> Markdown version of [/jobs/ext/2700632-senior-software-engineer-ruby-security-platform-authorization](https://www.wearedevelopers.com/jobs/ext/2700632-senior-software-engineer-ruby-security-platform-authorization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer (Ruby), Security Platform Authorization - **Company:** GitLab - **Location:** Leeds, UK - **Experience:** Expert - **Salary:** £139,200.0 - £235,200.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Code Review, Software Design Documents, Protocol Buffers, Ruby on Rails, Role-Based Access Control, Ruby, Service-Oriented Architecture, YAML, Gitlab, Graphql, Restful APIs, Code Restructuring - **Published:** September 4, 2026 - **Apply:** https://www.totaljobs.com/job/engineer-security/gitlab-job107935456 ## About the Role * Significant experience building and operating production Ruby on Rails applications. * Experience designing or implementing authorization systems, including role-based access control and fine-grained permissions. * A security mindset. You treat a permission bug as a security bug, and you reason about blast radius before elegance. * Comfort making careful changes to large, long-lived codebases. Incremental refactors, feature-flagged rollouts, and migrations that must not change behavior for existing users. * Working knowledge of GraphQL and API authorization patterns. * Attention to performance at scale. You understand why one uncached check matters when it runs hundreds of times per request. * Strong written communication. You are effective when most decisions happen in a document or a merge request rather than a meeting. * Helpful but not required: Rust, gRPC or Protocol Buffers, Cedar or other policy languages, Zanzibar-style authorization systems, Go, or service-oriented architecture. Several engineers on this team picked up Rust for this work and we will support you doing the same. * We welcome transferable experience from adjacent domains such as identity, policy engines, and platform security. ## Description As a Senior Software Engineer on GitLab's Authorization team, you will own significant parts of the system that decides what every user, token, and automated agent can access on GitLab.com, Self-Managed, and Dedicated. Today that work is Ruby on Rails. Roughly 400 policy classes and a YAML catalog of about 1,900 permissions sit behind every API request. You will work on the permission model itself (fine-grained token permissions, custom roles, and the GraphQL and REST surfaces that enforce them). You will also help move that model onto GitLab's next-generation authorization stack, which pairs the Rails monolith with a Rust policy engine using Zanzibar-style relationship tuples and Cedar policies. The monolith already loads that engine in-process and can reach it over gRPC. Some examples of our projects: * Refactoring GitLab's policy layer so the same permission definitions can be evaluated by the monolith and by our new authorization service * Extending fine-grained token permissions to more resources and more kinds of principal, including the service identities behind AI agents * Bringing GitLab's first modular service, Artifact Registry, onto the new authorization stack * Isolating custom-role and permission data per organization ahead of GitLab Cells What you'll do * Design and ship authorization changes in GitLab's Ruby on Rails monolith, where a single request can trigger hundreds of permission checks. * Own a workstream end to end. Problem definition through feature-flagged rollout, dual-run verification, and cleanup. * Build and extend fine-grained permissions for tokens and roles, and keep the permission catalog coherent as it grows. * Extend and harden authorization enforcement across GraphQL and the REST API. * Refactor long-lived policy code so both the monolith and our new authorization engine can evaluate it, without changing behavior for existing customers. * Improve the reliability, performance, and security posture of existing authorization systems, including paying down permission-model debt. * Partner with the authentication, platform, AI, and modular-service teams on interface contracts as authorization moves toward a shared service. * Drive technical decisions in writing. Design docs, architecture decision records, and code review, in a fully asynchronous organization. ## Related Videos - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Always on the Right Track with Rails with Eileen Uchitelle, Senior System Engineer at GitHub](https://www.wearedevelopers.com/videos/100358-always-on-the-right-track-with-rails-with-eileen-uchitelle-senior-system-engineer-at-github) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The 7 Most Popular Backend Frameworks for Developers](https://www.wearedevelopers.com/magazine/403-the-7-most-popular-backend-frameworks-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)