Image Loading

Backend Engineer (Ruby), Software Supply Chain Security: Authorization

Job Description

GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values. Learn more about Life at GitLab.

An Overview Of This Role

Help us architect and evolve our RBAC (role based access control) system. Our team's primary responsibility is to build a robust, scalable authorization system that gives customers complete control over their member access. From zero to owner.

Custom roles allow an organization to create user roles with the precise privileges and permissions required for that organization's needs. It's a valuable, paid feature that our enterprise customers increasingly depend on. As an intermediate engineer, you'll develop and implement solutions that shape the future of our authorization system.

Beyond implementing custom permissions and building features to help owners manage their teams, you'll influence critical architecture decisions to ensure the scalability, security, and performance of the product. We're at the earlier stages of the feature, giving you the opportunity to significantly influence our technical direction, including establishing conventions, design patterns, and development guidelines that will shape how the feature grows.

This role offers unique opportunities to collaborate with our "sister" team Anti-abuse to work on security-focused features. Help lead the battle against crypto-mining by architecting solutions that leverage risk models, identity verification, and pipeline verification and analysis.

What You’ll Do

  • Provide technical guidance on migrating our existing authorization system to a mature authorization system.
  • Collaborate with our authentication team on design and implementation of a greater authorization and authentication system.
  • Design and implement scalable solutions for our RBAC system, with a focus on enterprise-grade custom permissions
  • Architect features that enable efficient team management while maintaining performance at scale
  • Make and advocate for technical decisions that ensure the long-term maintainability and scalability of Custom Roles
  • Collaborate with Product Management to influence milestone planning and technical direction
  • Drive improvements to system performance, security, and reliability
  • Participate in and lead incident response when required
  • Represent the team in cross-functional technical discussions

What You’ll Bring

  • Significant professional experience with Ruby on Rails
  • Understanding of authorization systems including RBAC, ABAC, ReBac
  • Experience with using and implementing a mature authorization system (OPA, Cedar, Zanzibar)
  • Experience designing and implementing enterprise-grade authentication systems (OAuth, SAML, SCIM, LDAP)
  • Experience with relational databases and query optimization (postgres preferred)
  • Experience diagnosing and resolving performance issues at scale
  • Strong security mindset and experience with secure coding practices

About The Team
The Authorization group is responsible for ensuring that an authenticated user has access to the proper resources within the application. We are focused on making our customizable permissions offering more robust by adding additional granular permissions every milestone.

Skills

  • SAML
  • OAuth
  • ruby on rails
  • Relational Databases

Education

  • Master's Degree
  • Bachelor's Degree

Job Information

Job Posted Date

Apr 01, 2025

Experience

4 to 7 Years

Compensation (Annual in Lacs)

Best in the Industry

Work Type

Permanent

Type Of Work

8 hour shift

Category

Information Technology

Copyright © 2022 All Rights Reserved. Saas Talent