> Markdown version of [/jobs/ext/2985804-senior-software-engineer-ruby-security-platform-authorization](https://www.wearedevelopers.com/jobs/ext/2985804-senior-software-engineer-ruby-security-platform-authorization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer (Ruby), Security Platform: Authorization - **Company:** The Ladders - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $139,200.0 - $235,200.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Ruby on Rails, Role-Based Access Control, Ruby, Cloud Platform System, Graphql, Restful APIs, Code Restructuring - **Published:** September 18, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/pl4qurwdvx ## About the Role * 5-7 years building and operating production Ruby on Rails applications * Experience designing or implementing authorization systems with role-based access control and fine-grained permissions * Strong security mindset, treating permission issues as critical * Comfortable making changes to large, long-lived codebases with a careful approach * Knowledge of GraphQL and API authorization patterns * Attention to performance at scale regarding permission checks * Strong written communication skills for asynchronous decision-making ## Description This role will focus on advancing authorization capabilities across a large Ruby on Rails application and its surrounding services. You will own critical work from problem definition through rollout, with a strong emphasis on secure, reliable permission handling at scale. The position partners closely with engineering teams to evolve policy design, maintain consistency across systems, and support ongoing platform modernization., * Design and implement authorization changes in the Ruby on Rails monolith * Own workstreams from problem definition to feature rollout and verification * Build and manage fine-grained permissions and keep the permission model coherent * Enhance authorization enforcement across GraphQL and REST API * Refactor policy code for compatibility with both the monolith and the new engine * Improve reliability and security of existing authorization systems * Collaborate with teams on interface contracts as authorization evolves ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [The 7 Most Popular Backend Frameworks for Developers](https://www.wearedevelopers.com/magazine/403-the-7-most-popular-backend-frameworks-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)