Senior Software Engineer (Ruby), Security Platform: Authorization

Company: GitLab
Apply for the Senior Software Engineer (Ruby), Security Platform: Authorization
Location:
Job Description:

Overview

In this senior role, you will own and evolve GitLab’s authorization model across Ruby on Rails and a next-generation policy stack. You’ll work on fine-grained token permissions, custom roles, and the GraphQL/REST surfaces that enforce them, with an eye toward performance, security, and scalability. You’ll help bridge the Rails monolith with a Rust-based policy engine and a shared authorization platform. You’ll collaborate across authentication, platform, AI, and modular services to shape how access is governed at scale. This is a hands-on, impact-driven opportunity to strengthen security posture while enabling broad, secure access for users, tokens, and automated agents.

Pay / Benefits

  • Flexible Paid Time Off
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave
  • Team Member Resource Groups

Responsibilities

  • Design and ship authorization changes in the Rails monolith with high-permission-check workloads
  • Own work streams end-to-end from problem definition to rollout and verification
  • Extend fine-grained permissions for tokens and roles across resources and principals
  • Harden authorization enforcement across GraphQL and REST APIs
  • Refactor policy code to support dual evaluation by monolith and authorization engine
  • Improve reliability, performance, and security of authorization systems, reducing debt
  • Collaborate with authentication, platform, and modular-service teams on interfaces and contracts
  • Contribute to design docs, architecture decisions, and code reviews in an asynchronous environment

Key requirements

  • Production Ruby on Rails experience
  • Experience designing/implementing authorization systems (RBAC & fine-grained permissions)
  • Security mindset with ability to assess blast radius
  • Experience with large, long-lived codebases and careful migrations
  • Knowledge of GraphQL and API authorization patterns
  • Attention to performance at scale
  • Strong written communication
  • Strong written communication
  • ability to work asynchronously and document decisions
  • problem-solving mindset
  • Ruby on Rails
  • Authorization systems design (RBAC, fine-grained permissions)
  • GraphQL and REST API authorization patterns

Posted: September 14th, 2026