About This Role
<div><h1><b>Key Responsibilities</b></h1></div><h2><b>Quality Strategy & Leadership</b></h2><ul><li>Own the end-to-end quality strategy for PrognoCIS, aligning test coverage, release gates, and quality metrics with R&D and product roadmaps.</li><li>Build and lead a multi-disciplinary QA organization spanning functional, automation, performance, security, and AI-testing specialists.</li><li>Define and report quality KPIs (defect escape rate, test coverage, MTTR, automation ROI) to R&D and executive stakeholders.</li><li>Partner with Engineering, Product Management, and Technical Documentation to embed quality practices earlier in the SDLC (shift-left testing).</li><li>Drive a culture of quality ownership across the R&D organization, not just within the QA team.</li></ul><h2><b>Test Automation</b></h2><ul><li>Architect scalable, maintainable automation frameworks across UI, API, and integration layers (e.g., <b>Selenium</b>, <b>Playwright</b>, <b>Cypress</b>, <b>REST Assured</b>).</li><li>Establish automation-first standards for new feature development, targeting high regression-suite coverage with low flake rates.</li><li>Integrate automated test suites into CI/CD pipelines for continuous testing and fast feedback loops.</li><li>Evaluate and adopt self-healing test frameworks and AI-assisted test generation to reduce automation maintenance overhead.</li><li>Define coding standards, code review practices, and reusable component libraries for the automation codebase.</li></ul><h2><b>Performance Testing</b></h2><ul><li>Own performance, load, and stress testing strategy for a high-volume, multi-tenant healthcare platform (e.g., <b>JMeter</b>, <b>k6</b>, <b>Gatling</b>).</li><li>Establish performance baselines and SLAs for key clinical workflows (charting, scheduling, billing, order management) and validate against them each release.</li><li>Lead capacity planning and scalability testing in coordination with Engineering and Cloud/Infrastructure teams (AWS).</li><li>Institute production-like performance monitoring and proactively identify degradation trends before they impact clinics.</li></ul><h2><b>Security Testing</b></h2><ul><li>Embed security testing into the release lifecycle, covering OWASP Top 10 risks, authentication/authorization flows, and data-handling paths.</li><li>Coordinate vulnerability scanning, penetration testing (internal or third-party), and remediation tracking.</li><li>Ensure test coverage for HIPAA-relevant controls — access logging, PHI handling, encryption in transit/at rest — in partnership with Compliance and Engineering.</li><li>Maintain a security regression suite that runs continuously against the CI/CD pipeline, not just before major releases.</li></ul><h2><b>AI-Augmented & Emerging Test Practices</b></h2><ul><li>Evaluate and pilot AI-based test generation, exploratory test assistance, and defect-prediction tooling to increase QA velocity and coverage.</li><li>Apply AI-assisted approaches to test-case design for clinical decision-support and AI-driven product features (e.g., PrognoAI / AI Encounter Studio).</li><li>Establish testing methodology specific to AI/LLM-driven features — output validation, bias and edge-case testing, prompt-injection and adversarial-input testing, and model-drift monitoring in production.</li><li>Stay current on the evolving AI-testing tool landscape and bring in a lightweight evaluation-and-adopt process rather than one-off tool purchases.</li></ul><h2><b>Compliance & Healthcare Domain</b></h2><ul><li>Ensure QA processes support HIPAA, SOC 2, and relevant regulatory audit requirements, including audit-ready test documentation and traceability.</li><li>Maintain test traceability from requirements through to release for regulated clinical and billing workflows.</li><li>Partner with Technical Documentation and Compliance functions on release notes, validation evidence, and audit responses.</li></ul>