Security, Compliance, and Risk Testing Lead (Remote Contract)
This role leads security, compliance, and risk testing across enterprise IT initiatives, ensuring control assurance is built into the QA practice. It involves defining test strategies, managing traceability in JIRA/X-Ray, and validating access controls, segregation of duties, and audit evidence. The position is fully remote on a one-year renewable contract as an independent contractor (PJ).
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Security, Compliance, and Risk Testing Lead
Contract: One-year renewable contract
Work arrangement: Fully remote
Engagement type: PJ / Independent Contractor
Expected start date: October–November 2026
The Security, Compliance, and Risk Testing Lead will support the validation of security controls, compliance requirements, risk controls, access controls, segregation of duties, and audit evidence across the organization's IT Roadmap initiatives, ensuring control assurance is built into the enterprise QA practice.
Standards & Strategy
- Align testing activities with cybersecurity, risk, and compliance expectations, consistent with the QA Framework and Operational Manual.
- Support control-to-test traceability, ensuring security and compliance requirements map clearly to test cases and evidence, using JIRA with the X-Ray module to manage traceability and test coverage.
- Review security and compliance testing plans across projects, ensuring alignment with enterprise QA governance.
- Support quality gate evidence for security, compliance, and operational readiness, feeding into portfolio-level reporting and dashboards.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Control Validation
- Support identity and access management testing, role validation, and segregation of duties testing, defining repeatable test scenarios appropriate to each initiative's risk profile.
- Recommend enhancements to the existing toolchain — including how Selenium, Postman, or other automation tools can be extended to support repeatable access-control and permissions testing — in coordination with the QA Practice Lead's broader stack assessment.
- Where practical, integrate security and control test execution into Azure DevOps CI/CD pipelines to support continuous control validation rather than one-off audit checks.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Coordination & Vendor Collaboration
- Coordinate with security, risk, compliance, business SMEs, project teams, SaaS vendors, and system integrators to align control testing with delivery and audit timelines.
- Track security, compliance, and risk-related defects and evidence gaps through JIRA, ensuring clear ownership and resolution.
- Support residual risk documentation and escalation, feeding into leadership-level risk reporting.
Reusable Assets
- Create reusable security, compliance, and risk testing checklists to be adopted across project QA teams and institutionalized as part of the QA Practice.
Similar Jobs
Explore other opportunities that match your interests