I

Security, Compliance, and Risk Testing Lead (Remote Contract)

Remote
Apply Now
AI Summary

This role leads security, compliance, and risk testing across enterprise IT initiatives, ensuring control assurance is built into the QA practice. It involves defining test strategies, managing traceability in JIRA/X-Ray, and validating access controls, segregation of duties, and audit evidence. The position is fully remote on a one-year renewable contract as an independent contractor (PJ).

Key Highlights
Fully remote one-year renewable contract as an independent contractor (PJ)
Lead security, compliance, and risk control testing across enterprise IT Roadmap initiatives
Manage traceability and test coverage using JIRA with the X-Ray module
Integrate continuous control validation into Azure DevOps CI/CD pipelines
Key Responsibilities
Align testing activities with cybersecurity, risk, and compliance expectations, consistent with the QA Framework and Operational Manual.
Support control-to-test traceability in JIRA with the X-Ray module, ensuring security and compliance requirements map clearly to test cases and evidence.
Review security and compliance testing plans across projects, ensuring alignment with enterprise QA governance.
Support quality gate evidence for security, compliance, and operational readiness, feeding into portfolio-level reporting and dashboards.
Support identity and access management testing, role validation, and segregation of duties testing with repeatable test scenarios.
Recommend enhancements to the existing toolchain, including extending Selenium, Postman, or other automation tools for access-control testing.
Integrate security and control test execution into Azure DevOps CI/CD pipelines for continuous control validation.
Coordinate with security, risk, compliance, business SMEs, project teams, SaaS vendors, and system integrators to align control testing with delivery and audit timelines.
Track security, compliance, and risk-related defects and evidence gaps through JIRA, ensuring clear ownership and resolution.
Support residual risk documentation and escalation for leadership-level risk reporting.
Create reusable security, compliance, and risk testing checklists for adoption across project QA teams.
Technical Skills Required
Security Testing Compliance Testing Risk Management
Benefits & Perks
Fully remote work arrangement

Job Description


Security, Compliance, and Risk Testing Lead

Contract: One-year renewable contract

Work arrangement: Fully remote

Engagement type: PJ / Independent Contractor

Expected start date: October–November 2026


The Security, Compliance, and Risk Testing Lead will support the validation of security controls, compliance requirements, risk controls, access controls, segregation of duties, and audit evidence across the organization's IT Roadmap initiatives, ensuring control assurance is built into the enterprise QA practice.


Standards & Strategy

  • Align testing activities with cybersecurity, risk, and compliance expectations, consistent with the QA Framework and Operational Manual.
  • Support control-to-test traceability, ensuring security and compliance requirements map clearly to test cases and evidence, using JIRA with the X-Ray module to manage traceability and test coverage.
  • Review security and compliance testing plans across projects, ensuring alignment with enterprise QA governance.
  • Support quality gate evidence for security, compliance, and operational readiness, feeding into portfolio-level reporting and dashboards.


Control Validation

  • Support identity and access management testing, role validation, and segregation of duties testing, defining repeatable test scenarios appropriate to each initiative's risk profile.
  • Recommend enhancements to the existing toolchain — including how Selenium, Postman, or other automation tools can be extended to support repeatable access-control and permissions testing — in coordination with the QA Practice Lead's broader stack assessment.
  • Where practical, integrate security and control test execution into Azure DevOps CI/CD pipelines to support continuous control validation rather than one-off audit checks.


Coordination & Vendor Collaboration

  • Coordinate with security, risk, compliance, business SMEs, project teams, SaaS vendors, and system integrators to align control testing with delivery and audit timelines.
  • Track security, compliance, and risk-related defects and evidence gaps through JIRA, ensuring clear ownership and resolution.
  • Support residual risk documentation and escalation, feeding into leadership-level risk reporting.


Reusable Assets

  • Create reusable security, compliance, and risk testing checklists to be adopted across project QA teams and institutionalized as part of the QA Practice.



Similar Jobs

Explore other opportunities that match your interests

Senior Embedded Security Engineer (Secure Boot & Hardware Root of Trust)

Cyber Security
•
4w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

BairesDev

Brazil

Embedded Linux Security Engineer

Cyber Security
•
4w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

BairesDev

Brazil

Senior Identity and Access Management (IAM) Security Engineer

Cyber Security
•
4w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

BairesDev

Brazil

Subscribe our newsletter

New Things Will Always Update Regularly