Senior Software Engineer (Ruby), Security Platform: Authorization

GitLab
Canada, Israel, United Kingdom, United States
Workplace: RemoteFull timeUSD 139,200 - 235,200 annuallyFunction: Software EngineeringSkills: ["Written communication","Security mindset","Performance awareness","Attention to detail","Asynchronous collaboration"]

Build and evolve GitLab’s authorization system, owning critical parts of how users, tokens, and automated agents get access across GitLab.com and self-managed deployments. Work on Ruby on Rails permission models, extend fine-grained token permissions and custom roles, and harden enforcement across GraphQL and REST. Help migrate policy logic to a Rust authorization engine using Zanzibar-style relationship tuples and Cedar policies, improving reliability, performance, and security.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Senior Software Engineer (Ruby), Security Platform: Authorization

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Build and evolve GitLab’s authorization system, owning critical parts of how users, tokens, and automated agents get access across GitLab.com and self-managed deployments. Work on Ruby on Rails permission models, extend fine-grained token permissions and custom roles, and harden enforcement across GraphQL and REST. Help migrate policy logic to a Rust authorization engine using Zanzibar-style relationship tuples and Cedar policies, improving reliability, performance, and security.
Location: Canada, Israel, United Kingdom, United States
Workplace: Remote
Employment Type: Full time
Job Function: Software Engineering
Seniority: Mid level

Key Responsibilities

  • •Design and ship authorization changes in the Rails monolith, potentially triggering hundreds of permission checks per request.
  • •Own authorization work end to end from problem definition through feature-flagged rollout, dual-run verification, and cleanup.
  • •Build and extend fine-grained token permissions and roles, keeping the permission catalog coherent as it grows.
  • •Extend and harden authorization enforcement across GraphQL and the REST API.
  • •Refactor policy code so both the Rails monolith and the new authorization engine can evaluate it without changing existing customer behavior.

Pay and Benefits

Salary: USD 139,200 - 235,200 annually
Perks:Paid LeaveEquityLearning BudgetParental Leave

Key Requirements

  • •Significant experience building and operating production Ruby on Rails applications.
  • •Experience designing or implementing authorization systems, including RBAC and fine-grained permissions.
  • •Security mindset with ability to assess blast radius when fixing authorization/permission issues.
  • •Comfort making incremental, behavior-preserving changes to long-lived codebases using feature flags and migrations.
  • •Working knowledge of GraphQL and API authorization patterns.
Experience:DevSecOpsAuthorization systemsIdentityPolicy enginesPlatform security
Skills:Written communicationSecurity mindsetPerformance awarenessAttention to detailAsynchronous collaboration
Languages:English
Tech Stack:Ruby on RailsRubyRustGraphQLRESTYAMLGRPCProtocol BuffersCedarZanzibar-style authorizationGoFeature flagsPolicy engine

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn