Senior Quality Assurance Engineer — B2B SaaS Platform
About the role
Role Overview
OBRYN GUARD® is seeking an experienced Senior Quality Assurance Engineer to lead quality assurance across our B2B SaaS platform. This role is responsible for ensuring the application is reliable, secure, accurate, scalable, and ready for enterprise customers. The Senior QA Engineer will establish testing processes, perform manual and automated testing, validate critical workflows, document defects, and work directly with engineering, product, security, and leadership. This is not a basic manual testing role. The ideal candidate must be capable of independently building a structured QA program, creating automated test coverage, identifying technical risks, and determining whether releases are ready for production.
Key Responsibilities
QA Strategy and Ownership
Develop and maintain the platform’s QA strategy, testing standards, release criteria, and quality controls. Build scalable QA processes for an expanding enterprise SaaS platform. Identify risks early and track test coverage, defects, regression results, and production issues. Approve, reject, or block releases based on documented risk.
Functional and End-to-End Testing
Perform functional, integration, regression, exploratory, system, and end-to-end testing. Validate complete user journeys from onboarding through reporting.
Test critical functionality, including
Authentication, account recovery, and multi-factor authentication. Organization, property, and multi-location structures. Role-based access control and user permissions. Risk assessments, control tracking, and compliance questionnaires. Evidence uploads, document management, and approval workflows. Staff training, vendor access, and third-party risk records. Incident logging, dashboards, calculations, notifications, and reporting. Administrative tools and report generation. Confirm functionality works across different users, organizations, locations, roles, and account configurations. Identify edge cases, calculation errors, workflow failures, and usability problems.
Test Automation
Design, build, and maintain automated UI, API, integration, and regression tests. Select and implement suitable automation tools and frameworks. Integrate automated testing into CI/CD pipelines. Prioritize automation for high-risk and business-critical workflows. Maintain reliable test scripts, data, environments, and documentation. Investigate unstable tests and improve product testability with engineers.
API and Integration Testing
Test APIs, authentication mechanisms, webhooks, data exchanges, and approved integrations. Validate requests, responses, permissions, data accuracy, error handling, and performance. Test token permissions, expiration, failures, and reconnection processes. Confirm synchronized data is collected and displayed accurately. Ensure integration failures do not cause unauthorized access, data corruption, or inaccurate reporting.
Security and Access-Control Testing
Test authentication, authorization, session management, permissions, and tenant separation. Verify users cannot access organizations, files, reports, or functions outside their assigned permissions. Test for privilege escalation, improper access controls, data exposure, unsafe uploads, and weak input validation. Reproduce reported vulnerabilities, verify remediation, and escalate critical defects. Support penetration-testing remediation when required.
Platform and Control Validation
Validate control statuses, evidence requirements, risk scores, calculations, and reporting logic. Test the difference between automatically monitored and manually assessed controls. Confirm requirements are not marked complete without sufficient evidence or validation. Test functionality supporting PCI DSS, SOC 2, ISO 27001, NIST, cyber insurance readiness, and other approved standards. Work with technical and compliance specialists to verify platform accuracy.
Regression and Release Testing
Build and maintain a structured regression testing program. Complete regression and acceptance testing before production releases. Define release criteria and provide documented release recommendations. Conduct smoke testing after deployments. Verify fixes and confirm changes have not created new defects. Support pilot deployments and enterprise customer rollouts.
Performance and Reliability
Test performance under realistic customer usage conditions. Identify slow pages, delayed API responses, bottlenecks, and unstable workflows. Support load, stress, scalability, and endurance testing. Test across supported browsers, devices, operating systems, and screen sizes. Validate platform behaviour during service interruptions, integration failures, and unexpected inputs.
Defect Management
Identify, reproduce, document, prioritize, and track software defects. Produce clear defect reports containing the issue, environment, reproduction steps, expected and actual results, evidence, severity, and business impact. Participate in defect triage, verify fixes, and perform targeted regression testing. Identify recurring defect patterns and recommend preventive improvements. Escalate release-blocking issues immediately.
