client’s jurisdiction.
Support internal/external audit requests by ensuring OneTrust configuration and data are audit ready.
Identify and remediate configuration gaps, technical debt and process bottlenecks as the platform scales across business units and geographies.
Requirements
5+ years working with GRC / TPRM platforms in financial services, with hands-on OneTrust configuration experience (TPRM module mandatory; exposure to Privacy Management, GRC or Ethics modules a plus).
Proven experience owning or co-leading at least one full OneTrust TPRM implementation lifecycle (design, configure, UAT, go-live, hypercare).
Strong understanding of third-party/vendor risk management processes: inherent risk scoring, due diligence, contract risk, ongoing monitoring, offboarding.
Working knowledge of relevant regulatory/compliance frameworks: DORA, GDPR, FINMA circulars, NIST CSF, ISO 27001, SOC 2, SIG questionnaires.
Experience integrating OneTrust with procurement, CLM, GRC or ticketing platforms via API / connectors.
Strong stakeholder management skills — comfortable running workshops with senior Risk, Compliance and Procurement leaders.
Excellent written and verbal communication skills in English; ability to translate technical configuration into business language and vice versa.
Familiarity with agile delivery (Jira, GitLab or Azure DevOps) for tracking configuration and rollout
Comfortable operating as both an individual contributor (configuring the platform) and a trusted advisor (facing off with business/senior stakeholders).
Structured, detail-oriented, able to manage multiple concurrent workstreams under deadline pressure.
Pragmatic problem-solver who can navigate ambiguity in an evolving regulatory and organizational landscape.
Offer
The Offer & Logistics
Location: 100% Remote from Romania.
Working hours: Switzerland business hours (8 hours/day, CET schedule).
Compensation: Negotiable salary, based on experience.
Engagement type: Contract / Freelance / B2B.
Industry: Financial Services for a leading Swiss Enterprise.
Start Date: ASAP, with immediate availability preferred.
Applications
andra.ilie@randstad.ro
Organisation/Department
IT
Job description
We are looking for a hands-on OneTrust Architect / SME to design, configure and drive adoption of the OneTrust platform for Third-Party Risk Management (TPRM) within a leading Swiss enterprise environment.
This is a dual-facing role. The right person must be equally comfortable deep in platform configuration, workflows, risk models, inherent / residual risk scoring, integrations and in front of senior business stakeholders, translating risk, compliance and procurement requirements into a working, governed TPRM operating model.
The ideal candidate has led at least one end-to-end OneTrust TPRM implementation and can act as the technical and functional anchor for the program.
Key Responsibilities
Platform Architecture & Configuration
Design and configure OneTrust TPRM modules: vendor inventory, risk assessments, inherent/residual risk scoring models, due diligence questionnaires, contract and renewal workflows, and remediation/issue management.
Configure automated workflows, approval chains, notifications and SLA triggers aligned to the client’s third-party risk lifecycle (onboarding, assessment, monitoring, offboarding).
Own integration design between OneTrust and adjacent systems (e.g. SAP Ariba, GRC tools, CLM, SSO / IAM, ticketing systems) via APIs and connectors.
Configure and maintain risk taxonomies, scoring logic, inherent risk tiering and control libraries in line with the client’s risk appetite framework.
Define and maintain role-based access control (RBAC), data segregation and audit trail configuration within the platform.
Business & Stakeholder Engagement
Act as the primary liaison between Risk, Compliance, Procurement, Legal, Security and business stakeholders to gather and translate requirements into OneTrust configuration.
Run workshops to map current-state TPRM processes and design future-state workflows within OneTrust.
Present platform capabilities, roadmap and configuration trade-offs to senior stakeholders and steering committees.
Support change management and training for business users, vendor managers and risk/compliance teams adopting the platform.
TPRM Program Delivery
Drive the TPRM implementation roadmap in coordination with program / delivery leadership including scoping, sequencing modules, managing dependencies.
Define and track KPIs / metrics for TPRM maturity: assessment cycle time, overdue reviews, risk remediation SLAs, vendor coverage.
Ensure alignment with relevant regulatory frameworks (FINMA, DORA, GDPR, NIST, ISO 27001, SIG / SIG-Lite) as applicable to the client’s jurisdiction.
Support internal/external audit requests by ensuring OneTrust configuration and data are audit ready.
Identify and remediate configuration gaps, technical debt and process bottlenecks as the platform scales across business units and geographies.
Requirements
5+ years working with GRC / TPRM platforms in financial services, with hands-on OneTrust configuration experience (TPRM module mandatory; exposure to Privacy Management, GRC or Ethics modules a plus).
Proven experience owning or co-leading at least one full OneTrust TPRM implementation lifecycle (design, configure, UAT, go-live, hypercare).
Strong understanding of third-party/vendor risk management processes: inherent risk scoring, due diligence, contract risk, ongoing monitoring, offboarding.
Working knowledge of relevant regulatory/compliance frameworks: DORA, GDPR, FINMA circulars, NIST CSF, ISO 27001, SOC 2, SIG questionnaires.
Experience integrating OneTrust with procurement, CLM, GRC or ticketing platforms via API / connectors.
Strong stakeholder management skills — comfortable running workshops with senior Risk, Compliance and Procurement leaders.
Excellent written and verbal communication skills in English; ability to translate technical configuration into business language and vice versa.
Familiarity with agile delivery (Jira, GitLab or Azure DevOps) for tracking configuration and rollout
Comfortable operating as both an individual contributor (configuring the platform) and a trusted advisor (facing off with business/senior stakeholders).
Structured, detail-oriented, able to manage multiple concurrent workstreams under deadline pressure.
Pragmatic problem-solver who can navigate ambiguity in an evolving regulatory and organizational landscape.
Offer
The Offer & Logistics
Location: 100% Remote from Romania.
Working hours: Switzerland business hours (8 hours/day, CET schedule).
Compensation: Negotiable salary, based on experience.
Engagement type: Contract / Freelance / B2B.
Industry: Financial Services for a leading Swiss Enterprise.
Start Date: ASAP, with immediate availability preferred.