A live role

Senior Software Engineer (Ruby), Security Platform: Authorization

from GitLab · read the original and apply on their site

Remote, Canada; Remote, Israel; Remote, United Kingdom; Remote, United States

Our take: The real work here is careful, security-minded engineering on the authorization layer that decides what every user, token, and AI agent can access, while helping move that model onto a new Rust-based stack.

If you see a permission bug as a security bug and reason about blast radius before elegance, this is your kind of problem: owning the layer that decides what every user, token, and AI agent can touch across GitLab. You will make careful, behavior-preserving changes to a large Rails codebase, then help lift that whole model onto a next-generation Rust and Cedar engine, learning as you go. Decisions happen in writing, in the open, on a small distributed team that trusts you to own a workstream from problem to cleanup.

Needs

  • authorization systems design
  • refactoring policy code
  • rails engineering
  • reasoning about risk
  • performance tuning
  • writing decisions down

Rewards

  • high stakes work
  • end-to-end ownership
  • learning new domains
  • learning culture
  • visible security impact

Demands

  • rigour under scale
  • behavior-preserving migrations
  • careful codebase changes
  • deep focus
  • cross-team alignment

Grows

  • synthesising complexity
  • authorization strategy
  • learning rust
  • data modelling

Values

  • transparency
  • rigour
  • learning culture
  • candour
  • pragmatism

Drains

  • paying down debt
  • dual-run verification
  • async solo stretches

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next