27 Sep
|
SysTechCorp
|
Hyderabad
27 Sep
SysTechCorp
Hyderabad
Role Purpose
Own acceptance strategy, cross-stream validation governance, and evidence quality for all 16 delivery streams. This role does not replace domain-specific test execution by workstream engineers Playwright is owned by Frontend, TLS/security tests by the Security Engineer, infrastructure validation by Cloud engineers, and OWASP/unit/integration tests by Java engineers. The QA Validation Lead independently validates completeness, coordinates cross-stream validation, performs targeted independent spot-checks, and confirms agreed acceptance criteria are met before any package is submitted to the client.
Also owns the acceptance tracker, evidence index, gate status, and closure tracking.
Key Responsibilities
- Define formal, measurable acceptance criteria for each delivery stream at the Design Review gate criteria agreed with client stakeholders before execution begins; ambiguous criteria flagged and resolved before sign-off
- Independently validate completeness of all workstream evidence packages produced by stream engineers — spot-check for accuracy, completeness, and consistency before the four-gate submission
- Coordinate cross-stream validation — identify dependencies between streams, ensure evidence from one stream supports acceptance of dependent streams, flag gaps
- Own the acceptance tracker, evidence index, and gate status dashboard — live status per stream, per gate, per setting
- Collect and assemble final closure evidence from all stream engineers — Wiz rescan confirmation from Cloud Engineer Wiz, patch compliance from Cloud Engineer OS/Patching, cipher scan from Security Engineer, OWASP evidence from Java engineers, Playwright results from Frontend, linting reports from DevSecOps
- Coordinate Wiz rescan evidence — confirm specific finding IDs closed per batch using Wiz finding export; package evidence by remediation phase
- Track the 2-business-day four-gate review SLA — escalate any breach to the Program Manager within 4 hours; log in RAID
- Monitor QA capacity activation trigger — if more than 4 delivery streams are simultaneously in Pre-Delivery Testing/evidence closure for >5 business days, or utilisation exceeds 85% for 2 consecutive weeks, flag to Program Manager
- Produce the Phase 6 end-to-end validation report — all 16 streams accepted; report includes evidence index, outstanding risk-accepted findings, and post-engagement review dates
Must-Have Skills & Experience
- 7+ years QA engineering; 3+ years on cloud infrastructure or security remediation validation in a regulated industry
- Cross-stream validation governance — ability to coordinate evidence collection across 16 parallel delivery streams without losing threads
- Formal closure evidence packaging — SOC 2, ISO 27001, PCI DSS, or equivalent audit-quality documentation experience
- Acceptance criteria definition — writing measurable, unambiguous criteria that distinguish "done" from "done enough"
- AWS CloudWatch, VPC Flow Logs, AWS Config — interpretation of compliance reports as validation evidence
- AWS SSM Patch Manager — patch compliance report generation, patch state interpretation (Installed, Missing, Failed)
- OWASP Dependency-Check report interpretation — before/after Critical/High count comparison, PR reference mapping
- TLS/SSL endpoint validation — OpenSSL s_client cipher enumeration, nmap ssl-enum-ciphers, deprecated protocol detection
- Wiz finding export and analysis — CSV/JSON export, finding ID tracking, rescan result comparison, evidence packaging per finding
- Confluence documentation to executive standard — evidence packages self-contained and structured for CTO and ISSO review
Nice-to-Have Skills
- ISTQB Foundation or Advanced certification
- Qualys vulnerability report interpretation
- ISO 27001 internal audit or SOC 2 readiness assessment experience
- TestRail or Zephyr — test case management, test plan, execution tracking, coverage reporting
- AWS Security Hub — finding aggregation interpretation for cross-stream evidence cross-referencing
- Microsoft Excel or Google Sheets — evidence tracking matrix, gate status dashboard design
Tools & Platforms Confluence (evidence packaging, acceptance criteria), Jira (delivery tracking, SLA monitoring, RAID), OpenSSL (sclient TLS scanning), nmap (ssl-enum-ciphers), CloudWatch (Logs Insights, dashboards), AWS Config (compliance reports), AWS SSM Patch Manager (patch compliance), Qualys (read), Wiz (finding export, rescan coordination), OWASP Dependency-Check (report interpretation), Bitbucket (PR evidence), Nexus (artifact verification), Microsoft Excel (evidence tracking matrix, gate status dashboard)
📌 QA / Validation Lead (Hyderabad)
🏢 SysTechCorp
📍 Hyderabad