Similar Jobs

See all

Overview:

  • This role focuses on building and maintaining the authorization system that controls access for all users, tokens, and automated agents across GitLab.
  • You'll work on both the existing Ruby on Rails permission model and a next-generation Rust-based authorization engine.

What You’ll Do:

  • Own significant parts of the authorization system, from fine-grained token permissions to custom roles and GraphQL enforcement.
  • Refactor long-lived policy code to support both the monolith and new authorization engine without changing behavior.
  • Improve reliability, performance, and security of existing authorization systems, including paying down permission-model debt.

What You’ll Bring:

  • Significant experience building production Ruby on Rails applications and designing authorization systems.
  • A security mindset, treating permission bugs as security bugs and reasoning about blast radius.
  • Strong written communication and comfort working in a fully asynchronous, distributed team.

About the Team:

  • The Authorization team owns the capabilities that determine access across GitLab, working on two tracks: strengthening the monolith's permission model and building a shared authorization platform.
  • The team is small, distributed across time zones, works in the open, and makes decisions in writing.

GitLab

GitLab provides an intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With over 50 million registered users and a high-performance culture driven by values and continuous knowledge exchange, GitLab fosters innovation and collaboration.

Apply for This Position