Senior Software Engineer (Ruby), Security Platform: Authorization
New
G
GitLabDevSecOps
Location: Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States, distributed across time zonesFull-TimeSenior
Salary$139,200 — $235,200 USD
Apply NowOpens the employer's application page
Job Details
- Required Skills
- GraphQLRuby on RailsRESTful APIs
Requirements
- Significant experience building and operating production Ruby on Rails applications.
- Experience designing or implementing authorization systems (RBAC, fine-grained permissions).
- Security mindset with the ability to reason about blast radius.
- Experience making careful, incremental changes to large, long-lived codebases.
- Working knowledge of GraphQL and API authorization patterns.
- Attention to performance and scalability in code.
- Strong written communication skills.
- Comfort working in a fully asynchronous organization.
Responsibilities
- Design and ship authorization changes in GitLab's Ruby on Rails monolith.
- Own a workstream end to end, from problem definition through feature-flagged rollout, verification, and cleanup.
- Build and extend fine-grained permissions for tokens and roles.
- Extend and harden authorization enforcement across GraphQL and the REST API.
- Refactor long-lived policy code to support evaluation by both the monolith and the new authorization engine.
- Improve the reliability, performance, and security of existing authorization systems.
- Partner with authentication, platform, AI, and modular-service teams on interface contracts.
- Drive technical decisions in writing via design docs and architecture decision records.
View Full Description & ApplyYou'll be redirected to the employer's site