All Jobs Vacancy

AdTech Privacy QA Engineer/Test Analyst (Consent & Device Testing)

Posted Today by Staffworx Limited

About the Role

This is a hands-on testing role. We need an AdTech Privacy Test Analyst to test cookies and equivalent marketing and tracking technologies in consumer apps and confirm that customer consent preferences are respected.

Focus will be on intercepting network calls of apps, connected devices and Internet of Things and auditing HTTP Archive (HAR) logs, using Proxyman, Charles Proxy and Fiddler as the main tools.

The role has two parts:

  • Define a repeatable self-testing process so delivery teams can evidence their own consent testing.
  • Provide second line assurance by reviewing their HAR evidence and independently verifying results where technically possible.

Who We Are Looking For

Strong AdTech and MarTech knowledge combined with practical app and device testing. You do not need to be a formal QA engineer, but you do need a tester's discipline: structured test cases, clear evidence and repeatable results.

Key Responsibilities: Consent Testing

  • Test that consent choices are honoured before, during and after user interaction, including withdrawal of consent.
  • Test cookies, SDKs, pixels and equivalent tracking technologies across iOS and Android apps, then connected devices and IoT products.
  • Work from published app store builds where possible, and from test builds where deeper inspection is needed.

Traffic Interception & Evidence

Intercept and inspect network traffic using Proxyman, Charles Proxy and Fiddler, with Burp Suite as required.

  • Capture and audit HAR logs to identify tracking calls, identifiers, payloads and third-party endpoints.
  • Use Android Logcat and Xcode Console to gather supporting evidence where HAR files are incomplete or certificate pinning limits visibility.
  • Inspect SDKs and app packages with MobSF and APK Analyzer to identify undeclared or non-compliant tracking.
  • Agree test builds with engineering where HTTPS inspection needs certificate pinning disabled or the Proxy trusted.

Self-Testing Process & Second Line Assurance

Define and document a repeatable end-to-end self-testing process for app teams, including how to produce usable HAR evidence.

  • Coach teams on how to test for themselves.
  • Review HAR logs supplied by teams, including analysis in ObservePoint, and challenge gaps or inconsistencies.
  • Run independent verification of team results and report where evidence does not support a pass.

Reporting & Collaboration: Document findings with evidence, risk rating and recommended remediation.

  • Maintain tracker inventories, vendor and SDK registers and test records.
  • Present results to engineering, Product, Legal, privacy and delivery stakeholders in plain language.
  • Re-test releases, SDK updates and vendor changes to catch regressions.

Essential Experience

Strong, proven experience in AdTech or MarTech environments, including tagging, tracking, consent and analytics.

  • Hands-on testing of mobile apps and devices (iOS, Android, and connected or IoT devices).
  • Hands-on network interception using Proxyman, Charles Proxy and Fiddler.
  • Confident capturing, reading and auditing HAR files and tracking payloads.
  • Experience working around certificate pinning and HTTPS inspection constraints.
  • Working knowledge of CMPs, TCF, cookies and mobile identifiers (IDFA/GAID).
  • Sound understanding of GDPR, PECR, ePrivacy and ICO guidance as they apply to digital marketing.
  • Clear documentation skills and the ability to coach and challenge teams.
  • Availability to carry out regular on-site device testing in the UK.

Desirable: Formal QA or test engineering background.

  • Experience with ObservePoint or similar tag and privacy auditing platforms.
  • SDK analysis using MobSF and APK Analyzer, plus Logcat and Xcode Console.
  • Familiarity with tagging stacks (GTM, Tealium, Server Side tagging) and CDPs.
  • Scripting for traffic capture and analysis (eg Python, JavaScript).
  • Privacy certification (eg CIPP/E, CIPT).
Rate:
Not specified
Location:
London
IR35 Status:
Outside
Remote Status:
Hybrid
Industry:
IT
Seniority Level:
Not Specified

Take-Home Pay

Not Available

Visit calculators for additional details

Share job