Senior Software Engineer (Ruby), Security Platform: Authorization

at GitLab
USD 139,200-235,200 per year
SENIOR
✅ Remote

Tech Stack

AI API @ 4 Communication @ 7 GraphQL @ 4 Ruby @ 4 Ruby on Rails @ 4 Rust @ 6 Security @ 4 gRPC @ 6

Details

GitLab is hiring a Senior Software Engineer for its Authorization team. The team owns the systems that determine what users, tokens, and automated agents can access across GitLab.com, Self-Managed, and Dedicated.

The current authorization system is built in Ruby on Rails and includes approximately 400 policy classes and a YAML catalog of approximately 1,900 permissions. The role will focus on fine-grained token permissions, custom roles, and GraphQL and REST API authorization, while helping migrate the authorization model to a next-generation stack combining the Rails monolith with a Rust policy engine using Zanzibar-style relationship tuples and Cedar policies. The monolith loads the engine in-process and can communicate with it over gRPC.

Responsibilities

  • Design and ship authorization changes in GitLab's Ruby on Rails monolith, where a single request can trigger hundreds of permission checks.
  • Own workstreams end to end, from problem definition through feature-flagged rollout, dual-run verification, and cleanup.
  • Build and extend fine-grained permissions for tokens and roles while maintaining a coherent permission catalog.
  • Extend and harden authorization enforcement across GraphQL and REST APIs.
  • Refactor long-lived policy code so that both the monolith and the new authorization engine can evaluate it without changing behavior for existing customers.
  • Improve the reliability, performance, and security posture of existing authorization systems, including reducing permission-model debt.
  • Partner with authentication, platform, AI, and modular-service teams on interface contracts as authorization moves toward a shared service.
  • Drive technical decisions through design documents, architecture decision records, and code review in a fully asynchronous organization.
  • Contribute to projects such as refactoring the policy layer, expanding fine-grained token permissions, bringing Artifact Registry onto the new authorization stack, and isolating custom-role and permission data per organization ahead of GitLab Cells.

Requirements

  • Significant experience building and operating production Ruby on Rails applications.
  • Experience designing or implementing authorization systems, including role-based access control and fine-grained permissions.
  • A security mindset, including the ability to treat permission bugs as security bugs and reason about blast radius.
  • Comfort making careful changes to large, long-lived codebases through incremental refactors, feature-flagged rollouts, and behavior-preserving migrations.
  • Working knowledge of GraphQL and API authorization patterns.
  • Understanding of performance at scale, including the impact of uncached checks running hundreds of times per request.
  • Strong written communication skills for making decisions through documents and merge requests.
  • Helpful but not required: Rust, gRPC, Protocol Buffers, Cedar or other policy languages, Zanzibar-style authorization systems, Go, or service-oriented architecture.
  • Transferable experience from adjacent domains such as identity, policy engines, and platform security is welcome.

Team

The Authorization team is small, distributed across time zones, works in the open, and makes decisions in writing. It works closely with GitLab's authentication layer, Rust authorization engine, and modular services adopting the shared authorization platform.

Salary

The United States base salary range is $139,200–$235,200 USD per year. The range does not include bonuses, equity, or benefits. Salary ranges are determined based on factors including education, experience, knowledge, skills, abilities, equity with other team members, market data, and geographic location.

Benefits

  • Health, financial, and well-being benefits
  • Flexible paid time off
  • Team Member Resource Groups
  • Equity Compensation and Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

GitLab is a fully remote workplace. GitLab is an equal opportunity workplace and affirmative action employer.

More jobs at GitLab

Similar jobs