Requirements and Collaboration
Review requirements, user stories, designs, technical specifications, and acceptance criteria. Identify missing requirements, unclear workflows, risks, dependencies, and edge cases. Work with engineering and product teams to create measurable acceptance criteria. Participate in sprint planning, technical discussions, and release reviews. Challenge incomplete, unstable, or high-risk functionality before deployment. Support user acceptance testing with internal stakeholders and pilot customers.
Documentation and Reporting
Maintain test plans, test cases, regression suites, automation documentation, release checklists, defect reports, QA procedures, and coverage reports. Report testing progress, unresolved risks, defect trends, and release readiness to leadership. Document known limitations, accepted risks, workarounds, and deferred issues. Maintain testing evidence for customer reviews, audits, and internal assessments.
Continuous Improvement
Evaluate QA and engineering practices and recommend practical improvements. Analyze production issues and convert them into permanent regression tests. Improve testing efficiency without creating unnecessary development delays. Help establish quality as a shared responsibility across the company. Mentor future QA team members as the department expands.
Qualifications
Significant experience in software quality assurance, quality engineering, or test automation. Experience testing B2B SaaS platforms, enterprise web applications, or complex multi-user systems. Strong knowledge of Agile development, release management, defect management, and QA methodologies. Experience creating test strategies, regression suites, automated UI and API tests, and release criteria. Experience testing APIs with Postman or equivalent tools. Understanding of frontend, backend, database, API, and cloud application architecture. Strong knowledge of authentication, authorization, permissions, tenant separation, and data integrity. Experience with defect tracking, documentation, version control, and project-management tools. Ability to communicate technical issues clearly to technical and non-technical stakeholders. Strong attention to detail, accountability, organization, and professional judgment. Ability to independently prioritize risk and own platform quality. Comfortable working in an early-stage company where systems are developing quickly.
Preferred Technical Experience
Playwright, Cypress, Selenium, WebdriverIO, or equivalent tools. Postman, Newman, REST Assured, pytest, or equivalent frameworks. JavaScript, TypeScript, Python, Java, or another relevant language. GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or equivalent platforms. SQL, Git, relational databases, and data-integrity testing. JMeter, k6, Locust, or similar performance-testing tools. Experience with multi-tenant SaaS, RBAC, cloud applications, logging, monitoring, accessibility, and cross-browser testing.
Preferred Industry Experience
Experience in B2B SaaS, governance, risk and compliance, audit technology, hospitality technology, or enterprise software. Familiarity with PCI DSS, SOC 2, ISO 27001, NIST, vendor risk, evidence management, or access control. Experience testing platforms that manage sensitive customer, business, financial, or compliance information. Experience supporting security reviews, audits, enterprise assessments, or penetration-testing remediation. Hospitality or multi-location business experience is an asset.
Ideal Candidate
The ideal candidate is methodical, technically capable, highly accountable, and unwilling to approve software simply because it works under normal conditions. They must think like an enterprise customer, test like a technical specialist, document like an auditor, and communicate like a business professional. They must be comfortable challenging assumptions and preventing unfinished or high-risk functionality from reaching production. The successful candidate will take ownership of product quality and help ensure OBRYN GUARD® becomes a reliable, scalable, and enterprise-ready B2B SaaS platform.
Compensation
Compensation and engagement terms will be discussed with qualified candidates based on experience, technical ability, availability, and expected responsibilities.
Thank you for your interest in OBRYN GUARD®
Sincerely, Leadership Team OBRYN GUARD INC.
Not the right fit? Search for Quality Assurance Engineer jobs in Toronto, Ontario, Canada
About OBRYN GUARD
OBRYN GUARD™ helps hospitality ownership groups and operators strengthen cyber risk, compliance, and audit readiness.
Built for hotel environments, we support leadership teams with cyber risk assessments, control gap analysis, vendor risk visibility, policy documentation, executive reporting, and readiness support for PCI DSS, SOC 2, ISO 27001, NIST CSF, HIPAA, and cyber insurance requirements.
Our focus is simple: help hospitality organizations move beyond checkbox compliance toward measurable risk reduction, stronger operational control, and defensible security maturity.
