
About the Role
As a Senior Software Engineer on GitLab's Authorization team, you will own significant parts of the system that governs access for every user, token, and automated agent across GitLab.com, Self-Managed, and Dedicated instances.
You will work on the core permission model—managing roughly 400 policy classes and 1,900 permissions—while helping transition the architecture from a Ruby on Rails monolith to a next-generation stack utilizing a Rust-based policy engine with Zanzibar-style relationship tuples and Cedar policies.
What You’ll Do
- Design and Ship: Implement authorization changes in the Rails monolith, managing end-to-end workstreams from definition to feature-flagged rollout.
- Scale Permissions: Extend fine-grained permissions for tokens and roles, ensuring the permission catalog remains coherent as it grows.
- Modernize Architecture: Refactor long-lived policy code to support evaluation by both the monolith and the new authorization service.
- Harden Security: Extend and harden authorization enforcement across GraphQL and REST APIs.
- Collaborate: Partner with authentication, platform, AI, and modular-service teams on interface contracts.
- Drive Decisions: Lead technical direction through design docs, architecture decision records, and asynchronous code reviews.
What You’ll Bring
- Ruby Expertise: Significant experience building and operating production Ruby on Rails applications.
- Authorization Knowledge: Experience designing or implementing RBAC and fine-grained permission systems.
- Security Mindset: Ability to reason about blast radius and treat permission bugs as critical security issues.
- Operational Excellence: Comfort with incremental refactors, feature-flagged rollouts, and maintaining performance at scale.
- Communication: Strong written communication skills suitable for a fully asynchronous, distributed environment.
- Bonus Skills: Experience with Rust, gRPC, Protocol Buffers, Cedar, Zanzibar-style systems, or Go is helpful but not required.
How GitLab Supports You
- Flexible Paid Time Off
- Equity Compensation & Employee Stock Purchase Plan
- Comprehensive health, finance, and well-being benefits
- Growth and Development Fund
- Parental Leave
- Team Member Resource Groups
Timezone overlap
UTC-8–-4
Open to
US · Canada · UK · Israel
Sign in to track applications and earn points.