Senior Software Engineer (Ruby), Security Platform: AuthorizationActive$235K

The opportunity

The Authorization team owns the capabilities that determine what users, tokens, and automated agents can access across GitLab. Our work runs on two tracks.

What you'll do

  • Design and ship authorization changes in GitLab's Ruby on Rails monolith,: where a single request can trigger hundreds of permission checks.

  • Own a workstream end to end. Problem definition through feature-flagged: rollout, dual-run verification, and cleanup.

  • Build and extend fine-grained permissions for tokens and roles, and keep the: permission catalog coherent as it grows.

  • Extend and harden authorization enforcement across GraphQL and the REST API.

  • Refactor long-lived policy code so both the monolith and our new: authorization engine can evaluate it, without changing behavior for existing customers.

  • Improve the reliability, performance, and security posture of existing: authorization systems, including paying down permission-model debt.

What they're looking for

  • Partner with the authentication, platform, AI, and modular-service teams on: interface contracts as authorization moves toward a shared service.
  • Drive technical decisions in writing. Design docs, architecture decision: records, and code review, in a fully asynchronous organization.