Senior Software Engineer (Ruby), Security Platform: Authorization
Core
Design and ship authorization changes in GitLab's Ruby on Rails monolith and migrate the permission model to a new Rust-based authorization engine.
Role type
Senior Software Engineer (Authorization)
Builds
Fine-grained token permissions, custom roles, and policy enforcement layers for GitLab.com, Self-Managed, and Dedicated.
Domain
DevSecOps, Identity & Access Management (IAM), Policy Engines
Deliverable
production ML models | product features | infrastructure
Required skills
Ruby on Rails, Authorization systems (RBAC, fine-grained permissions), Security mindset, GraphQL, REST API, Large codebase refactoring, Performance optimization at scale
Preferred skills
Rust, gRPC, Protocol Buffers, Cedar, Zanzibar-style authorization, Go, Service-oriented architecture
Technologies
Ruby on Rails, Rust, GraphQL, REST, gRPC, Cedar, Zanzibar
Responsibilities
Design and ship authorization changes in the Ruby on Rails monolith; Own workstreams end-to-end from definition to rollout; Build and extend fine-grained permissions for tokens and roles; Extend and harden authorization enforcement across GraphQL and REST APIs; Refactor policy code for dual evaluation by monolith and new engine; Improve reliability and security posture of authorization systems; Partner with authentication and platform teams on interface contracts.
Seniority
Senior, hands-on IC
