The opportunity
The Authorization team owns the capabilities that determine what users, tokens, and automated agents can access across GitLab. Our work runs on two tracks.
What you'll do
Design and ship authorization changes in GitLab's Ruby on Rails monolith,: where a single request can trigger hundreds of permission checks.
Own a workstream end to end. Problem definition through feature-flagged: rollout, dual-run verification, and cleanup.
Build and extend fine-grained permissions for tokens and roles, and keep the: permission catalog coherent as it grows.
Extend and harden authorization enforcement across GraphQL and the REST API.
Refactor long-lived policy code so both the monolith and our new: authorization engine can evaluate it, without changing behavior for existing customers.
Improve the reliability, performance, and security posture of existing: authorization systems, including paying down permission-model debt.
What they're looking for
- Partner with the authentication, platform, AI, and modular-service teams on: interface contracts as authorization moves toward a shared service.
- Drive technical decisions in writing. Design docs, architecture decision: records, and code review, in a fully asynchronous organization.