RegScale is a continuous controls monitoring platform that helps organizations automate and scale their security, risk, and compliance programs. The Senior Software Quality Engineer will develop and own quality strategies for features and releases, partner with developers from the start of each sprint, and ensure quality is built in from the beginning of the development process.
Responsibilities:
- Develop and own quality strategies for features and releases, determining the appropriate mix of manual testing, automated testing, and developer contributed testing based on risk, complexity, and customer impact
- Embed within scrum teams and partner with developers from the start of each sprint, contributing to requirement reviews, design discussions, and testability decisions before a line of code is written
- Work with developers to ensure they are contributing meaningfully to unit and integration test coverage, providing guidance, review, and coaching on testing practices
- Build, maintain, and extend automated test coverage across API, UI, and integration layers using sound engineering practices. Treat automation as a product that requires design, maintainability, and ongoing investment
- Identify and prioritize testing based on real world GRC workflows and customer usage patterns, ensuring test coverage reflects how customers use the platform, rather than how it is implemented
- Proactively identify quality risks early in the development cycle, bring proposed mitigation strategies, and escalate concerns with sufficient lead time for the team to act
- Contribute to CI/CD quality gates, ensuring automated tests run reliably on every build and provide meaningful, actionable signal rather than noise
- Analyze failures, escapes, and production defects to identify root causes and recommend systemic improvements that reduce recurrence across the team
- Collaborate with Customer Enablement to incorporate real customer scenarios, edge cases, and support patterns into test coverage
- Contribute to quality visibility by tracking and communicating test coverage, pass rates, escape rates, and trends in a way that informs engineering decisions
Requirements:
- 8 or more years of quality engineering experience with a demonstrated track record of owning quality outcomes across the full development lifecycle, not just test execution
- Strong problem-solving skills and the ability to develop quality strategies that determine the right approach for a given feature, release, or risk profile
- Proven experience partnering with developers in an embedded or shift left model, influencing how teams write code rather than only testing after the fact
- Solid automation engineering skills including API testing, UI automation, and integration testing, with the judgment to know when automation adds value and when it does not
- Experience contributing to or owning CI/CD quality integration, including test reliability, pipeline health, and actionable test reporting
- Ability to analyze defect patterns, escapes, and production issues and translate findings into systemic recommendations rather than one off fixes
- Strong written and verbal communication skills, able to articulate quality risk and testing strategy clearly to both engineering peers and non-technical stakeholders
- Experience in regulated industries or with compliance, security, or risk management platforms. GRC, FedRAMP, or NIST familiarity is a meaningful advantage given the depth of domain knowledge required to test effectively in this space
- Background in enterprise SaaS companies where quality strategy had to account for enterprise scale, multi-tenant complexity, and high stakes customer environments
- Experience with performance and load testing, particularly validating system behavior under enterprise scale conditions
- Familiarity with security testing practices and secure software development in a compliance focused product context
- Experience building or improving quality visibility through dashboards, metrics, and reporting that drive engineering decisions rather than just satisfy reporting requirements