Similar Jobs
Senior Quality Assurance Engineer — B2B SaaS Platform
About the role
Role Overview
OBRYN GUARD® is seeking an experienced Senior Quality Assurance Engineer to lead quality assurance across our B2B SaaS platform. This role is responsible for ensuring the application is reliable, secure, accurate, scalable, and ready for enterprise customers. The Senior QA Engineer will establish testing processes, perform manual and automated testing, validate critical workflows, document defects, and work directly with engineering, product, security, and leadership. This is not a basic manual testing role. The ideal candidate must be capable of independently building a structured QA program, creating automated test coverage, identifying technical risks, and determining whether releases are ready for production.
Key Responsibilities
QA Strategy and Ownership
Develop and maintain the platform’s QA strategy, testing standards, release criteria, and quality controls. Build scalable QA processes for an expanding enterprise SaaS platform. Identify risks early and track test coverage, defects, regression results, and production issues. Approve, reject, or block releases based on documented risk.
Functional and End-to-End Testing
Perform functional, integration, regression, exploratory, system, and end-to-end testing. Validate complete user journeys from onboarding through reporting.
Test critical functionality, including
Authentication, account recovery, and multi-factor authentication. Organization, property, and multi-location structures. Role-based access control and user permissions. Risk assessments, control tracking, and compliance questionnaires. Evidence uploads, document management, and approval workflows. Staff training, vendor access, and third-party risk records. Incident logging, dashboards, calculations, notifications, and reporting. Administrative tools and report generation. Confirm functionality works across different users, organizations, locations, roles, and account configurations. Identify edge cases, calculation errors, workflow failures, and usability problems.
Test Automation
Design, build, and maintain automated UI, API, integration, and regression tests. Select and implement suitable automation tools and frameworks. Integrate automated testing into CI/CD pipelines. Prioritize automation for high-risk and business-critical workflows. Maintain reliable test scripts, data, environments, and documentation. Investigate unstable tests and improve product testability with engineers.
API and Integration Testing
Test APIs, authentication mechanisms, webhooks, data exchanges, and approved integrations. Validate requests, responses, permissions, data accuracy, error handling, and performance. Test token permissions, expiration, failures, and reconnection processes. Confirm synchronized data is collected and displayed accurately. Ensure integration failures do not cause unauthorized access, data corruption, or inaccurate reporting.
Security and Access-Control Testing
Test authentication, authorization, session management, permissions, and tenant separation. Verify users cannot access organizations, files, reports, or functions outside their assigned permissions. Test for privilege escalation, improper access controls, data exposure, unsafe uploads, and weak input validation. Reproduce reported vulnerabilities, verify remediation, and escalate critical defects. Support penetration-testing remediation when required.
Platform and Control Validation
Validate control statuses, evidence requirements, risk scores, calculations, and reporting logic. Test the difference between automatically monitored and manually assessed controls. Confirm requirements are not marked complete without sufficient evidence or validation. Test functionality supporting PCI DSS, SOC 2, ISO 27001, NIST, cyber insurance readiness, and other approved standards. Work with technical and compliance specialists to verify platform accuracy.
Regression and Release Testing
Build and maintain a structured regression testing program. Complete regression and acceptance testing before production releases. Define release criteria and provide documented release recommendations. Conduct smoke testing after deployments. Verify fixes and confirm changes have not created new defects. Support pilot deployments and enterprise customer rollouts.
Performance and Reliability
Test performance under realistic customer usage conditions. Identify slow pages, delayed API responses, bottlenecks, and unstable workflows. Support load, stress, scalability, and endurance testing. Test across supported browsers, devices, operating systems, and screen sizes. Validate platform behaviour during service interruptions, integration failures, and unexpected inputs.
Defect Management
Identify, reproduce, document, prioritize, and track software defects. Produce clear defect reports containing the issue, environment, reproduction steps, expected and actual results, evidence, severity, and business impact. Participate in defect triage, verify fixes, and perform targeted regression testing. Identify recurring defect patterns and recommend preventive improvements. Escalate release-blocking issues immediately.
