What you’ll do
We build platforms for government and enterprise operations, where a regression is not an inconvenience but a public failure. You will own the automated coverage that keeps those platforms honest: end-to-end, API, performance and accessibility tests that run on every change and are trusted enough to gate a release.
Test automation:
- Build and maintain end-to-end suites for web applications with Playwright or Cypress, covering the critical journeys across browsers and mobile viewports.
- Write API and integration tests against REST services: contracts, authentication, error paths and the edge cases nobody demos.
- Extend unit and component coverage alongside developers rather than after them.
- Keep suites fast and deterministic — isolate state, control test data, and hunt flakiness instead of retrying it away.
In the pipeline:
- Run every suite in CI, on GitHub Actions or Azure DevOps: on pull requests, before release, and as smoke tests after deployment.
- Make failures legible — traces, screenshots, videos and reports a developer can act on without reproducing locally.
- Gate releases on quality signals, and keep the gate trustworthy enough that nobody wants to bypass it.
- Manage test environments and data with Docker and disposable databases.
Beyond the happy path:
- Performance and load testing with k6, JMeter or Locust against APIs and critical journeys; set baselines and catch regressions before users do.
- Accessibility testing against WCAG 2.2 AA — a requirement in public-sector work, not a nicety.
- Security-adjacent checks in the pipeline: dependency and image scanning, authentication and authorisation test cases.
- Testing AI features whose output is not deterministic: evaluation sets, retrieval quality checks, and regression harnesses for prompts and RAG pipelines.
Quality as a practice:
- Own the test strategy: what gets automated, what stays exploratory, and where the risk actually sits.
- Write reproducible bug reports and follow them to resolution.
- Join design and code review early, while a testing problem is still a design problem.
- Document how to run, extend and debug the suites so they outlive you.
We look for
Required:
- Three years or more in test automation, QA engineering or SDET work.
- Strong programming in at least one of Python, TypeScript/JavaScript, Java or C# — you write code, not recordings.
- Hands-on with a modern browser automation framework: Playwright, Cypress or Selenium.
- API testing: REST, authentication flows, and either Postman/Newman or code-driven equivalents.
- Suites running in CI/CD — GitHub Actions, Azure DevOps, GitLab CI or Jenkins.
- Solid testing fundamentals: test design, boundary and negative cases, risk-based prioritisation, the test pyramid.
- SQL, and the instinct to verify what actually landed in the database.
- Git and code review as daily habits.
- A particular stubbornness about flaky tests — you isolate the cause rather than adding a retry.
- Good communication in English; Arabic is an advantage.
Nice to have:
- Docker and Kubernetes-based test environments.
- Performance testing with k6, JMeter or Locust.
- Accessibility testing and WCAG experience.
- Contract testing with Pact, or mocking and service virtualisation (WireMock, MSW).
- Evaluating LLM or RAG systems: golden sets, retrieval metrics, output evaluation.
- Mobile testing with Appium, or visual regression tooling.
- Security testing basics: OWASP Top 10, ZAP, dependency scanning.
- ISTQB certification.
- Government, banking or other regulated environments.