Senior Manager - QA
Summary
Lead the end-to-end QA strategy for PrognoCIS, a multi-tenant healthcare EHR platform, managing teams across functional, automation, performance, and security testing using tools like Selenium, Playwright, JMeter, and AWS.
Key Responsibilities
Quality Strategy & Leadership
- Own the end-to-end quality strategy for PrognoCIS, aligning test coverage, release gates, and quality metrics with R&D and product roadmaps.
- Build and lead a multi-disciplinary QA organization spanning functional, automation, performance, security, and AI-testing specialists.
- Define and report quality KPIs (defect escape rate, test coverage, MTTR, automation ROI) to R&D and executive stakeholders.
- Partner with Engineering, Product Management, and Technical Documentation to embed quality practices earlier in the SDLC (shift-left testing).
- Drive a culture of quality ownership across the R&D organization, not just within the QA team.
Test Automation
- Architect scalable, maintainable automation frameworks across UI, API, and integration layers (e.g., Selenium, Playwright, Cypress, REST Assured).
- Establish automation-first standards for new feature development, targeting high regression-suite coverage with low flake rates.
- Integrate automated test suites into CI/CD pipelines for continuous testing and fast feedback loops.
- Evaluate and adopt self-healing test frameworks and AI-assisted test generation to reduce automation maintenance overhead.
- Define coding standards, code review practices, and reusable component libraries for the automation codebase.
Performance Testing
- Own performance, load, and stress testing strategy for a high-volume, multi-tenant healthcare platform (e.g., JMeter, k6, Gatling).
- Establish performance baselines and SLAs for key clinical workflows (charting, scheduling, billing, order management) and validate against them each release.
- Lead capacity planning and scalability testing in coordination with Engineering and Cloud/Infrastructure teams (AWS).
- Institute production-like performance monitoring and proactively identify degradation trends before they impact clinics.
Security Testing
- Embed security testing into the release lifecycle, covering OWASP Top 10 risks, authentication/authorization flows, and data-handling paths.
- Coordinate vulnerability scanning, penetration testing (internal or third-party), and remediation tracking.
- Ensure test coverage for HIPAA-relevant controls — access logging, PHI handling, encryption in transit/at rest — in partnership with Compliance and Engineering.
- Maintain a security regression suite that runs continuously against the CI/CD pipeline, not just before major releases.
AI-Augmented & Emerging Test Practices
- Evaluate and pilot AI-based test generation, exploratory test assistance, and defect-prediction tooling to increase QA velocity and coverage.
- Apply AI-assisted approaches to test-case design for clinical decision-support and AI-driven product features (e.g., PrognoAI / AI Encounter Studio).
- Establish testing methodology specific to AI/LLM-driven features — output validation, bias and edge-case testing, prompt-injection and adversarial-input testing, and model-drift monitoring in production.
- Stay current on the evolving AI-testing tool landscape and bring in a lightweight evaluation-and-adopt process rather than one-off tool purchases.
Compliance & Healthcare Domain
- Ensure QA processes support HIPAA, SOC 2, and relevant regulatory audit requirements, including audit-ready test documentation and traceability.
- Maintain test traceability from requirements through to release for regulated clinical and billing workflows.
- Partner with Technical Documentation and Compliance functions on release notes, validation evidence, and audit responses.