SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer (Ruby), Security Platform: Authorization

GitLab - Remote - Remote - posted 2026-09-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

GitLab is seeking a Senior Software Engineer to own significant portions of the authorization system that controls access for every user, token, and automated agent across GitLab.com, Self-Managed, and Dedicated deployments. In this role, you will design and ship authorization changes in GitLab's Ruby on Rails monolith, where a single request can trigger hundreds of permission checks. You'll own workstreams end-to-end—from problem definition through feature-flagged rollout, dual-run verification, and cleanup. Key responsibilities include building and extending fine-grained permissions for tokens and roles, refactoring long-lived policy code to work with both the monolith and a new Rust-based authorization engine, and improving reliability, performance, and security of existing systems. The authorization stack currently comprises roughly 400 policy classes and a YAML catalog of ~1,900 permissions. You'll help migrate this to GitLab's next-generation system, which pairs the Rails monolith with a Rust policy engine using Zanzibar-style relationship tuples and Cedar policies. Example projects include refactoring the policy layer for dual evaluation, extending fine-grained token permissions to more resources and AI agent service identities, bringing the Artifact Registry modular service onto the new stack, and isolating custom-role data per organization ahead of GitLab Cells. You'll extend and harden authorization enforcement across GraphQL and REST APIs, partner with authentication, platform, AI, and modular-service teams on interface contracts, and drive technical decisions in writing through design docs, architecture decision records, and code review in a fully asynchronous organization. Required: significant production Ruby on Rails experience, authorization system design/implementation expertise (RBAC, fine-grained permissions), security mindset, comfort with large-codebase refactoring and feature-flagged rollouts, GraphQL and API authorization knowledge, performance-at-scale thinking, and strong written communication. Helpful but not required: Rust, gRPC, Protocol Buffers, Cedar, Zanzibar systems, Go, or service-oriented architecture experience.

Similar roles