Automated Testing & Quality Engineering for Laravel Vapor (Multi-Tenant SaaS CRM) -- 2

Job ID: 40096259

Budget: $250 – $750 AUD

We are seeking a skilled QA and automation specialist to design and integrate a robust, CI-gated automated testing suite for our multi-tenant legal SaaS CRM, Lemarex. The goal is to validate tenant experiences and enforce quality/security thresholds across environments (dev → qa → stg → prod). This project requires expertise in Laravel Vapor, GitHub Actions (OIDC), and modern testing tools.

---

### Scope of Work:
1. Unit & Feature Tests:
- Achieve/maintain ≥80% coverage using PHPUnit.
- Cover key flows like authentication, tenancy scoping, billing webhooks, file uploads.

2. Static Analysis:
- Configure Larastan/Psalm to fail on errors; run before deploy steps.

3. Browser/E2E Tests:
- Preferred tools: Ghost Inspector or Testim (low-code). Alternatives like Cypress/Playwright acceptable with justification.
- Execute post-deploy on qa/stg environments only (not prod).

4. Security & Supply Chain:
- Enable Dependabot and Trivy scans with fail-on High/Critical thresholds.

5. Performance Testing:
- Use k6 or Artillery against staging with threshold assertions (p95 latency, error rate).

6. CI Integration:
- Integrate tests into GitHub Actions pipelines with OIDC role assumption.
- Ensure failures block promotions; publish artifacts like screenshots/videos.

7. Documentation & Handover:
- Provide Markdown-based guides covering QA strategy, CI workflows, test data setup, and artifact locations.

---

### Key Deliverables:
- Automated testing suite integrated into CI/CD pipelines with gating mechanisms.
- ≥80% unit/feature test coverage with artifacts published.
- Browser/E2E tests running post-deploy on qa/stg environments.
- Security scans (Dependabot + Trivy) and performance tests with clear pass/fail criteria.
- Comprehensive documentation for local setup, CI workflows, and test data management.

---

### Ideal Freelancer:
The ideal candidate should have:
- Proven experience in delivering CI-gated automated testing suites for Laravel Vapor or similar stacks.
- Expertise in tools like Ghost Inspector/Testim, k6/Artillery, or alternatives like Cypress/Playwright.
- Strong understanding of tenant-aware testing strategies and secure credential handling.

---

### Budget & Timeline:
Propose your plan for completing this project within 1 week or less. Payments will be milestone-based upon acceptance of deliverables.

---

### Milestones:
1. Unit/Feature Baseline & Static Analysis (≥80% coverage; Larastan/Psalm configured).
2. E2E Tests on QA/STG Environments (artifacts uploaded; flaky-test policy documented).
3. Security & Performance Testing (Dependabot + Trivy thresholds; k6/Artillery assertions).
4. Documentation & Handover (QA strategy, CI guides, artifact locations).

---

### Proposal Requirements:
Please include the following in your proposal:
1. Examples of similar CI-gated suites you’ve delivered (preferably using Ghost Inspector/Testim; k6/Artillery a plus).
2. Your approach to achieving ≥80% coverage while maintaining stability in tests.
3. Tool choices (preferred or alternatives) with reasoning based on speed-to-value and cost-effectiveness.
4. Confirmation of compliance with AWS Secrets Manager usage and OIDC role assumption.

Optional add-ons are welcome if they bring additional value (e.g., BrowserStack grid, visual diffs, chaos drills).

# Skills Required

## Must-have (technical)

* **Laravel/PHP testing:** PHPUnit (or Pest), test doubles/factories/seeders, coverage gating (≥80%), failure triage.
* **Static analysis:** Larastan (preferred) or Psalm configuration, baseline management, fail-on-error in CI.
* **CI/CD (GitHub Actions):** authoring workflows, job matrices, artifact uploads, environment promotions, **OIDC role assumption** (no long-lived keys).
* **AWS basics for testing:** Laravel Vapor deploy flow, using **AWS Secrets Manager** from CI, reading CloudWatch logs/metrics in non-prod.
* **Browser/E2E automation (pick at least one):**

* **Ghost Inspector** (preferred) — suite design, env/tenant parameters, API trigger + status polling.
* **Testim (Tricentis)** (preferred) — AI/self-healing locators, low-code flows, API integration with CI gates.
* **Katalon Studio/Platform** — web + API (and mobile if needed), data-driven tests, CI execution/runtime engine.
* **Cypress/Playwright** — selectors, fixtures, screenshots/videos, flake control (if proposing code-based).
* **Cross-browser execution:** **BrowserStack Automate** setup (credentials hygiene, parallels, artifacts).
* **API testing:** Postman collections (or Katalon API module), env/tenant paramization, CI runs.
* **Security & supply chain:** Dependabot policies, **Trivy** FS/SCA scans, allowlist hygiene with expiries.
* **Performance testing:** **k6** (preferred) or Artillery scripts, p95 latency/error-rate thresholds on `stg`, CI pass/fail wiring.
* **Multi-tenant testing:** isolated test tenants per env, data masking, guarding against cross-tenant access.

## Nice-to-have

* **Visual regression:** Percy (BrowserStack) or vendor visual checks.
* **Feature flags in tests:** Laravel **Pennant** to route risky paths safely.
* **Chaos experiments (non-prod):** AWS **FIS** templates (latency injection, DB failover) with rollback.
* **SBOM & dependency health:** Syft/Grype (or similar) familiarity.
* **Test data pipelines:** anonymization/masking jobs; seeded golden datasets.

## Quality & robustness

* Flake mitigation: deterministic seeds, idempotent setup/teardown, stable selectors, retries/timeouts policy.
* Test architecture: layering (unit/feature/API/E2E), tagging/smoke suites, parallel strategy, artifact retention.

## Security & compliance

* **Least privilege** IAM; never storing secrets in Git/CI/vapor.yml; handling of PII in non-prod; auditability of test actions.
* Region discipline (**ap-southeast-2**), adherence to internal **SOP v7** and promotion gates.

## Documentation & comms

* Clear **QA strategy**, **local run guides**, **CI gating docs**, and **test data** playbooks (fixtures, masking).
* Async status updates, risk/issue logs, and crisp handover notes.

## Bonus (domain)

* Experience testing **legal/financial workflows** (trust accounting, reconciliation, billing webhooks).
* Observability for QA: linking test failures to logs/metrics (CloudWatch), creating actionable defect reports.

> Availability during **AEST** hours for handover/questions is appreciated.