Paysign is seeking a QA Engineer to own the quality of our payment processing and healthcare platform releases through a combination of manual testing and test automation. This role builds and executes test plans across web, mobile, API, and data/back-end layers, integrates automated checks into CI/CD pipelines, and partners with developers, data engineers, and product stakeholders to catch defects before they reach production. The position operates within a Cardholder Data Environment (CDE) subject to PCI-DSS requirements, so test data handling, environment segregation, and audit-evidence practices are integral to the role.
Key Responsibility Areas
Test Planning & Manual QA
- Analyze requirements, user stories, and acceptance criteria to design comprehensive test plans, test cases, and test data
- Execute manual functional, regression, exploratory, and UAT-support testing across web, mobile, and back-end systems
- Validate business logic for payment, cardholder, and copay/healthcare workflows including edge cases and negative scenarios
- Verify fixes and perform root-cause-aware retesting; maintain traceability between requirements, tests, and defects
Test Automation (API / UI / Regression)
- Build and maintain automated test suites for APIs (REST) and UI using frameworks such as Playwright, Cypress, Selenium, Postman/Newman, or equivalent
- Grow and maintain a reliable regression suite, keeping tests deterministic, well-factored, and low-maintenance
- Implement data-driven and contract tests that validate request/response schemas between services
- Manage test data setup/teardown and environment configuration for repeatable automated runs
Data & Back-End Testing
- Write SQL to validate data correctness across MariaDB/MySQL and analytics sources (Redshift/Athena), including reconciliation and transformation checks
- Test ETL/ELT pipeline outputs, file loaders, and batch jobs for completeness, accuracy, and idempotency
- Validate reports and dashboards (e.g., Tableau) against source-of-truth data
Release Testing & CI/CD Integration
- Integrate automated tests into GitLab CI/CD pipelines and gate deployments on test results
- Perform smoke and sanity testing across environments (dev, test, stage, prod) as part of release promotion
- Coordinate release/regression cycles with developers and DevOps, and support rollback verification
Compliance & CDE Testing
- Ensure test data in non-production environments contains no real cardholder or PHI data; use masked, tokenized, or synthetic data per PCI-DSS and CDE rules
- Support security, penetration, and access-control testing efforts and capture audit evidence for PCI-DSS and SOC 2
- Follow CDE change-management and separation-of-duties controls in all testing and sign-off activities
- Log, prioritize, and track defects in Jira with clear reproduction steps, severity, and expected vs. actual results
- Report test coverage, pass/fail trends, and release-readiness status to engineering and stakeholders
- Contribute to continuous improvement of QA processes, standards, and test documentation
Required Qualifications
- 3+ years of experience in software quality assurance (manual and automation)
- Hands-on experience building automated tests for APIs and/or UI (Playwright, Cypress, Selenium, Postman/Newman, or equivalent)
- Experience testing REST APIs and web/mobile applications
- Solid understanding of the SDLC, test methodologies, and defect lifecycle
- Experience integrating automated tests into CI/CD pipelines (GitLab CI preferred)
- Proficiency with a defect/test management tool (Jira or equivalent)
- Strong analytical skills and attention to detail with clear written communication
Preferred Qualifications
- ISTQB or similar QA certification
- Experience testing in PCI-DSS Cardholder Data Environments (CDE) or other regulated industries
- Experience testing data pipelines, ETL/ELT, or BI/reporting outputs (e.g., Tableau)
- Experience with performance/load testing (JMeter, k6, or equivalent)
- Familiarity with AWS services (ECS, Lambda, S3, RDS)
- Experience in fintech, payment processing, or healthcare software
- Knowledge of SOC 2 controls and audit evidence practices