QA Cyber
ASM Research San Antonio, Texas, United States
IT Services and IT Consulting · 1,001-5,000 employees
About the role
The QA Cyber evaluates the quality, accuracy, and defensibility of app review decisions by auditing cases against established standards. They identify quality trends, provide reviewer feedback, and collaborate with operations teams to improve review consistency and policy interpretation.
What they look for
Requirements
Candidates must possess strong analytical judgment, policy fluency, and the ability to assess technical evidence for app reviews. A background in trust and safety, quality assurance, or compliance operations is preferred, along with excellent written communication skills.
Full description
The QA Cyber evaluates the quality, accuracy, consistency, and defensibility of app review decisions. While App Review reviewers assess submitted applications for functionality, policy compliance, privacy, safety, and platform requirements, the QA Analyst evaluates the quality of those reviews — ensuring reviewers apply the correct policies and review criteria, perform sufficient testing or evidence review, document their findings clearly, and reach decisions supported by the facts of the case. The QA Analyst maintains a high and consistent review standard by identifying reviewer errors, missed risks, unsupported decisions, documentation gaps, policy interpretation issues, and recurring quality trends, and requires strong analytical judgment, policy fluency, attention to detail, technical curiosity, and the ability to distinguish reviewer error from ambiguity in policy, process, tooling, or available evidence.
Key Responsibilities
Review Quality Audits
- Audit completed app review cases against established QA standards and scoring rubrics.
- Assess whether the reviewer selected and applied the correct review checks, policies, and escalation paths.
- Determine whether the reviewer's final decision was accurate, complete, and supported by available evidence.
- Classify quality issues by severity, including decision-impacting errors, process errors, documentation gaps, and coaching opportunities.
- Identify both under-enforcement (missed policy or safety issues) and over-enforcement (unsupported rejections or unnecessary escalations).
Case and Evidence Assessment
- Review submitted app metadata, developer-provided materials, reviewer notes, screenshots, testing evidence, tool information, policies, privacy disclosures, and relevant case context.
- Determine whether the reviewer gathered and documented enough evidence to support their conclusions.
- Identify missing, contradictory, irrelevant, or insufficient evidence.
- Evaluate whether another reviewer could reasonably understand and reproduce the original decision based on the documented record.
- Perform targeted validation where required by the QA workflow, without assuming every case requires a full second review.
Policy and Risk Evaluation
- Validate whether reviewers correctly interpreted and applied app review policies and platform requirements.
- Assess reviewer handling of privacy, data access, user safety, regulated or high-impact domains, impersonation, misrepresentation, third-party access, and other trust-related risks.
- Ensure reviewers evaluate the app's actual functionality and submitted evidence rather than relying on unsupported assumptions or hypothetical misuse.
- Identify cases where ambiguity should have led to escalation rather than approval or rejection.
- Surface unclear policy guidance or recurring interpretation gaps.
Functional and Technical Review Quality
- Evaluate whether reviewers sufficiently assessed the app's core workflows, tool behavior, authentication requirements, MCP server connectivity, OAuth flows, test account access, and developer-provided testing instructions.
- Determine whether technical blockers were reasonably investigated before being treated as review-limiting.
- Identify cases where an app was approved despite meaningful technical failures or incomplete testing.
- Distinguish between true app issues, reviewer execution errors, incomplete submission materials, and tooling limitations.
Reviewer Feedback and Calibration
- Support internal and client-facing calibration sessions to align on review standards, QA scoring, defect severity, and policy interpretation.
- Present QA findings, trends, and examples clearly to client stakeholders during calibration discussions.
- Explain the rationale behind QA decisions in a balanced, evidence-based way, including where cases involve ambiguity or reasonable judgment.
- Capture client feedback, alignment decisions, and follow-up actions from calibration sessions and incorporate them into QA guidance or reviewer coaching where appropriate.
Quality Insights and Process Improvement
- Track recurring review errors, quality trends, and high-risk issue areas.
- Identify reviewer knowledge gaps, training needs, unclear guidance, tooling limitations, and process breakdowns.
- Produce QA summaries, defect analyses, calibration notes, and recommendations for operational improvement.
- Partner with App Review Operations and Training teams to improve review quality and consistency over time.
Required Qualifications
- Strong analytical judgment — able to reconstruct the logic of a review and determine what the app does, what should have been evaluated, which policies apply, what evidence matters, and whether the reviewer's conclusion was justified.
- Policy fluency — able to apply app review policies and platform requirements consistently across varied app types, workflows, metadata, tools, permissions, and user-facing claims, and to recognize edge cases, exceptions, and appropriate escalation paths.
- Evidence discipline — able to ground findings in the case record without unsupported assumptions or speculative risk claims.
- Working knowledge of QA rubric application, distinguishing critical, major, minor, process, documentation, and coaching-only defects.
- Technical aptitude with web applications, APIs, integrations, MCP servers, OAuth, authentication, and test credentials sufficient to assess whether technical testing was reasonable and sufficient (software engineering background not required).
- Ability to identify missed or mishandled risks involving privacy, safety, compliance, deception, sensitive data, regulated activities, user trust, and ecosystem integrity.
- Strong written communication skills — able to produce concise, objective, actionable QA feedback that cites evidence, maps to policy/rubric, classifies severity, and explains outcome impact.
- Calibration and consistency skills — able to recognize inconsistent treatment of similar cases and help align reviewers/QA peers around shared standards.
- Root-cause thinking — able to look beyond individual errors to identify training gaps, unclear guidance, process ambiguity, tooling limitations, or emerging app behaviors.
- Sound judgment and discretion handling confidential app submissions, test credentials, internal review guidance, reviewer performance data, and sensitive case evidence.
Preferred Qualifications
- Prior experience in app review or marketplace review.
- Background in trust and safety quality assurance, policy operations, or content moderation QA.
- Experience in risk, compliance, or integrity operations.
- Software testing or technical QA experience.
- Technical support quality experience.
- Privacy or data-handling review experience.
- Operational excellence or quality auditing background.
Job-Specific Skills
- Review quality auditing against rubrics/scoring standards.
- Case and evidence sufficiency assessment.
- App review policy interpretation and risk evaluation (privacy, safety, trust/integrity).
- Functional/technical review assessment (APIs, OAuth, MCP servers, authentication, test credentials).
- Defect classification and severity scoring.
- Calibration facilitation (internal and client-facing).
- QA reporting, trend analysis, and defect documentation.
- Root-cause and process-improvement analysis.
- Confidential case-data handling and access discipline.
Success Profile
A successful App Review QA Analyst improves reviewer accuracy and consistency without creating unnecessary friction — catching material mistakes, recognizing fair judgment calls, explaining quality issues clearly, and helping the review organization learn from patterns over time. They are rigorous without being punitive, skeptical without being speculative, and focused on making app review decisions more accurate, defensible, and trustworthy.
Qualifications
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Similar roles
-
QA Analyst (F/M/NB) [AAA Project]
Ubisoft Annecy, Auvergne-Rhône-Alpes, France
-
QA Automation Fullstack Expérimenté
SQLI Rabat, Rabat-Salé-Kénitra, Morocco
-
QA SQF Practitioner
SSS Of Parma Independence, Ohio, United States
-
Senior QA Lead - Data Engineering & Analytics Testing - Retail domain is mandatory
Syncreon Consulting Boston, Massachusetts, United States
-
Manual QA Engineer (with mobile testing experience)
Synergetica Warsaw, Masovian Voivodeship, Poland
-
QA Receiving Inspector I
Toray Advanced Composites USA,Inc Fairfield, California, United States · $44K–$69K/yr