All vacancies
Senior Software Engineer (Ruby), Security Platform: Authorization
GitLab
Remote · United StatesSalary not disclosedfull-timeGitLab Careers
An overview of this role As a Senior Software Engineer on GitLab's Authorization team, you will own significant parts of the system that decides what every user, token, and automated agent can access on GitLab.com, Self-Managed, and Dedicated. Today that work is Ruby on Rails.
Responsibilities
- Design and ship authorization changes in GitLab's Ruby on Rails monolith, where a single request can trigger hundreds of permission checks.
- Own a workstream end to end. Problem definition through feature-flagged rollout, dual-run verification, and cleanup.
- Build and extend fine-grained permissions for tokens and roles, and keep the permission catalog coherent as it grows.
- Extend and harden authorization enforcement across GraphQL and the REST API.
- Refactor long-lived policy code so both the monolith and our new authorization engine can evaluate it, without changing behavior for existing customers.
- Improve the reliability, performance, and security posture of existing authorization systems, including paying down permission-model debt.
- Partner with the authentication, platform, AI, and modular-service teams on interface contracts as authorization moves toward a shared service.
- Drive technical decisions in writing.
- Design docs, architecture decision records, and code review, in a fully asynchronous organization.
Languages
- Work format
- Remote
- Seniority
- Senior
- Posted
- 2 Sept 2026
- Last verified
- In the last 5 days
