> Markdown version of [/jobs/ext/3040669-senior-software-engineer-ruby-security-platform-authorization](https://www.wearedevelopers.com/jobs/ext/3040669-senior-software-engineer-ruby-security-platform-authorization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer (Ruby), Security Platform: Authorization - **Company:** TALENTHOP LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Code Review, Software Design Documents, Protocol Buffers, Ruby on Rails, Role-Based Access Control, Ruby, Service-Oriented Architecture, Rust (Programming Language), Graphql, Restful APIs, Grpc, Code Restructuring - **Published:** September 23, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/pm0melmrps ## About the Role * Extensive experience with production Ruby on Rails applications. * Knowledge of authorization systems, including role-based access control and fine-grained permissions. * Strong security mindset with attention to permission-related risks. * Experience working with large, long-standing codebases and performing incremental, behavior-preserving changes. * Familiarity with GraphQL and API authorization patterns. * Awareness of performance considerations at scale. * Strong written communication skills for asynchronous decision-making. * Beneficial but not required: experience with Rust, gRPC, Protocol Buffers, policy languages like Cedar, Zanzibar-style authorization systems, Go, or service-oriented architectures. ## Description The Senior Software Engineer (Ruby), Security Platform: Authorization is responsible for developing and maintaining critical authorization systems that control access for users, tokens, and automated agents across the platform. This role focuses on designing and implementing fine-grained permission models and transitioning authorization logic to a next-generation stack. The position directly impacts the security and scalability of access control, ensuring robust and efficient permission enforcement., * Design and implement authorization changes within a Ruby on Rails monolith handling complex permission checks. * Own workstreams from problem definition through feature rollout and verification. * Develop and maintain fine-grained permission catalogs and token roles. * Extend authorization enforcement across GraphQL and REST API endpoints. * Refactor policy code to support evaluation by both the monolith and a new authorization engine without altering current behavior. * Enhance reliability, performance, and security of existing authorization systems. * Collaborate with authentication, platform, AI, and modular-service teams on authorization interfaces. * Document and communicate technical decisions through written design documents and code reviews. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Full-stack role-based authorization in 45 minutes](https://www.wearedevelopers.com/videos/312-full-stack-role-based-authorization-in-45-minutes) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [The 7 Most Popular Backend Frameworks for Developers](https://www.wearedevelopers.com/magazine/403-the-7-most-popular-backend-frameworks-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)