Mid-Level Quality Assurance Specialist
RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.
That’s RIVA.
We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.
POSITION OVERVIEW
This role develops and executes quality control methodologies to ensure that all deliverables, Wiz DSPM platform configurations, GitLab CI/CD pipeline gate outputs, and ServiceNow remediation workflows meet or exceed USPTO requirements and applicable federal standards. The QA Specialist is a cross-cutting resource supporting all three Agile teams equally—no team is more deserving of QA than another—and integrates QA practices directly into the two-week sprint cadence.
CORE RESPONSIBILITIES
- Develop and maintain the Quality Management Plan covering all three Agile teams and all five program objectives; define acceptance criteria for each program deliverable that align with CPARS evaluation dimensions: responsiveness, technical quality, schedule adherence, and customer satisfaction
- Validate Wiz Federal DSPM platform configurations against the Enterprise Architecture and Deployment Plan and Discovery and Classification Configuration: verify scanner connector coverage, confirm classification rule precision and recall measurements, and document configuration baselines prior to COR submission
- Test GitLab CI/CD pipeline security gates end-to-end in the AWS Lab sandbox environment: confirm Wiz Code container scanning, Snyk Agent Scan AI artifact analysis, and IaC policy checks produce expected findings and route to the correct ServiceNow SMP queue with appropriate severity tags
- Validate ServiceNow SMP remediation workflow configurations: confirm correct routing of DSPM, CASB, SIEM, and pipeline findings to the right queue tier, verify SLA timer behavior, and test exception register workflows including approver, justification, and expiration-date fields
- Review and validate Kubernetes admission control gate configurations and runtime scanning alert thresholds in coordination with Security Engineers; confirm findings from the approximately 4,000-container estate route correctly through the remediation workflow
- Verify that AWS CloudWatch dashboard metrics and AWS S3 reporting outputs map to the published metric definitions fixed in the Reporting and Dashboard Package; confirm every dashboard number resolves to a defined policy version and detection evidence source (XSIAM, QRadar, or Wiz)
- Coordinate with the Senior Technical Writer on all documentation deliverables: review for technical accuracy, completeness, formatting consistency, and alignment with the approved content-class taxonomy before each submission to the COR
- Track defects, configuration discrepancies, and corrective actions in a structured defect log; escalate quality risks to the Project Manager and reflect findings in the monthly COR review re-baselining process
- Participate in Agile sprint ceremonies; integrate QA into sprint review definition-of-done checklists and retrospective improvement cycles across all three Agile teams
MINIMUM QUALIFICATIONS
- Bachelor's degree and 5 years of relevant experience, or Master's degree and 3 years of relevant experience in quality assurance, software engineering, information technology, or a related field
- Experience developing and implementing quality management plans and QA/QC methodologies for complex federal IT programs; familiarity with FAR deliverable quality standards and CPARS evaluation criteria
- Demonstrated ability to define quality metrics, scoring parameters, and acceptance criteria for both technical platform configurations and written deliverables in a government program context
- Experience testing CI/CD pipeline security gates, cloud platform configurations, or ITSM workflow logic in a structured test environment (AWS Lab sandbox or equivalent)
- Ability to trace dashboard metrics or reporting outputs back to source evidence; comfort working with AWS CloudWatch, AWS S3-backed reports, or SIEM telemetry outputs for validation purposes
- Strong written and verbal communication skills; ability to clearly document QA findings, defect logs, and corrective actions for both technical leads and program management
- Hands-on test tooling proficiency: structured test case management, API testing tools (Postman or equivalent) for validating integration endpoints, basic scripting or query skills (Python, SQL, or advanced spreadsheet analysis) for validating findings data, and GitLab issues/boards for defect tracking
PREFERRED QUALIFICATIONS
- Prior QA experience on a federal cybersecurity, DSPM, data governance, or DevSecOps program; familiarity with Wiz, GitLab, ServiceNow, or Netskope platform testing
- Experience validating Kubernetes container security configurations or cloud-native security tool outputs in a multi-cloud environment
- Familiarity with Agile QA practices including acceptance test-driven development (ATDD), behavior-driven development (BDD), and definition-of-done checklists within two-week sprints
- Certifications such as CSTE, ISTQB, ASQ Certified Quality Engineer (CQE), or AWS Certified Cloud Practitioner
- Experience working in or validating outputs from a GitLab-based DevSecOps software factory
- Experience with automated test frameworks or CI-integrated test stages in GitLab, and with validating role-based access behavior (Okta SSO/MFA) in enterprise security applications
Pay range
$95,000 - $120,000 USD
EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION
We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords.
RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.
If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.
VETERAN SUPPORT & ACCESSIBILITY
As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self-identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.
RIVA also invites applicants to voluntarily self-identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.
Apply for this job
*
indicates a required field