GitLab Logo

GitLab

Intermediate Backend Engineer (Ruby), Software Supply Chain Security: Authorization

Reposted 3 Days Ago
Easy Apply
Remote
Hiring Remotely in United States
Senior level
Easy Apply
Remote
Hiring Remotely in United States
Senior level
As a Senior Backend Engineer, you will lead the development of a scalable authorization system, implement custom permissions, and influence technical decisions for performance and security while mentoring team members.
The summary above was generated by AI

GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values. Learn more about Life at GitLab.

An overview of this role

Help us architect and evolve our RBAC (role based access control) system. Our team's primary responsibility is to build a robust, scalable authorization system that gives customers complete control over their member access. From zero to owner.

Custom roles allow an organization to create user roles with the precise privileges and permissions required for that organization's needs. It's a valuable, paid feature that our enterprise customers increasingly depend on. As an intermediate engineer, you'll develop and implement solutions that shape the future of our authorization system.

Beyond implementing custom permissions and building features to help owners manage their teams, you'll influence critical architecture decisions to ensure the scalability, security, and performance of the product. We're at the earlier stages of the feature, giving you the opportunity to significantly influence our technical direction, including establishing conventions, design patterns, and development guidelines that will shape how the feature grows.

This role offers unique opportunities to collaborate with our "sister" team Anti-abuse to work on security-focused features. Help lead the battle against crypto-mining by architecting solutions that leverage risk models, identity verification, and pipeline verification and analysis.

What You’ll Do  

  • Provide technical guidance on migrating our existing authorization system to a mature authorization system.
  • Collaborate with our authentication team on design and implementation of a greater authorization and authentication system.
  • Design and implement scalable solutions for our RBAC system, with a focus on enterprise-grade custom permissions
  • Architect features that enable efficient team management while maintaining performance at scale
  • Make and advocate for technical decisions that ensure the long-term maintainability and scalability of Custom Roles
  • Collaborate with Product Management to influence milestone planning and technical direction
  • Drive improvements to system performance, security, and reliability
  • Participate in and lead incident response when required
  • Represent the team in cross-functional technical discussions

What You’ll Bring 

  • Significant professional experience with Ruby on Rails
  • Understanding of authorization systems including RBAC, ABAC, ReBac
  • Experience with using and implementing a mature authorization system (OPA, Cedar, Zanzibar)
  • Experience designing and implementing enterprise-grade authentication systems (OAuth, SAML, SCIM, LDAP)
  • Experience with relational databases and query optimization (postgres preferred)
  • Experience diagnosing and resolving performance issues at scale
  • Strong security mindset and experience with secure coding practices

About the team

The Authorization group is responsible for ensuring that an authenticated user has access to the proper resources within the application. We are focused on making our customizable permissions offering more robust by adding additional granular permissions every milestone. 

You can read about the work that the team is doing here.

How GitLab will support you

  • Benefits to support your health, finances, and well-being
  • All remote, asynchronous work environment
  • Flexible Paid Time Off 
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave 
  • Home office support

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

The base salary range for this role’s listed level is currently for residents of listed locations only. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, and alignment with market data. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

California/Colorado/Hawaii/New Jersey/New York/Washington/DC/Illinois/Minnesota pay range

$98,000$210,000 USD

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.  

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Top Skills

Abac
Cedar
Ldap
Oauth
Opa
Postgres
Rbac
Rebac
Ruby On Rails
SAML
Scim
Zanzibar

Similar Jobs at GitLab

4 Days Ago
Easy Apply
Remote
United States
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
As a Senior Backend Engineer, you will maintain compliance tools, develop automated solutions for financial compliance, analyze code changes, and collaborate with auditors to ensure regulatory adherence.
Top Skills: Compliance ReportingData AnalysisGitRuby On Rails
5 Days Ago
Easy Apply
Remote
US
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
The Zuora Engineer will manage finance software applications, implement billing workflows, integrate systems, and improve business process efficiencies.
Top Skills: APIsAvalaraNetSuiteRelational DatabasesSalesforce CpqStripeZuoraZuora Cpq
8 Days Ago
Easy Apply
Remote
United States
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
The Senior Site Reliability Engineer is responsible for maintaining user-facing services, managing database operations, and optimizing cloud infrastructure at GitLab. Key responsibilities include designing and maintaining ClickHouse and PostgreSQL clusters, implementing monitoring systems, and ensuring security compliance. The role requires strong technical skills in database management and cloud automation, along with leadership and communication abilities.
Top Skills: AnsibleChefClickhouseGoGrafanaHelmKubernetesLinuxPostgresPrometheusPythonRubyTerraform

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account