Requirements and Collaboration
Review requirements, user stories, designs, technical specifications, and acceptance criteria. Identify missing requirements, unclear workflows, risks, dependencies, and edge cases. Work with engineering and product teams to create measurable acceptance criteria. Participate in sprint planning, technical discussions, and release reviews. Challenge incomplete, unstable, or high-risk functionality before deployment. Support user acceptance testing with internal stakeholders and pilot customers.
Documentation and Reporting
Maintain test plans, test cases, regression suites, automation documentation, release checklists, defect reports, QA procedures, and coverage reports. Report testing progress, unresolved risks, defect trends, and release readiness to leadership. Document known limitations, accepted risks, workarounds, and deferred issues. Maintain testing evidence for customer reviews, audits, and internal assessments.
Continuous Improvement
Evaluate QA and engineering practices and recommend practical improvements. Analyze production issues and convert them into permanent regression tests. Improve testing efficiency without creating unnecessary development delays. Help establish quality as a shared responsibility across the company. Mentor future QA team members as the department expands.
Qualifications
Significant experience in software quality assurance, quality engineering, or test automation. Experience testing B2B SaaS platforms, enterprise web applications, or complex multi-user systems. Strong knowledge of Agile development, release management, defect management, and QA methodologies. Experience creating test strategies, regression suites, automated UI and API tests, and release criteria. Experience testing APIs with Postman or equivalent tools. Understanding of frontend, backend, database, API, and cloud application architecture. Strong knowledge of authentication, authorization, permissions, tenant separation, and data integrity. Experience with defect tracking, documentation, version control, and project-management tools. Ability to communicate technical issues clearly to technical and non-technical stakeholders. Strong attention to detail, accountability, organization, and professional judgment. Ability to independently prioritize risk and own platform quality. Comfortable working in an early-stage company where systems are developing quickly.
Preferred Technical Experience
Playwright, Cypress, Selenium, WebdriverIO, or equivalent tools. Postman, Newman, REST Assured, pytest, or equivalent frameworks. JavaScript, TypeScript, Python, Java, or another relevant language. GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or equivalent platforms. SQL, Git, relational databases, and data-integrity testing. JMeter, k6, Locust, or similar performance-testing tools. Experience with multi-tenant SaaS, RBAC, cloud applications, logging, monitoring, accessibility, and cross-browser testing.
Preferred Industry Experience
Experience in B2B SaaS, governance, risk and compliance, audit technology, hospitality technology, or enterprise software. Familiarity with PCI DSS, SOC 2, ISO 27001, NIST, vendor risk, evidence management, or access control. Experience testing platforms that manage sensitive customer, business, financial, or compliance information. Experience supporting security reviews, audits, enterprise assessments, or penetration-testing remediation. Hospitality or multi-location business experience is an asset.
Ideal Candidate
The ideal candidate is methodical, technically capable, highly accountable, and unwilling to approve software simply because it works under normal conditions. They must think like an enterprise customer, test like a technical specialist, document like an auditor, and communicate like a business professional. They must be comfortable challenging assumptions and preventing unfinished or high-risk functionality from reaching production. The successful candidate will take ownership of product quality and help ensure OBRYN GUARD® becomes a reliable, scalable, and enterprise-ready B2B SaaS platform.
Compensation
Compensation and engagement terms will be discussed with qualified candidates based on experience, technical ability, availability, and expected responsibilities.
Thank you for your interest in OBRYN GUARD®
Sincerely, Leadership Team OBRYN GUARD INC.
Not the right fit? Search for Quality Assurance Engineer jobs in Toronto, Ontario, Canada
About OBRYN GUARD
OBRYN GUARD™ helps hospitality ownership groups and operators strengthen cyber risk, compliance, and audit readiness.
Built for hotel environments, we support leadership teams with cyber risk assessments, control gap analysis, vendor risk visibility, policy documentation, executive reporting, and readiness support for PCI DSS, SOC 2, ISO 27001, NIST CSF, HIPAA, and cyber insurance requirements.
Our focus is simple: help hospitality organizations move beyond checkbox compliance toward measurable risk reduction, stronger operational control, and defensible security maturity.